Loading ...

Play interactive tourEdit tour

Linux Analysis Report ND41FX6xbB

Overview

General Information

Sample Name:ND41FX6xbB
Analysis ID:528752
MD5:12043cc1462a781e9ea20eb5eeb55e5e
SHA1:e4130164d83e593541b6965e28c081bafa618ede
SHA256:f1a4ed45d580688ed0acc2e7e0aabeb44ead0011661b9a1f51fdaaa8b64bb70f
Tags:32armelfmirai
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample is packed with UPX
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Static ELF header machine description suggests that the sample might not execute correctly on this machine
Exit code information suggests that the sample terminated abnormally, try to lookup the sample's target architecture

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:528752
Start date:25.11.2021
Start time:18:33:14
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 2s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:ND41FX6xbB
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal52.evad.lin@0/0@0/0

Process Tree

  • system is lnxubuntu20
  • ND41FX6xbB (PID: 5220, Parent: 5105, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/ND41FX6xbB
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
ND41FX6xbBSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0xce24:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0xce93:$s2: $Id: UPX
  • 0xce44:$s3: $Info: This file is packed with the UPX executable packer

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: ND41FX6xbBVirustotal: Detection: 30%Perma Link
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: ND41FX6xbBString found in binary or memory: http://upx.sf.net
Source: LOAD without section mappingsProgram segment: 0x8000
Source: ND41FX6xbB, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: classification engineClassification label: mal52.evad.lin@0/0@0/0

Data Obfuscation:

barindex
Sample is packed with UPXShow sources
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/ND41FX6xbB (PID: 5220)Queries kernel information via 'uname': Jump to behavior
Source: ND41FX6xbB, 5220.1.00000000f5095392.0000000077bc2f81.rw-.sdmpBinary or memory string: zx86_64/usr/bin/qemu-arm/tmp/ND41FX6xbBSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ND41FX6xbB
Source: ND41FX6xbB, 5220.1.000000008353051a.000000006e463d0a.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: ND41FX6xbB, 5220.1.000000008353051a.000000006e463d0a.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: ND41FX6xbB, 5220.1.00000000f5095392.0000000077bc2f81.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: ND41FX6xbB, 5220.1.00000000f5095392.0000000077bc2f81.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionObfuscated Files or Information1OS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothApplication Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
ND41FX6xbB30%VirustotalBrowse

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netND41FX6xbBfalse
    high

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse


    Runtime Messages

    Command:/tmp/ND41FX6xbB
    Exit Code:139
    Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
    Killed:False
    Standard Output:

    Standard Error:qemu: uncaught target signal 11 (Segmentation fault) - core dumped

    Joe Sandbox View / Context

    IPs

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    109.202.202.202rY6NBuBYivGet hashmaliciousBrowse
      DZhVesq972Get hashmaliciousBrowse
        nOQIiIST3nGet hashmaliciousBrowse
          Ar71Zq4WOlGet hashmaliciousBrowse
            i.5.8.6Get hashmaliciousBrowse
              x.8.6Get hashmaliciousBrowse
                Nkl22sQjFwGet hashmaliciousBrowse
                  m.i.p.sGet hashmaliciousBrowse
                    uKc673FWAMGet hashmaliciousBrowse
                      A7ZUziZ5jxGet hashmaliciousBrowse
                        jTVzI4fJDkGet hashmaliciousBrowse
                          OSGxiHdGIFGet hashmaliciousBrowse
                            a.r.m.v.7.lGet hashmaliciousBrowse
                              a.r.m.v.6.lGet hashmaliciousBrowse
                                m.i.p.s.e.lGet hashmaliciousBrowse
                                  a.r.m.v.5.lGet hashmaliciousBrowse
                                    a.r.m.v.4.lGet hashmaliciousBrowse
                                      i.6.8.6Get hashmaliciousBrowse
                                        2MzNonluPUGet hashmaliciousBrowse
                                          EWUJrwD61IGet hashmaliciousBrowse
                                            91.189.91.43rY6NBuBYivGet hashmaliciousBrowse
                                              DZhVesq972Get hashmaliciousBrowse
                                                nOQIiIST3nGet hashmaliciousBrowse
                                                  Ar71Zq4WOlGet hashmaliciousBrowse
                                                    i.5.8.6Get hashmaliciousBrowse
                                                      x.8.6Get hashmaliciousBrowse
                                                        Nkl22sQjFwGet hashmaliciousBrowse
                                                          m.i.p.sGet hashmaliciousBrowse
                                                            uKc673FWAMGet hashmaliciousBrowse
                                                              A7ZUziZ5jxGet hashmaliciousBrowse
                                                                jTVzI4fJDkGet hashmaliciousBrowse
                                                                  OSGxiHdGIFGet hashmaliciousBrowse
                                                                    a.r.m.v.7.lGet hashmaliciousBrowse
                                                                      a.r.m.v.6.lGet hashmaliciousBrowse
                                                                        m.i.p.s.e.lGet hashmaliciousBrowse
                                                                          a.r.m.v.5.lGet hashmaliciousBrowse
                                                                            a.r.m.v.4.lGet hashmaliciousBrowse
                                                                              i.6.8.6Get hashmaliciousBrowse
                                                                                2MzNonluPUGet hashmaliciousBrowse
                                                                                  EWUJrwD61IGet hashmaliciousBrowse

                                                                                    Domains

                                                                                    No context

                                                                                    ASN

                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                    CANONICAL-ASGBrY6NBuBYivGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    DZhVesq972Get hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    nOQIiIST3nGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    Ar71Zq4WOlGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    i.5.8.6Get hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    x.8.6Get hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    Nkl22sQjFwGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    m.i.p.sGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    uKc673FWAMGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    A7ZUziZ5jxGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    jTVzI4fJDkGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    OSGxiHdGIFGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    a.r.m.v.7.lGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    a.r.m.v.6.lGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    m.i.p.s.e.lGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    a.r.m.v.5.lGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    a.r.m.v.4.lGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    i.6.8.6Get hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    2MzNonluPUGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    EWUJrwD61IGet hashmaliciousBrowse
                                                                                    • 91.189.91.42
                                                                                    INIT7CHrY6NBuBYivGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    DZhVesq972Get hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    nOQIiIST3nGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    Ar71Zq4WOlGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    i.5.8.6Get hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    x.8.6Get hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    Nkl22sQjFwGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    m.i.p.sGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    uKc673FWAMGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    A7ZUziZ5jxGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    jTVzI4fJDkGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    OSGxiHdGIFGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    a.r.m.v.7.lGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    a.r.m.v.6.lGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    m.i.p.s.e.lGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    a.r.m.v.5.lGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    a.r.m.v.4.lGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    i.6.8.6Get hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    2MzNonluPUGet hashmaliciousBrowse
                                                                                    • 109.202.202.202
                                                                                    EWUJrwD61IGet hashmaliciousBrowse
                                                                                    • 109.202.202.202

                                                                                    JA3 Fingerprints

                                                                                    No context

                                                                                    Dropped Files

                                                                                    No context

                                                                                    Created / dropped Files

                                                                                    No created / dropped files found

                                                                                    Static File Info

                                                                                    General

                                                                                    File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, stripped
                                                                                    Entropy (8bit):7.981306555590721
                                                                                    TrID:
                                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                    File name:ND41FX6xbB
                                                                                    File size:54876
                                                                                    MD5:12043cc1462a781e9ea20eb5eeb55e5e
                                                                                    SHA1:e4130164d83e593541b6965e28c081bafa618ede
                                                                                    SHA256:f1a4ed45d580688ed0acc2e7e0aabeb44ead0011661b9a1f51fdaaa8b64bb70f
                                                                                    SHA512:3689790d6be15cfdaf4a6c6eeefeeaa1fb8d7f7edc08fb0e1142867dfafa7ed8c77488f63cdfc50d7d31e6ab2637179ff893c2a8835aa8bc2f9b0680feeb0c09
                                                                                    SSDEEP:1536:5j/3kZTB21uJJ6aZpma9brpEaE//dpUmv1PnLq:2ZTksJ3+ad6aE//d2mdfLq
                                                                                    File Content Preview:.ELF..............(.....0C..4...........4. ...(.........................................D...D...D...................Q.td...............................sUPX!.........6...6......T..........?.E.h;....#..$..1)....v{$\I.rV.i...+1E.........d..[.......S....w.4L1

                                                                                    Static ELF Info

                                                                                    ELF header

                                                                                    Class:ELF32
                                                                                    Data:2's complement, little endian
                                                                                    Version:1 (current)
                                                                                    Machine:ARM
                                                                                    Version Number:0x1
                                                                                    Type:EXEC (Executable file)
                                                                                    OS/ABI:UNIX - Linux
                                                                                    ABI Version:0
                                                                                    Entry Point Address:0x14330
                                                                                    Flags:0x4000002
                                                                                    ELF Header Size:52
                                                                                    Program Header Offset:52
                                                                                    Program Header Size:32
                                                                                    Number of Program Headers:3
                                                                                    Section Header Offset:0
                                                                                    Section Header Size:40
                                                                                    Number of Section Headers:0
                                                                                    Header String Table Index:0

                                                                                    Program Segments

                                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                    LOAD0x00x80000x80000xd51d0xd51d4.02310x5R E0x8000
                                                                                    LOAD0x1c440x41c440x41c440x00x00.00000x6RW 0x8000
                                                                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                                    Network Behavior

                                                                                    Network Port Distribution

                                                                                    TCP Packets

                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                    Nov 25, 2021 18:34:00.420248985 CET42836443192.168.2.2391.189.91.43
                                                                                    Nov 25, 2021 18:34:00.420262098 CET4251680192.168.2.23109.202.202.202
                                                                                    Nov 25, 2021 18:34:16.037431955 CET43928443192.168.2.2391.189.91.42
                                                                                    Nov 25, 2021 18:34:26.278067112 CET42836443192.168.2.2391.189.91.43
                                                                                    Nov 25, 2021 18:34:30.374315977 CET4251680192.168.2.23109.202.202.202
                                                                                    Nov 25, 2021 18:34:57.000123024 CET43928443192.168.2.2391.189.91.42
                                                                                    Nov 25, 2021 18:35:17.481517076 CET42836443192.168.2.2391.189.91.43

                                                                                    System Behavior

                                                                                    General

                                                                                    Start time:18:34:00
                                                                                    Start date:25/11/2021
                                                                                    Path:/tmp/ND41FX6xbB
                                                                                    Arguments:/tmp/ND41FX6xbB
                                                                                    File size:4956856 bytes
                                                                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1