Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf

Overview

General Information

Sample name:SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
Analysis ID:1437704
MD5:eb65fd44f257d54af7a6a90ed87c2d0d
SHA1:ad9ed7c39707d22ec6abdf6047c03736ce5bf5f6
SHA256:16306ab4a96df149421114e043af688d6e40f61974f642f65756d2251105c9aa
Tags:elf

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
ELF contains segments with high entropy indicating compressed/encrypted content
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1437704
Start date and time:2024-05-07 20:26:21 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
  • VT rate limit hit for: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
Command:/tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
PID:5527
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/lib32/ld.so.1: No such file or directory
  • system is lnxubuntu20
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elfReversingLabs: Detection: 15%
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elfSubmission file: segment LOAD with 7.9644 entropy (max. 8.0)
Source: /tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf (PID: 5527)Queries kernel information via 'uname': Jump to behavior
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.000055c37ec13000.000055c37ec99000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsn32
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.000055c37ec13000.000055c37ec99000.rw-.sdmpBinary or memory string: U1MIPS64R2-generic-mips64-cpu1/etc/qemu-binfmt/mipsn32pu
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.00007fff4de37000.00007fff4de58000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsn32
Source: SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf, 5527.1.00007fff4de37000.00007fff4de58000.rw-.sdmpBinary or memory string: rwx86_64/usr/bin/qemu-mipsn32/tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf16%ReversingLabsLinux.Trojan.Generic
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
No context
No context
No context
No context
No context
No created / dropped files found
File type:ELF 32-bit MSB executable, MIPS, N32 MIPS64 rel2 version 1 (SYSV), dynamically linked, interpreter /lib32/ld.so.1, for GNU/Linux 2.6.16, stripped
Entropy (8bit):7.025729760944969
TrID:
  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
File name:SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
File size:51'108 bytes
MD5:eb65fd44f257d54af7a6a90ed87c2d0d
SHA1:ad9ed7c39707d22ec6abdf6047c03736ce5bf5f6
SHA256:16306ab4a96df149421114e043af688d6e40f61974f642f65756d2251105c9aa
SHA512:98b9e6691b330d5862bde0009811c76be1522561aa9f202436ba0f984547f0c95d987e5732e7bf8a5e10d3160b793207f8020d52e3d7504641479a98cb0f5cdd
SSDEEP:768:xqoqtJl83+ALmnd635H/MuCewKlKERQSrw4xyqn7la97xbznScNdGfQ2JrYaI:xv8h4SsGGlFeSrPx2lZS8UF2F
TLSH:66338C03FA4BDC1EF9AB4B7AD4E3837046D132862BF3C196BC25B68EAC553C416A5D41
File Content Preview:.ELF...........................4...D...'.4. ...(...........4...4...4.......................4...4...4................p......h...h...h..................................lT..lT..............lT..lT..lT..R4..R\...............................................D...

ELF header

Class:ELF32
Data:2's complement, big endian
Version:1 (current)
Machine:MIPS R3000
Version Number:0x1
Type:EXEC (Executable file)
OS/ABI:UNIX - System V
ABI Version:0
Entry Point Address:0x10000bc0
Flags:0x80000027
ELF Header Size:52
Program Header Offset:52
Program Header Size:32
Number of Program Headers:8
Section Header Offset:49988
Section Header Size:40
Number of Section Headers:28
Header String Table Index:27
NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
NULL0x00x00x00x00x0000
.interpPROGBITS0x100001340x1340xf0x00x2A001
.note.ABI-tagNOTE0x100001440x1440x200x00x2A004
.reginfoMIPS_REGINFO0x100001680x1680x180x180x2A008
.dynamicDYNAMIC0x100001800x1800xe00x80x2A704
.hashHASH0x100002600x2600xe00x40x2A604
.dynsymDYNSYM0x100003400x3400x2500x100x2A714
.dynstrSTRTAB0x100005900x5900x1610x00x2A001
.gnu.versionVERSYM0x100006f20x6f20x4a0x20x2A602
.gnu.version_rVERNEED0x1000073c0x73c0x300x00x2A714
.initPROGBITS0x1000076c0x76c0x800x00x6AX004
.textPROGBITS0x100007f00x7f00x56200x00x6AX0016
.MIPS.stubsPROGBITS0x10005e100x5e100x1600x00x6AX004
.finiPROGBITS0x10005f700x5f700x480x00x6AX004
.rodataPROGBITS0x10005fc00x5fc00xc900x00x2A0016
.eh_framePROGBITS0x10006c500x6c500x40x00x2A004
.ctorsPROGBITS0x10016c540x6c540x80x00x3WA004
.dtorsPROGBITS0x10016c5c0x6c5c0x80x00x3WA004
.jcrPROGBITS0x10016c640x6c640x40x00x3WA004
.dataPROGBITS0x10016c700x6c700x51600x00x3WA0016
.rld_mapPROGBITS0x1001bdd00xbdd00x40x00x3WA004
.gotPROGBITS0x1001bde00xbde00xa40x40x10000003WAp0016
.sdataPROGBITS0x1001be840xbe840x40x00x10000003WAp004
.bssNOBITS0x1001be900xbe880x200x00x3WA0016
.pdrPROGBITS0x00xbe880x3a00x00x0004
.commentPROGBITS0x00xc2280x230x10x30MS001
.gnu.attributesGNU_ATTRIBUTES0x00xc24b0x100x00x0001
.shstrtabSTRTAB0x00xc25b0xe60x00x0001
TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
PHDR0x340x100000340x100000340x1000x1002.24310x5R E0x4
INTERP0x1340x100001340x100001340xf0xf3.50690x4R 0x1/lib32/ld.so.1.interp
<unknown>0x1680x100001680x100001680x180x181.68970x4R 0x8.reginfo
LOAD0x00x100000000x100000000x6c540x6c545.83450x5R E0x10000.interp .note.ABI-tag .reginfo .dynamic .hash .dynsym .dynstr .gnu.version .gnu.version_r .init .text .MIPS.stubs .fini .rodata .eh_frame
LOAD0x6c540x10016c540x10016c540x52340x525c7.96440x6RW 0x10000.ctors .dtors .jcr .data .rld_map .got .sdata .bss
DYNAMIC0x1800x100001800x100001800xe00xe02.64820x7RWE0x4.dynamic
NOTE0x1440x100001440x100001440x200x201.68620x4R 0x4.note.ABI-tag
NULL0x00x00x00x00x00.00000x0 0x4
TypeMetaValueTag
DT_NEEDEDsharedliblibdl.so.20x1
DT_NEEDEDsharedliblibc.so.60x1
DT_INITvalue0x1000076c0xc
DT_FINIvalue0x10005f700xd
DT_HASHvalue0x100002600x4
DT_STRTABvalue0x100005900x5
DT_SYMTABvalue0x100003400x6
DT_STRSZbytes3530xa
DT_SYMENTbytes160xb
DT_MIPS_RLD_MAPvalue0x1001bdd00x70000016
DT_DEBUGvalue0x00x15
DT_PLTGOTvalue0x1001bde00x3
DT_MIPS_RLD_VERSIONvalue0x10x70000001
DT_MIPS_FLAGSvalue0x20x70000005
DT_MIPS_BASE_ADDRESSvalue0x100000000x70000006
DT_MIPS_LOCAL_GOTNOvalue0xd0x7000000a
