Linux Analysis Report
A29IA3dFx4.elf

Overview

General Information

Sample name: A29IA3dFx4.elf
renamed because original name is a hash value
Original sample name: d0511015ef5a3ed82eb09778bf9f42cb.elf
Analysis ID: 1431544
MD5: d0511015ef5a3ed82eb09778bf9f42cb
SHA1: 8ed8fbc81045344f700d905a70557156749cc254
SHA256: d27dd0e6df6ceb190ba50eef9d377d1bb7e0f4618f5726f5f962f971bb0be50b
Tags: 32armelfmirai
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: A29IA3dFx4.elf Avira: detected
Source: A29IA3dFx4.elf ReversingLabs: Detection: 70%
Source: A29IA3dFx4.elf Virustotal: Detection: 57% Perma Link
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@2/0
Source: /tmp/A29IA3dFx4.elf (PID: 5556) Queries kernel information via 'uname': Jump to behavior
Source: A29IA3dFx4.elf, 5556.1.00007ffd9fa44000.00007ffd9fa65000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/A29IA3dFx4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/A29IA3dFx4.elf
Source: A29IA3dFx4.elf, 5556.1.0000559e46a55000.0000559e46b83000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: A29IA3dFx4.elf, 5556.1.00007ffd9fa44000.00007ffd9fa65000.rw-.sdmp Binary or memory string: qemu: %s: %s
Source: A29IA3dFx4.elf, 5556.1.00007ffd9fa44000.00007ffd9fa65000.rw-.sdmp Binary or memory string: leqemu: %s: %s
Source: A29IA3dFx4.elf, 5556.1.0000559e46a55000.0000559e46b83000.rw-.sdmp Binary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: A29IA3dFx4.elf, 5556.1.0000559e46a55000.0000559e46b83000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: A29IA3dFx4.elf, 5556.1.00007ffd9fa44000.00007ffd9fa65000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: A29IA3dFx4.elf, 5556.1.0000559e46a55000.0000559e46b83000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
No contacted IP infos