Linux Analysis Report
Lj7qNwy54U.elf

Overview

General Information

Sample name: Lj7qNwy54U.elf
renamed because original name is a hash value
Original sample name: 92a059d069b3cbf607b1d1608f5f82b0.elf
Analysis ID: 1438521
MD5: 92a059d069b3cbf607b1d1608f5f82b0
SHA1: a5aafc90ede43ca636bf64d872bbe84bf5ee1495
SHA256: 1d7d672b8e29a2043714b2d8c3c9ebb4601d5a69da274aa0ab78c4fa3d1b06da
Tags: 32elfmiraimotorola
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: Lj7qNwy54U.elf ReversingLabs: Detection: 55%

Networking

barindex
Source: global traffic TCP traffic: 91.92.244.58 ports 0,1,5,6,9,60195
Source: global traffic TCP traffic: 192.168.2.15:38228 -> 91.92.244.58:60195
Source: /tmp/Lj7qNwy54U.elf (PID: 5534) Socket: 127.0.0.1::63841 Jump to behavior
Source: global traffic DNS traffic detected: DNS query: minuoddos.top
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal52.troj.linELF@0/0@1/0
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1185/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3241/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1732/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1730/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1333/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1695/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3235/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3234/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/911/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/515/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/914/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1617/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1615/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/917/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3255/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3253/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1591/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3252/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3251/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3250/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1623/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1588/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3249/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/764/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1585/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3246/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/766/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/800/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/888/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/802/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1509/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/803/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/804/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1867/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1484/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/490/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1514/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1634/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1479/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1875/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/654/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/655/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/656/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/777/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/931/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1595/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/657/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/812/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/779/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/658/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/933/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/418/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/419/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3275/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3274/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3273/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3272/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/782/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1762/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3027/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1486/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/789/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1806/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1660/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3044/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/793/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/794/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/674/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/796/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/675/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/676/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1498/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1497/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1496/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3157/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3278/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1659/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3210/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3298/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3052/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/680/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/681/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3292/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1701/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1666/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3205/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3047/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3201/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/723/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/724/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1704/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1669/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3060/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1440/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3222/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3188/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3220/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3064/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3062/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/3183/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1679/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/850/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1432/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1553/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5541) File opened: /proc/1431/maps Jump to behavior
Source: /tmp/Lj7qNwy54U.elf (PID: 5534) Queries kernel information via 'uname': Jump to behavior
Source: Lj7qNwy54U.elf, 5534.1.0000562a21a21000.0000562a21aa6000.rw-.sdmp, Lj7qNwy54U.elf, 5536.1.0000562a21a21000.0000562a21aa6000.rw-.sdmp, Lj7qNwy54U.elf, 5540.1.0000562a21a21000.0000562a21aa6000.rw-.sdmp Binary or memory string: !*V!/etc/qemu-binfmt/m68k
Source: Lj7qNwy54U.elf, 5534.1.00007ffdcc9c7000.00007ffdcc9e8000.rw-.sdmp, Lj7qNwy54U.elf, 5536.1.00007ffdcc9c7000.00007ffdcc9e8000.rw-.sdmp, Lj7qNwy54U.elf, 5540.1.00007ffdcc9c7000.00007ffdcc9e8000.rw-.sdmp Binary or memory string: Cx86_64/usr/bin/qemu-m68k/tmp/Lj7qNwy54U.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Lj7qNwy54U.elf
Source: Lj7qNwy54U.elf, 5534.1.00007ffdcc9c7000.00007ffdcc9e8000.rw-.sdmp, Lj7qNwy54U.elf, 5536.1.00007ffdcc9c7000.00007ffdcc9e8000.rw-.sdmp, Lj7qNwy54U.elf, 5540.1.00007ffdcc9c7000.00007ffdcc9e8000.rw-.sdmp Binary or memory string: /usr/bin/qemu-m68k
Source: Lj7qNwy54U.elf, 5534.1.0000562a21a21000.0000562a21aa6000.rw-.sdmp, Lj7qNwy54U.elf, 5536.1.0000562a21a21000.0000562a21aa6000.rw-.sdmp, Lj7qNwy54U.elf, 5540.1.0000562a21a21000.0000562a21aa6000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/m68k
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs