Linux Analysis Report
kYeWacX52V.elf

Overview

General Information

Sample name: kYeWacX52V.elf
renamed because original name is a hash value
Original sample name: fe7342800b4725e95f0cc7aa9ec5cec0.elf
Analysis ID: 1428277
MD5: fe7342800b4725e95f0cc7aa9ec5cec0
SHA1: 37940a15e4b233bf2337d5944e69a3b7961bcaf3
SHA256: ccf74c293c8d23babdf49dddd32fe6a2b2cfc64a203f5d54e1f0358a2e4b2d36
Tags: 32elfmiraimotorola
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: kYeWacX52V.elf Avira: detected
Source: kYeWacX52V.elf ReversingLabs: Detection: 34%
Source: /tmp/kYeWacX52V.elf (PID: 5431) Socket: 127.0.0.1::1234 Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5433) Socket: 0.0.0.0::23 Jump to behavior

System Summary

barindex
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 914, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 917, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3104, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3161, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3162, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3163, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3164, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3165, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3170, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3182, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3208, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3212, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5457, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5458, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5459, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5460, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5461, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5462, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5564, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5580, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5581, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5586, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5526) SIGKILL sent: pid: 5522, result: successful Jump to behavior
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 914, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 917, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3104, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3161, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3162, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3163, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3164, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3165, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3170, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3182, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3208, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 3212, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5457, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5458, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5459, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5460, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5461, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5462, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5564, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5580, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5581, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) SIGKILL sent: pid: 5586, result: successful Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5526) SIGKILL sent: pid: 5522, result: successful Jump to behavior
Source: classification engine Classification label: mal60.spre.linELF@0/0@0/0
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/235/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/115/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/236/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/116/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/237/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/117/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/238/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/118/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/239/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/5379/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/119/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/914/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/914/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/10/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/11/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/12/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/5273/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/5273/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/13/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/14/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/15/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/16/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/17/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/18/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/19/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/240/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/3095/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/3095/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/120/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/241/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/121/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/242/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/122/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/243/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/2/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/123/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/244/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/3/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/124/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/245/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1588/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1588/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/125/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/4/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/246/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/126/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/5/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/247/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/127/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/6/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/248/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/128/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/7/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/249/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/129/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/8/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/800/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/800/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/9/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1906/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1906/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/802/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/802/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/803/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/803/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/20/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/21/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/22/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/23/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/24/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/25/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/26/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/27/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/28/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/29/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/3420/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/3420/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1482/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1482/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/490/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/490/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1480/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/1480/maps Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/250/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/371/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/130/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/251/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/131/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/252/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/132/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5435) File opened: /proc/253/cmdline Jump to behavior
Source: /tmp/kYeWacX52V.elf (PID: 5431) Queries kernel information via 'uname': Jump to behavior
Source: kYeWacX52V.elf, 5431.1.00005629b013b000.00005629b019f000.rw-.sdmp, kYeWacX52V.elf, 5522.1.00005629b013b000.00005629b019f000.rw-.sdmp, kYeWacX52V.elf, 5526.1.00005629b013b000.00005629b019f000.rw-.sdmp Binary or memory string: )V!/etc/qemu-binfmt/m68k
Source: kYeWacX52V.elf, 5431.1.00007ffeae245000.00007ffeae266000.rw-.sdmp, kYeWacX52V.elf, 5522.1.00007ffeae245000.00007ffeae266000.rw-.sdmp, kYeWacX52V.elf, 5526.1.00007ffeae245000.00007ffeae266000.rw-.sdmp Binary or memory string: /usr/bin/qemu-m68k
Source: kYeWacX52V.elf, 5431.1.00007ffeae245000.00007ffeae266000.rw-.sdmp, kYeWacX52V.elf, 5522.1.00007ffeae245000.00007ffeae266000.rw-.sdmp, kYeWacX52V.elf, 5526.1.00007ffeae245000.00007ffeae266000.rw-.sdmp Binary or memory string: Ox86_64/usr/bin/qemu-m68k/tmp/kYeWacX52V.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/kYeWacX52V.elf
Source: kYeWacX52V.elf, 5431.1.00005629b013b000.00005629b019f000.rw-.sdmp, kYeWacX52V.elf, 5522.1.00005629b013b000.00005629b019f000.rw-.sdmp, kYeWacX52V.elf, 5526.1.00005629b013b000.00005629b019f000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/m68k
No contacted IP infos