Source: x.rar.elf |
ReversingLabs: Detection: 31% |
Source: Yara match |
File source: x.rar.elf, type: SAMPLE |
Source: x.rar.elf |
String found in binary or memory: stratum+ssl://randomx.xmrig.com:443 |
Source: x.rar.elf |
String found in binary or memory: cryptonight/0 |
Source: x.rar.elf |
String found in binary or memory: -o, --url=URL URL of mining server |
Source: x.rar.elf |
String found in binary or memory: stratum+tcp:// |
Source: x.rar.elf |
String found in binary or memory: Usage: xmrig [OPTIONS] |
Source: x.rar.elf |
String found in binary or memory: XMRig 6.18.1 |
Source: unknown |
HTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: x.rar.elf |
String found in binary or memory: https://xmrig.com/benchmark/%s |
Source: x.rar.elf |
String found in binary or memory: https://xmrig.com/docs/algorithms |
Source: x.rar.elf |
String found in binary or memory: https://xmrig.com/wizard |
Source: x.rar.elf |
String found in binary or memory: https://xmrig.com/wizard%s |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 33606 |
Source: unknown |
Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 33606 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: unknown |
HTTPS traffic detected: 54.171.230.55:443 -> 192.168.2.23:33606 version: TLS 1.2 |
Source: x.rar.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown |
Source: x.rar.elf, type: SAMPLE |
Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown |
Source: x.rar.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16 |
Source: x.rar.elf, type: SAMPLE |
Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25 |
Source: classification engine |
Classification label: mal72.mine.linELF@0/0@0/0 |
Source: /usr/bin/dash (PID: 6259) |
Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.dAWMy7umgP /tmp/tmp.AJJQBzrGT2 /tmp/tmp.ySOq9iUnPf |
Jump to behavior |
Source: /usr/bin/dash (PID: 6268) |
Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.dAWMy7umgP /tmp/tmp.AJJQBzrGT2 /tmp/tmp.ySOq9iUnPf |
Jump to behavior |