Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
.report_system.elf
|
ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for
GNU/Linux 2.6.32, BuildID[sha1]=8afd33b2af62232440a91e62c1990b7361563967, stripped
|
initial sample
|
||
/sys/devices/system/node/node0/hugepages/hugepages-2048kB/nr_hugepages
|
ASCII text, with no line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/.report_system.elf
|
/tmp/.report_system.elf
|
||
/tmp/.report_system.elf
|
-
|
||
/tmp/.report_system.elf
|
-
|
||
/bin/sh
|
sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1"
|
||
/bin/sh
|
-
|
||
/sbin/modprobe
|
/sbin/modprobe msr allow_writes=on
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://xmrig.com/benchmark/%s
|
unknown
|
||
https://xmrig.com/wizard
|
unknown
|
||
https://gcc.gnu.org/bugsterminate
|
unknown
|
||
https://xmrig.com/wizard%s
|
unknown
|
||
https://xmrig.com/docs/algorithms
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
xkobeproxy.xkobeimparatu.net
|
91.184.240.129
|
||
daisy.ubuntu.com
|
162.213.35.25
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
91.184.240.129
|
xkobeproxy.xkobeimparatu.net
|
Russian Federation
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
c29000
|
page execute read
|
|||
c29000
|
page execute read
|
|||
7f921c021000
|
page read and write
|
|||
7f92c68a5000
|
page read and write
|
|||
e6b000
|
page read and write
|
|||
7f92c2a00000
|
page read and write
|
|||
2053000
|
page read and write
|
|||
7ffe9fda6000
|
page read and write
|
|||
7f92c6a6f000
|
page read and write
|
|||
7f92c6691000
|
page read and write
|
|||
f07000
|
page read and write
|
|||
7f92bc021000
|
page read and write
|
|||
7f92b8021000
|
page read and write
|
|||
7ffe9fda6000
|
page read and write
|
|||
7f92c6a6f000
|
page read and write
|
|||
f07000
|
page read and write
|
|||
7f92c6a2a000
|
page read and write
|
|||
7f92c3e8c000
|
page read and write
|
|||
7f92c66b3000
|
page read and write
|
|||
7f92c6a2a000
|
page read and write
|
|||
7f92c5e90000
|
page read and write
|
|||
7f92c468d000
|
page read and write
|
|||
e6b000
|
page read and write
|
|||
2053000
|
page read and write
|
|||
7f92c3e0c000
|
page execute and read and write
|
|||
7f92c568f000
|
page read and write
|
|||
20ad000
|
page read and write
|
|||
7ffe9fdab000
|
page execute read
|
|||
7f9231e00000
|
page read and write
|
|||
7f92c66b1000
|
page execute read
|
|||
7f92c3e72000
|
page read and write
|
|||
7f92c2dca000
|
page execute and read and write
|
|||
7f92c3dcc000
|
page read and write
|
|||
7ffe9fdab000
|
page execute read
|
|||
7f92b4000000
|
page read and write
|
|||
7f92c66b1000
|
page execute read
|
|||
7f92c35cb000
|
page read and write
|
|||
7f92c3e4d000
|
page read and write
|
|||
7f92c2800000
|
page read and write
|
|||
7f92c68a5000
|
page read and write
|
|||
7f92c2c00000
|
page read and write
|
|||
7f92c66b3000
|
page read and write
|
|||
7f92b4021000
|
page read and write
|
|||
7f92c4e8e000
|
page read and write
|
There are 34 hidden memdumps, click here to show them.