Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
xmrig.elf

Overview

General Information

Sample name:xmrig.elf
Analysis ID:1592323
MD5:0c4fd70fbb52ed89a08ee75b5ae7d95a
SHA1:de76b59dbd5e2eebb8d6162c8d074d6580758cb7
SHA256:ac3a08aa60e6e41bba950023856f53ace5ecff030d4bce675a3f087457fb7a25
Tags:elfuser-abuse_ch
Infos:

Detection

Xmrig
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Found strings related to Crypto-Mining
Executes the "rm" command used to delete files or directories
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1592323
Start date and time:2025-01-16 01:07:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:xmrig.elf
Detection:MAL
Classification:mal68.mine.linELF@0/0@0/0
Command:/tmp/xmrig.elf
PID:6247
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6221, Parent: 4332)
  • rm (PID: 6221, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.I2XgSzoVus /tmp/tmp.GjkSLpvseV /tmp/tmp.Ogm1aowLaV
  • dash New Fork (PID: 6222, Parent: 4332)
  • rm (PID: 6222, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.I2XgSzoVus /tmp/tmp.GjkSLpvseV /tmp/tmp.Ogm1aowLaV
  • cleanup
SourceRuleDescriptionAuthorStrings
xmrig.elfJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    xmrig.elfLinux_Trojan_Pornoasset_927f314funknownunknown
    • 0x2099d8:$a: C3 D3 CB D3 C3 48 31 C3 48 0F AF F0 48 0F AF F0 48 0F AF F0 48
    xmrig.elfMacOS_Cryptominer_Xmrig_241780a1unknownunknown
    • 0x5ce6c6:$a1: mining.set_target
    • 0x5cd909:$a2: XMRIG_HOSTNAME
    • 0x5e7e70:$a3: Usage: xmrig [OPTIONS]
    • 0x5cd8ea:$a4: XMRIG_VERSION
    xmrig.elfminer_lin_xmrig_stringsDetects XMRig ELFSekoia.io
    • 0x5ce2d2:$: XMRig
    • 0x5e9730:$: XMRig
    • 0x5ce3f2:$: pool_wallet
    • 0x5ce42c:$: IP Address currently banned
    • 0x5ce45d:$: rigid
    • 0x5ce494:$: diff_current
    • 0x5ce4a1:$: shares_good
    • 0x5ce4ad:$: shares_total
    • 0x5ce4ba:$: avg_time
    • 0x5ce4c3:$: avg_time
    • 0x5ce4c3:$: avg_time_ms
    • 0x5ce4cf:$: hashes_total
    • 0x5ce589:$: pool address
    • 0x5ce596:$: ping time
    • 0x5ce5a0:$: connection time
    • 0x5e2e2c:$: connection time
    • 0x6049e0:$: daemon+https://
    • 0x6049f0:$: daemon+http://
    • 0x604a00:$: socks5://
    • 0x5cf6d7:$: stratum+ssl://
    • 0x5e7e18:$: stratum+ssl://
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: xmrig.elfReversingLabs: Detection: 28%
    Source: xmrig.elfVirustotal: Detection: 40%Perma Link

    Bitcoin Miner

    barindex
    Source: Yara matchFile source: xmrig.elf, type: SAMPLE
    Source: xmrig.elfString found in binary or memory: stratum+ssl://%s
    Source: xmrig.elfString found in binary or memory: cryptonight/0
    Source: xmrig.elfString found in binary or memory: -o, --url=URL URL of mining server
    Source: xmrig.elfString found in binary or memory: stratum+tcp://
    Source: xmrig.elfString found in binary or memory: Usage: xmrig [OPTIONS]
    Source: xmrig.elfString found in binary or memory: XMRig 6.22.2
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: xmrig.elfString found in binary or memory: https://gcc.gnu.org/bugsrg/bugs/):
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/benchmark/%s
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/docs/algorithms
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/wizard
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/wizard%s
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

    System Summary

    barindex
    Source: xmrig.elf, type: SAMPLEMatched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
    Source: xmrig.elf, type: SAMPLEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
    Source: xmrig.elf, type: SAMPLEMatched rule: Detects XMRig ELF Author: Sekoia.io
    Source: xmrig.elf, type: SAMPLEMatched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
    Source: xmrig.elf, type: SAMPLEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
    Source: xmrig.elf, type: SAMPLEMatched rule: miner_lin_xmrig_strings author = Sekoia.io, description = Detects XMRig ELF, creation_date = 2022-09-08, classification = TLP:CLEAR, version = 1.0, modification_date = 2024-01-04, id = 2f99020b-424c-4433-860c-5e9ab4e1f1de
    Source: classification engineClassification label: mal68.mine.linELF@0/0@0/0
    Source: /usr/bin/dash (PID: 6221)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.I2XgSzoVus /tmp/tmp.GjkSLpvseV /tmp/tmp.Ogm1aowLaVJump to behavior
    Source: /usr/bin/dash (PID: 6222)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.I2XgSzoVus /tmp/tmp.GjkSLpvseV /tmp/tmp.Ogm1aowLaVJump to behavior
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    File Deletion
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    xmrig.elf29%ReversingLabsLinux.Trojan.Multiverze
    xmrig.elf41%VirustotalBrowse
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    https://gcc.gnu.org/bugsrg/bugs/):xmrig.elffalse
      high
      https://xmrig.com/benchmark/%sxmrig.elffalse
        high
        https://xmrig.com/wizardxmrig.elffalse
          high
          https://xmrig.com/wizard%sxmrig.elffalse
            high
            https://xmrig.com/docs/algorithmsxmrig.elffalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              109.202.202.202
              unknownSwitzerland
              13030INIT7CHfalse
              91.189.91.43
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              91.189.91.42
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
              91.189.91.43boatnet.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  91.189.91.42boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                    boatnet.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      CANONICAL-ASGBboatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      boatnet.spc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      • 185.125.190.26
                                                      res.arc.elfGet hashmaliciousUnknownBrowse
                                                      • 185.125.190.26
                                                      boatnet.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      CANONICAL-ASGBboatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      boatnet.spc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      • 185.125.190.26
                                                      res.arc.elfGet hashmaliciousUnknownBrowse
                                                      • 185.125.190.26
                                                      boatnet.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 91.189.91.42
                                                      INIT7CHboatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      boatnet.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      na.elfGet hashmaliciousPrometeiBrowse
                                                      • 109.202.202.202
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, missing section headers at 8297648
                                                      Entropy (8bit):6.576025621807749
                                                      TrID:
                                                      • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                      • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                      • Lumena CEL bitmap (63/63) 0.78%
                                                      File name:xmrig.elf
                                                      File size:7'846'952 bytes
                                                      MD5:0c4fd70fbb52ed89a08ee75b5ae7d95a
                                                      SHA1:de76b59dbd5e2eebb8d6162c8d074d6580758cb7
                                                      SHA256:ac3a08aa60e6e41bba950023856f53ace5ecff030d4bce675a3f087457fb7a25
                                                      SHA512:c2b33155d691941b41405dc6b28288c6e4b17f565768a2df8d3d50718897f3bb4f20e9c09d579909ab08ef95f01c43437efc2f6f525744bcce295edac4262fdf
                                                      SSDEEP:98304:yr6P2CZlp4ledj/mf7ukUzX093B9VK/OQGthOlgPEWi1MVNWoGt7rPAW3R1lrepP:bl4lcmDi1WIPFCBNcJ7oEkLsQ3
                                                      TLSH:F1865B47B6E318FDC19AC870472FD563BD7078A84221B97B76989A302F67E205B1DF21
                                                      File Content Preview:.ELF..............>.....S.@.....@.......p.~.........@.8...@.......................@.......@...............................................@.......@.......\.......\.......................\.....................................................`.w.....`......
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Jan 16, 2025 01:07:52.173552990 CET43928443192.168.2.2391.189.91.42
                                                      Jan 16, 2025 01:07:57.548851013 CET42836443192.168.2.2391.189.91.43
                                                      Jan 16, 2025 01:07:59.084618092 CET4251680192.168.2.23109.202.202.202
                                                      Jan 16, 2025 01:08:12.906755924 CET43928443192.168.2.2391.189.91.42
                                                      Jan 16, 2025 01:08:23.145354986 CET42836443192.168.2.2391.189.91.43
                                                      Jan 16, 2025 01:08:29.288472891 CET4251680192.168.2.23109.202.202.202
                                                      Jan 16, 2025 01:08:53.861207008 CET43928443192.168.2.2391.189.91.42
                                                      Jan 16, 2025 01:09:14.338345051 CET42836443192.168.2.2391.189.91.43

                                                      System Behavior

                                                      Start time (UTC):00:07:48
                                                      Start date (UTC):16/01/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):00:07:48
                                                      Start date (UTC):16/01/2025
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.I2XgSzoVus /tmp/tmp.GjkSLpvseV /tmp/tmp.Ogm1aowLaV
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):00:07:48
                                                      Start date (UTC):16/01/2025
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):00:07:48
                                                      Start date (UTC):16/01/2025
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.I2XgSzoVus /tmp/tmp.GjkSLpvseV /tmp/tmp.Ogm1aowLaV
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b