Linux Analysis Report
ATvOcqLo1D.elf

Overview

General Information

Sample name: ATvOcqLo1D.elf
renamed because original name is a hash value
Original sample name: f936eeae81c038c18a30dace4bfb7505.elf
Analysis ID: 1438526
MD5: f936eeae81c038c18a30dace4bfb7505
SHA1: 193abe35791727748cb28d6a2ae8332fa803ddb1
SHA256: 3dd9416be6531584186df5a14bc0fd51be79dfeeaec1b100b24f53df9309bdb8
Tags: 32armelfmirai
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: ATvOcqLo1D.elf ReversingLabs: Detection: 57%

Networking

barindex
Source: global traffic TCP traffic: 91.92.244.58 ports 0,1,5,6,9,60195
Source: global traffic TCP traffic: 192.168.2.23:54928 -> 91.92.244.58:60195
Source: /tmp/ATvOcqLo1D.elf (PID: 6211) Socket: 127.0.0.1::63841 Jump to behavior
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: global traffic DNS traffic detected: DNS query: minuoddos.top
Source: unknown Network traffic detected: HTTP traffic on port 39244 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39244
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 33608 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal52.troj.linELF@0/0@1/0
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1582/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2033/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1612/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1579/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1699/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1335/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1698/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2028/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1334/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1576/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2025/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2146/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/910/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/912/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/517/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/759/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/918/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1594/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1349/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1623/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/761/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1622/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/884/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1983/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2038/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1344/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1465/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1586/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1860/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1463/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2156/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/800/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/801/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1629/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1627/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1900/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/491/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2050/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1877/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/772/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1633/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1599/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1632/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/774/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1477/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/654/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/896/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1476/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1872/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2048/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/655/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1475/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/656/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/777/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/657/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/658/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/419/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/936/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1639/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1638/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2180/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1809/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1494/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1890/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2063/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2062/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1888/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1886/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/420/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1489/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/785/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1642/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/788/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/667/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/789/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1648/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2078/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2077/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2074/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/670/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/793/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1656/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1654/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/674/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1532/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/796/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/675/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/797/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/676/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/677/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2069/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2102/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/799/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2080/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2084/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2083/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1668/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1664/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1389/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/720/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2114/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/721/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/1661/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/2079/maps Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6218) File opened: /proc/847/maps Jump to behavior
Source: /usr/bin/dash (PID: 6286) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.B9Tw0HsgJh /tmp/tmp.kHyRMWeAzR /tmp/tmp.ChHck7QHtr Jump to behavior
Source: /usr/bin/dash (PID: 6287) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.B9Tw0HsgJh /tmp/tmp.kHyRMWeAzR /tmp/tmp.ChHck7QHtr Jump to behavior
Source: /tmp/ATvOcqLo1D.elf (PID: 6211) Queries kernel information via 'uname': Jump to behavior
Source: ATvOcqLo1D.elf, 6211.1.000055e42bb7f000.000055e42bcad000.rw-.sdmp, ATvOcqLo1D.elf, 6213.1.000055e42bb7f000.000055e42bcad000.rw-.sdmp, ATvOcqLo1D.elf, 6216.1.000055e42bb7f000.000055e42bcad000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: ATvOcqLo1D.elf, 6211.1.000055e42bb7f000.000055e42bcad000.rw-.sdmp, ATvOcqLo1D.elf, 6213.1.000055e42bb7f000.000055e42bcad000.rw-.sdmp, ATvOcqLo1D.elf, 6216.1.000055e42bb7f000.000055e42bcad000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: ATvOcqLo1D.elf, 6211.1.00007ffe3c348000.00007ffe3c369000.rw-.sdmp, ATvOcqLo1D.elf, 6213.1.00007ffe3c348000.00007ffe3c369000.rw-.sdmp, ATvOcqLo1D.elf, 6216.1.00007ffe3c348000.00007ffe3c369000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: ATvOcqLo1D.elf, 6211.1.00007ffe3c348000.00007ffe3c369000.rw-.sdmp, ATvOcqLo1D.elf, 6213.1.00007ffe3c348000.00007ffe3c369000.rw-.sdmp, ATvOcqLo1D.elf, 6216.1.00007ffe3c348000.00007ffe3c369000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/ATvOcqLo1D.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ATvOcqLo1D.elf
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs