IOC Report
.report_system.elf

loading gif

Files

File Path
Type
Category
Malicious
.report_system.elf
ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=8afd33b2af62232440a91e62c1990b7361563967, stripped
initial sample
malicious
/sys/devices/system/node/node0/hugepages/hugepages-2048kB/nr_hugepages
ASCII text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
/tmp/.report_system.elf
/tmp/.report_system.elf
/tmp/.report_system.elf
-
/tmp/.report_system.elf
-
/bin/sh
sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1"
/bin/sh
-
/sbin/modprobe
/sbin/modprobe msr allow_writes=on

URLs

Name
IP
Malicious
https://xmrig.com/benchmark/%s
unknown
https://xmrig.com/wizard
unknown
https://gcc.gnu.org/bugsterminate
unknown
https://xmrig.com/wizard%s
unknown
https://xmrig.com/docs/algorithms
unknown

Domains

Name
IP
Malicious
xkobeproxy.xkobeimparatu.net
91.184.240.129
malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
91.184.240.129
xkobeproxy.xkobeimparatu.net
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
c29000
page execute read
malicious
c29000
page execute read
malicious
7f921c021000
page read and write
7f92c68a5000
page read and write
e6b000
page read and write
7f92c2a00000
page read and write
2053000
page read and write
7ffe9fda6000
page read and write
7f92c6a6f000
page read and write
7f92c6691000
page read and write
f07000
page read and write
7f92bc021000
page read and write
7f92b8021000
page read and write
7ffe9fda6000
page read and write
7f92c6a6f000
page read and write
f07000
page read and write
7f92c6a2a000
page read and write
7f92c3e8c000
page read and write
7f92c66b3000
page read and write
7f92c6a2a000
page read and write
7f92c5e90000
page read and write
7f92c468d000
page read and write
e6b000
page read and write
2053000
page read and write
7f92c3e0c000
page execute and read and write
7f92c568f000
page read and write
20ad000
page read and write
7ffe9fdab000
page execute read
7f9231e00000
page read and write
7f92c66b1000
page execute read
7f92c3e72000
page read and write
7f92c2dca000
page execute and read and write
7f92c3dcc000
page read and write
7ffe9fdab000
page execute read
7f92b4000000
page read and write
7f92c66b1000
page execute read
7f92c35cb000
page read and write
7f92c3e4d000
page read and write
7f92c2800000
page read and write
7f92c68a5000
page read and write
7f92c2c00000
page read and write
7f92c66b3000
page read and write
7f92b4021000
page read and write
7f92c4e8e000
page read and write
There are 34 hidden memdumps, click here to show them.