Source: MGTyV3yLFW |
Virustotal: Detection: 68% |
Perma Link |
Source: MGTyV3yLFW |
Metadefender: Detection: 67% |
Perma Link |
Source: MGTyV3yLFW |
ReversingLabs: Detection: 77% |
Source: MGTyV3yLFW, type: SAMPLE |
Matched rule: NetWiredRC Author: Jean-Philippe Teissier / @Jipe_ |
Source: ELF static info symbol of initial sample |
Name: DecodeSQLitePayloadData |
Source: ELF static info symbol of initial sample |
Name: GetChromiumPasswords |
Source: ELF static info symbol of initial sample |
Name: GetGoogleChromePasswords |
Source: ELF static info symbol of initial sample |
Name: GetMozillaProductPasswords |
Source: ELF static info symbol of initial sample |
Name: GetPidginPasswords |
Source: ELF static info symbol of initial sample |
Name: Password |
Source: ELF static info symbol of initial sample |
Name: cpGetUsername |
Source: ELF static info symbol of initial sample |
.symtab present: no |
Source: MGTyV3yLFW, type: SAMPLE |
Matched rule: NetWiredRC_B date = 2014-12-23, filetype = memory, author = Jean-Philippe Teissier / @Jipe_, description = NetWiredRC, version = 1.1 |
Source: classification engine |
Classification label: mal68.lin@0/9@0/0 |
Source: /bin/mkdir (PID: 3647) |
Directory: .cache |
Source: /bin/mkdir (PID: 3648) |
Directory: .cache |
Source: /bin/egrep (PID: 3649) |
Grep executable: /bin/grep -> grep -E [^[:print:]] /home/user/.cache/logrotate/status |
Source: /sbin/resolvconf (PID: 3609) |
Mkdir executable: /bin/mkdir -> mkdir -p /run/resolvconf/interface |
Source: /bin/dash (PID: 3647) |
Mkdir executable: /bin/mkdir -> mkdir -p /home/user/.cache/logrotate |
Source: /bin/dash (PID: 3648) |
Mkdir executable: /bin/mkdir -> mkdir -p /home/user/.cache/upstart |
Source: /bin/dash (PID: 3651) |
Mktemp executable: /bin/mktemp -> mktemp |
Source: /bin/dash (PID: 3784) |
Rm executable: /bin/rm -> rm -f /tmp/tmp.s1YjGIpgkp |
Source: /bin/dash (PID: 3192) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3223) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3248) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3279) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3307) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3332) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3370) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3402) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3427) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3455) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3487) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3528) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3543) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3585) |
Sleep executable: /bin/sleep -> sleep 1 |