Linux Analysis Report
XWHpNIPKrM.elf

Overview

General Information

Sample name: XWHpNIPKrM.elf
renamed because original name is a hash value
Original sample name: c4f71c7502f67b1ae047875bcd95f491.elf
Analysis ID: 1428278
MD5: c4f71c7502f67b1ae047875bcd95f491
SHA1: cb4bc785c4c901c3517d1421af147a04b875e39b
SHA256: 9a1fbb3f1d6b568898495316e593a94461d6aff63b112427032663c7618b6522
Tags: 32elfmiraipowerpc
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: XWHpNIPKrM.elf Avira: detected
Source: XWHpNIPKrM.elf ReversingLabs: Detection: 31%
Source: /tmp/XWHpNIPKrM.elf (PID: 5509) Socket: 127.0.0.1::1234 Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5511) Socket: 0.0.0.0::23 Jump to behavior

System Summary

barindex
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 917, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 928, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 940, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3129, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3184, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3187, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3188, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3189, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3190, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3193, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3207, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3215, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3235, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5535, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5536, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5537, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5538, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5539, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5540, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5639, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5652, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5653, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5656, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5657, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5658, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5596) SIGKILL sent: pid: 5594, result: successful Jump to behavior
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 917, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 928, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 940, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3129, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3184, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3187, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3188, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3189, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3190, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3193, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3207, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3215, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 3235, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5535, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5536, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5537, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5538, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5539, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5540, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5639, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5652, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5653, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5656, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5657, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) SIGKILL sent: pid: 5658, result: successful Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5596) SIGKILL sent: pid: 5594, result: successful Jump to behavior
Source: classification engine Classification label: mal60.spre.linELF@0/0@0/0
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3760/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3761/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1583/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/2672/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1577/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1577/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/235/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/115/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/116/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/117/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/118/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/119/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/10/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/11/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/12/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/13/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/14/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/15/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/16/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/17/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/5157/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/18/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/19/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1593/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1593/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/240/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/120/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3094/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3094/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/121/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/242/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3406/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3406/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/122/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/243/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/2/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/123/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/244/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1589/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1589/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/124/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/245/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1588/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/1588/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/125/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/4/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/246/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3402/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3402/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/126/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/5/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/247/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/127/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/6/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/248/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/128/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/7/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/249/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/8/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/129/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/800/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/800/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3762/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/9/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/801/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/801/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3763/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/803/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/803/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/20/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/806/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/806/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/21/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/807/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/807/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/928/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/928/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/22/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/23/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/24/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/25/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/26/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/27/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/28/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/29/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3420/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/3420/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/490/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/490/maps Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/250/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/130/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/251/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/131/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5515) File opened: /proc/252/cmdline Jump to behavior
Source: /tmp/XWHpNIPKrM.elf (PID: 5509) Queries kernel information via 'uname': Jump to behavior
Source: XWHpNIPKrM.elf, 5509.1.000055edba1b3000.000055edba263000.rw-.sdmp, XWHpNIPKrM.elf, 5594.1.000055edba1b3000.000055edba263000.rw-.sdmp, XWHpNIPKrM.elf, 5596.1.000055edba1b3000.000055edba263000.rw-.sdmp Binary or memory string: !/etc/qemu-binfmt/ppc1
Source: XWHpNIPKrM.elf, 5509.1.000055edba1b3000.000055edba263000.rw-.sdmp, XWHpNIPKrM.elf, 5594.1.000055edba1b3000.000055edba263000.rw-.sdmp, XWHpNIPKrM.elf, 5596.1.000055edba1b3000.000055edba263000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/ppc
Source: XWHpNIPKrM.elf, 5509.1.00007ffeb6aa4000.00007ffeb6ac5000.rw-.sdmp, XWHpNIPKrM.elf, 5594.1.00007ffeb6aa4000.00007ffeb6ac5000.rw-.sdmp, XWHpNIPKrM.elf, 5596.1.00007ffeb6aa4000.00007ffeb6ac5000.rw-.sdmp Binary or memory string: /usr/bin/qemu-ppc
Source: XWHpNIPKrM.elf, 5509.1.00007ffeb6aa4000.00007ffeb6ac5000.rw-.sdmp, XWHpNIPKrM.elf, 5594.1.00007ffeb6aa4000.00007ffeb6ac5000.rw-.sdmp, XWHpNIPKrM.elf, 5596.1.00007ffeb6aa4000.00007ffeb6ac5000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-ppc/tmp/XWHpNIPKrM.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/XWHpNIPKrM.elf
No contacted IP infos