DT_MIPS_SYMTABNOvalue0x250x70000011
DT_MIPS_UNREFEXTNOvalue0x1b0x70000012
DT_MIPS_GOTSYMvalue0x90x70000013
DT_VERNEEDvalue0x1000073c0x6ffffffe
DT_VERNEEDNUMvalue10x6fffffff
DT_VERSYMvalue0x100006f20x6ffffff0
DT_NULLvalue0x00x0
NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
_DYNAMIC_LINKING.dynsym0x10SECTION<unknown>DEFAULTSHN_ABS
_IO_stdin_used.dynsym0x10005fc04OBJECT<unknown>DEFAULT14
_ITM_deregisterTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
_ITM_registerTMCloneTable.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
_Jv_RegisterClasses.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
__RLD_MAP.dynsym0x1001bdd00OBJECT<unknown>DEFAULT20
__gmon_start__.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
__libc_csu_fini.dynsym0x10005d888FUNC<unknown>DEFAULT11
__libc_csu_init.dynsym0x10005ce0168FUNC<unknown>DEFAULT11
__libc_start_mainGLIBC_2.0libc.so.6.dynsym0x10005e700FUNC<unknown>DEFAULTSHN_UNDEF
__xstatGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
_exitGLIBC_2.0libc.so.6.dynsym0x10005e900FUNC<unknown>DEFAULTSHN_UNDEF
_init.dynsym0x1000076c0FUNC<unknown>DEFAULT10
chmodGLIBC_2.0libc.so.6.dynsym0x10005ea00FUNC<unknown>DEFAULTSHN_UNDEF
closeGLIBC_2.0libc.so.6.dynsym0x10005f100FUNC<unknown>DEFAULTSHN_UNDEF
dup2GLIBC_2.0libc.so.6.dynsym0x10005ec00FUNC<unknown>DEFAULTSHN_UNDEF
execlGLIBC_2.0libc.so.6.dynsym0x10005e800FUNC<unknown>DEFAULTSHN_UNDEF
exitGLIBC_2.0libc.so.6.dynsym0x10005f500FUNC<unknown>DEFAULTSHN_UNDEF
fcloseGLIBC_2.2libc.so.6.dynsym0x10005ee00FUNC<unknown>DEFAULTSHN_UNDEF
fopenGLIBC_2.2libc.so.6.dynsym0x10005f400FUNC<unknown>DEFAULTSHN_UNDEF
forkGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
freeGLIBC_2.0libc.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
fwriteGLIBC_2.0libc.so.6.dynsym0x10005f200FUNC<unknown>DEFAULTSHN_UNDEF
main.dynsym0x100007f0968FUNC<unknown>HIDDEN11
mallocGLIBC_2.0libc.so.6.dynsym0x10005f300FUNC<unknown>DEFAULTSHN_UNDEF
memcpyGLIBC_2.0libc.so.6.dynsym0x10005ef00FUNC<unknown>DEFAULTSHN_UNDEF
memsetGLIBC_2.0libc.so.6.dynsym0x10005e500FUNC<unknown>DEFAULTSHN_UNDEF
openGLIBC_2.0libc.so.6.dynsym0x10005e100FUNC<unknown>DEFAULTSHN_UNDEF
reallocGLIBC_2.0libc.so.6.dynsym0x10005e300FUNC<unknown>DEFAULTSHN_UNDEF
setsidGLIBC_2.0libc.so.6.dynsym0x10005e600FUNC<unknown>DEFAULTSHN_UNDEF
signalGLIBC_2.0libc.so.6.dynsym0x10005e200FUNC<unknown>DEFAULTSHN_UNDEF
stat.dynsym0x10005d9036FUNC<unknown>HIDDEN11
systemGLIBC_2.0libc.so.6.dynsym0x10005e400FUNC<unknown>DEFAULTSHN_UNDEF
umaskGLIBC_2.0libc.so.6.dynsym0x10005ed00FUNC<unknown>DEFAULTSHN_UNDEF
unlinkGLIBC_2.0libc.so.6.dynsym0x10005f000FUNC<unknown>DEFAULTSHN_UNDEF
wait4GLIBC_2.0libc.so.6.dynsym0x10005eb00FUNC<unknown>DEFAULTSHN_UNDEF
No network behavior found

System Behavior

Start time (UTC):18:27:04
Start date (UTC):07/05/2024
Path:/tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
Arguments:/tmp/SecuriteInfo.com.ELF.Agent-BXR.25799.9458.elf
File size:5834552 bytes
MD5 hash:3c9c1d5c72f067b06010ef4c7ad2bc48