Linux Analysis Report
y0LFA0bJoY.elf

Overview

General Information

Sample name: y0LFA0bJoY.elf
renamed because original name is a hash value
Original sample name: f44166e1605f80c974c8300b425b349b.elf
Analysis ID: 1438525
MD5: f44166e1605f80c974c8300b425b349b
SHA1: 62df2cad1ea41ce37797221bb2534822b02f722a
SHA256: c0f31144e9664f473f04e24352bc08d52a7271073a52b63a1981edb5d8050eb3
Tags: 32armelfmirai
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: y0LFA0bJoY.elf ReversingLabs: Detection: 60%
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal48.linELF@0/0@2/0
Source: /tmp/y0LFA0bJoY.elf (PID: 5490) Queries kernel information via 'uname': Jump to behavior
Source: y0LFA0bJoY.elf, 5490.1.000055564db06000.000055564dc34000.rw-.sdmp Binary or memory string: MVU!/etc/qemu-binfmt/arm
Source: y0LFA0bJoY.elf, 5490.1.00007ffe3f5ba000.00007ffe3f5db000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/y0LFA0bJoY.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/y0LFA0bJoY.elf
Source: y0LFA0bJoY.elf, 5490.1.00007ffe3f5ba000.00007ffe3f5db000.rw-.sdmp Binary or memory string: qemu: %s: %s
Source: y0LFA0bJoY.elf, 5490.1.000055564db06000.000055564dc34000.rw-.sdmp Binary or memory string: MVUrg.qemu.gdb.arm.sys.regs">
Source: y0LFA0bJoY.elf, 5490.1.00007ffe3f5ba000.00007ffe3f5db000.rw-.sdmp Binary or memory string: leqemu: %s: %s
Source: y0LFA0bJoY.elf, 5490.1.000055564db06000.000055564dc34000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: y0LFA0bJoY.elf, 5490.1.00007ffe3f5ba000.00007ffe3f5db000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: y0LFA0bJoY.elf, 5490.1.000055564db06000.000055564dc34000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
No contacted IP infos