Source: 4wA5neDGrq |
Virustotal: Detection: 59% |
Perma Link |
Source: 4wA5neDGrq |
ReversingLabs: Detection: 61% |
Source: motd-news.15.dr |
String found in binary or memory: https://ubuntu.com/blog/microk8s-memory-optimisation |
Source: ELF static info symbol of initial sample |
FILE: /home/landley/work/ab7/build/temp-armv6l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/landley/work/ab7/build/temp-armv6l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/landley/work/ab7/build/temp-armv6l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/landley/work/ab7/build/temp-armv6l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/landley/work/ab7/build/temp-armv6l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/landley/work/ab7/build/temp-armv6l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/landley/work/ab7/build/temp-armv6l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: classification engine |
Classification label: mal56.lin@0/1@0/0 |
Source: 4wA5neDGrq |
Joe Sandbox Cloud Basic: Detection: clean Score: 0 |
Perma Link |
Source: /usr/bin/dash (PID: 5212) |
Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.USJYxzaCuE /tmp/tmp.T3hUP4mjcM /tmp/tmp.wRaDNMdR2W |
Jump to behavior |
Source: /tmp/4wA5neDGrq (PID: 5263) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: 4wA5neDGrq, 5263.1.00000000cc99f7b8.0000000039f489a9.rw-.sdmp |
Binary or memory string: O}x86_64/usr/bin/qemu-arm/tmp/4wA5neDGrqSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/4wA5neDGrq |
Source: 4wA5neDGrq, 5263.1.00000000e42f88d3.0000000003b9e0e5.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: 4wA5neDGrq, 5263.1.00000000e42f88d3.0000000003b9e0e5.rw-.sdmp |
Binary or memory string: V!/etc/qemu-binfmt/arm |
Source: 4wA5neDGrq, 5263.1.00000000cc99f7b8.0000000039f489a9.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |