Linux Analysis Report
SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf

Overview

General Information

Sample name: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
Analysis ID: 1437704
MD5: eb65fd44f257d54af7a6a90ed87c2d0d
SHA1: ad9ed7c39707d22ec6abdf6047c03736ce5bf5f6
SHA256: 16306ab4a96df149421114e043af688d6e40f61974f642f65756d2251105c9aa
Tags: elf

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
ELF contains segments with high entropy indicating compressed/encrypted content
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf ReversingLabs: Detection: 15%
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal48.linELF@0/0@0/0
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf Submission file: segment LOAD with 7.9644 entropy (max. 8.0)
Source: /tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf (PID: 5527) Queries kernel information via 'uname': Jump to behavior
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.000055c37ec13000.000055c37ec99000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mipsn32
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.000055c37ec13000.000055c37ec99000.rw-.sdmp Binary or memory string: U1MIPS64R2-generic-mips64-cpu1/etc/qemu-binfmt/mipsn32pu
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.00007fff4de37000.00007fff4de58000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mipsn32
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.00007fff4de37000.00007fff4de58000.rw-.sdmp Binary or memory string: rwx86_64/usr/bin/qemu-mipsn32/tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
No contacted IP infos