Linux Analysis Report
520VcHQQj7.elf

Overview

General Information

Sample name: 520VcHQQj7.elf
renamed because original name is a hash value
Original sample name: b63e82fe3c5aa94bdd7fc89340615d58.elf
Analysis ID: 1430900
MD5: b63e82fe3c5aa94bdd7fc89340615d58
SHA1: d02619bcf1a5a535e7d68852b14c209d376b39a6
SHA256: ad914622f916beefa859533229a609e4cd16aeea0907959d717aa7405eec92b3
Tags: 32armelfgafgyt
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: 520VcHQQj7.elf Avira: detected
Source: 520VcHQQj7.elf ReversingLabs: Detection: 47%
Source: 520VcHQQj7.elf Virustotal: Detection: 54% Perma Link
Source: unknown TCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39242
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 33608 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 39242 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 6277) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.VvlajSV6vl /tmp/tmp.ifOWL5gyno /tmp/tmp.8UBmpxyLbq Jump to behavior
Source: /usr/bin/dash (PID: 6278) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.VvlajSV6vl /tmp/tmp.ifOWL5gyno /tmp/tmp.8UBmpxyLbq Jump to behavior
Source: /tmp/520VcHQQj7.elf (PID: 6215) Queries kernel information via 'uname': Jump to behavior
Source: 520VcHQQj7.elf, 6215.1.00007ffc5f27f000.00007ffc5f2a0000.rw-.sdmp Binary or memory string: qemu: %s: %s
Source: 520VcHQQj7.elf, 6215.1.00007ffc5f27f000.00007ffc5f2a0000.rw-.sdmp Binary or memory string: leqemu: %s: %s
Source: 520VcHQQj7.elf, 6215.1.0000560daf661000.0000560daf78f000.rw-.sdmp Binary or memory string: Vrg.qemu.gdb.arm.sys.regs">
Source: 520VcHQQj7.elf, 6215.1.0000560daf661000.0000560daf78f000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: 520VcHQQj7.elf, 6215.1.00007ffc5f27f000.00007ffc5f2a0000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: 520VcHQQj7.elf, 6215.1.0000560daf661000.0000560daf78f000.rw-.sdmp Binary or memory string: V!/etc/qemu-binfmt/arm
Source: 520VcHQQj7.elf, 6215.1.0000560daf661000.0000560daf78f000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
Source: 520VcHQQj7.elf, 6215.1.00007ffc5f27f000.00007ffc5f2a0000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/520VcHQQj7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/520VcHQQj7.elf
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs