Edit tour

Linux Analysis Report
SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf

Overview

General Information

Sample Name:SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf
Analysis ID:1275430
MD5:2f6409ac30ccc8ae7dcce576a05422a4
SHA1:0eb6663f5839715a9632efc0b1e5d6d78ab031c1
SHA256:3ceecfa55ff8ab8eeb0d99d8a84a7cace26e4bb5f20b3ec8f710bdb4647d97ef
Tags:elf
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false

Signatures

Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Sample has stripped symbol table

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

Analysis Advice

Static ELF header type description suggests that the sample is a shared object file and not-self-executable.
Exit code information suggests that the sample terminated abnormally, try to lookup the sample's target architecture.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Non-zero exit code suggests an error during the execution. Lookup the error code for hints.
Joe Sandbox Version:38.0.0 Beryl
Analysis ID:1275430
Start date and time:2023-07-18 21:15:15 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 4s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample file name:SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf
Detection:CLEAN
Classification:clean1.linELF@0/0@0/0
Command:/tmp/SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf
PID:6227
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elfString found in binary or memory: https://android.googlesource.com/toolchain/llvm-project
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: clean1.linELF@0/0@0/0
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1275430 Sample: SecuriteInfo.com.HEUR.Troja... Startdate: 18/07/2023 Architecture: LINUX Score: 1 7 109.202.202.202, 80 INIT7CH Switzerland 2->7 9 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->9 11 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->11 5 SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf 2->5         started        process3
SourceDetectionScannerLabelLink
SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf0%ReversingLabs
SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://android.googlesource.com/toolchain/llvm-projectSecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202ryidtyjrhGet hashmaliciousUnknownBrowse
      mimic_mipselGet hashmaliciousUnknownBrowse
        mimic_mipsGet hashmaliciousUnknownBrowse
          magicPussyMommyGet hashmaliciousXmrigBrowse
            attachment_1.htmlGet hashmaliciousHTMLPhisherBrowse
              nKLjpwdv4s.elfGet hashmaliciousUnknownBrowse
                VtBcEl7kKl.elfGet hashmaliciousMiraiBrowse
                  ILl7GFCusO.elfGet hashmaliciousMiraiBrowse
                    zbqOo5tVlw.elfGet hashmaliciousMiraiBrowse
                      TpA5RHesL2.elfGet hashmaliciousUnknownBrowse
                        4Zg3b62KL3.elfGet hashmaliciousUnknownBrowse
                          1d2H0YpA0D.elfGet hashmaliciousMiraiBrowse
                            XXwtisfd64.elfGet hashmaliciousMiraiBrowse
                              b.elfGet hashmaliciousUnknownBrowse
                                hlUZhl7Es2.elfGet hashmaliciousUnknownBrowse
                                  SecuriteInfo.com.Heur.20230717142745921918488.elfGet hashmaliciousUnknownBrowse
                                    hpon9AoPXX.elfGet hashmaliciousUnknownBrowse
                                      pnbQzgH4l3.elfGet hashmaliciousUnknownBrowse
                                        nKVRdnEQnN.elfGet hashmaliciousMiraiBrowse
                                          94KDY0DkCh.elfGet hashmaliciousUnknownBrowse
                                            91.189.91.43ryidtyjrhGet hashmaliciousUnknownBrowse
                                              mimic_mipselGet hashmaliciousUnknownBrowse
                                                mimic_mipsGet hashmaliciousUnknownBrowse
                                                  magicPussyMommyGet hashmaliciousXmrigBrowse
                                                    attachment_1.htmlGet hashmaliciousHTMLPhisherBrowse
                                                      nKLjpwdv4s.elfGet hashmaliciousUnknownBrowse
                                                        VtBcEl7kKl.elfGet hashmaliciousMiraiBrowse
                                                          ILl7GFCusO.elfGet hashmaliciousMiraiBrowse
                                                            zbqOo5tVlw.elfGet hashmaliciousMiraiBrowse
                                                              TpA5RHesL2.elfGet hashmaliciousUnknownBrowse
                                                                4Zg3b62KL3.elfGet hashmaliciousUnknownBrowse
                                                                  1d2H0YpA0D.elfGet hashmaliciousMiraiBrowse
                                                                    XXwtisfd64.elfGet hashmaliciousMiraiBrowse
                                                                      b.elfGet hashmaliciousUnknownBrowse
                                                                        hlUZhl7Es2.elfGet hashmaliciousUnknownBrowse
                                                                          SecuriteInfo.com.Heur.20230717142745921918488.elfGet hashmaliciousUnknownBrowse
                                                                            hpon9AoPXX.elfGet hashmaliciousUnknownBrowse
                                                                              pnbQzgH4l3.elfGet hashmaliciousUnknownBrowse
                                                                                nKVRdnEQnN.elfGet hashmaliciousMiraiBrowse
                                                                                  94KDY0DkCh.elfGet hashmaliciousUnknownBrowse
                                                                                    No context
                                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                    CANONICAL-ASGBryidtyjrhGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    mimic_mipselGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    mimic_mipsGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    magicPussyMommyGet hashmaliciousXmrigBrowse
                                                                                    • 91.189.91.42
                                                                                    attachment_1.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                    • 91.189.91.42
                                                                                    nKLjpwdv4s.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    VtBcEl7kKl.elfGet hashmaliciousMiraiBrowse
                                                                                    • 91.189.91.42
                                                                                    ILl7GFCusO.elfGet hashmaliciousMiraiBrowse
                                                                                    • 91.189.91.42
                                                                                    zbqOo5tVlw.elfGet hashmaliciousMiraiBrowse
                                                                                    • 91.189.91.42
                                                                                    TpA5RHesL2.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    4Zg3b62KL3.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    1d2H0YpA0D.elfGet hashmaliciousMiraiBrowse
                                                                                    • 91.189.91.42
                                                                                    XXwtisfd64.elfGet hashmaliciousMiraiBrowse
                                                                                    • 91.189.91.42
                                                                                    b.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    hlUZhl7Es2.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    SecuriteInfo.com.Heur.20230717142745921918488.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    hpon9AoPXX.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    pnbQzgH4l3.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    nKVRdnEQnN.elfGet hashmaliciousMiraiBrowse
                                                                                    • 91.189.91.42
                                                                                    94KDY0DkCh.elfGet hashmaliciousUnknownBrowse
                                                                                    • 91.189.91.42
                                                                                    INIT7CHryidtyjrhGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    mimic_mipselGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    mimic_mipsGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    magicPussyMommyGet hashmaliciousXmrigBrowse
                                                                                    • 109.202.202.202
                                                                                    attachment_1.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                    • 109.202.202.202
                                                                                    nKLjpwdv4s.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    VtBcEl7kKl.elfGet hashmaliciousMiraiBrowse
                                                                                    • 109.202.202.202
                                                                                    ILl7GFCusO.elfGet hashmaliciousMiraiBrowse
                                                                                    • 109.202.202.202
                                                                                    zbqOo5tVlw.elfGet hashmaliciousMiraiBrowse
                                                                                    • 109.202.202.202
                                                                                    TpA5RHesL2.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    4Zg3b62KL3.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    1d2H0YpA0D.elfGet hashmaliciousMiraiBrowse
                                                                                    • 109.202.202.202
                                                                                    XXwtisfd64.elfGet hashmaliciousMiraiBrowse
                                                                                    • 109.202.202.202
                                                                                    b.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    hlUZhl7Es2.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    SecuriteInfo.com.Heur.20230717142745921918488.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    hpon9AoPXX.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    pnbQzgH4l3.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    nKVRdnEQnN.elfGet hashmaliciousMiraiBrowse
                                                                                    • 109.202.202.202
                                                                                    94KDY0DkCh.elfGet hashmaliciousUnknownBrowse
                                                                                    • 109.202.202.202
                                                                                    No context
                                                                                    No context
                                                                                    No created / dropped files found
                                                                                    File type:ELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=739b3df0d77e91bd42e1b2e5a8f48269dde58829, stripped
                                                                                    Entropy (8bit):3.499595743264743
                                                                                    TrID:
                                                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                    File name:SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf
                                                                                    File size:9'660 bytes
                                                                                    MD5:2f6409ac30ccc8ae7dcce576a05422a4
                                                                                    SHA1:0eb6663f5839715a9632efc0b1e5d6d78ab031c1
                                                                                    SHA256:3ceecfa55ff8ab8eeb0d99d8a84a7cace26e4bb5f20b3ec8f710bdb4647d97ef
                                                                                    SHA512:d1bdff5403d784b729da35c569f1b9f4c0c655b5c30ade76318de43d992735edb49a96d5781c76f28122893073c79f5ac67700efb0fc3bb58da0842c96a479c7
                                                                                    SSDEEP:96:+AKPDPdyZX3Qa/eyVfl87lBHW8KOFLCL4ewyEA4z/sEsj7hmx0eTXQV:pePdyZX3QgeyVfsJjTFC40/4rIhg
                                                                                    TLSH:46129307FB41C633E899127D588B433ACA36C954D3A387437A0CF64D7DB13A89B8325A
                                                                                    File Content Preview:.ELF........................4....!......4. ...(.........4...4...4...................................................................t...t...............................................4...4...4...................P.td`...`...`...D...D...........Q.td.......

                                                                                    ELF header

                                                                                    Class:
                                                                                    Data:
                                                                                    Version:
                                                                                    Machine:
                                                                                    Version Number:
                                                                                    Type:
                                                                                    OS/ABI:
                                                                                    ABI Version:
                                                                                    Entry Point Address:
                                                                                    Flags:
                                                                                    ELF Header Size:
                                                                                    Program Header Offset:
                                                                                    Program Header Size:
                                                                                    Number of Program Headers:
                                                                                    Section Header Offset:
                                                                                    Section Header Size:
                                                                                    Number of Section Headers:
                                                                                    Header String Table Index:
                                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                    NULL0x00x00x00x00x0000
                                                                                    .note.android.identNOTE0x1340x1340x980x00x2A002
                                                                                    .note.gnu.build-idNOTE0x1cc0x1cc0x240x00x2A004
                                                                                    .dynsymDYNSYM0x1f00x1f00x1800x100x2A414
                                                                                    .dynstrSTRTAB0x3700x3700x1590x00x2A001
                                                                                    .gnu.hashGNU_HASH0x4cc0x4cc0x480x40x2A304
                                                                                    .hashHASH0x5140x5140xac0x40x2A304
                                                                                    .gnu.versionVERSYM0x5c00x5c00x300x20x2A302
                                                                                    .gnu.version_dVERDEF0x5f00x5f00x1c0x00x2A414
                                                                                    .gnu.version_rVERNEED0x60c0x60c0x200x00x2A414
                                                                                    .rel.dynREL0x62c0x62c0x200x80x2A304
                                                                                    .rel.pltREL0x64c0x64c0x800x80x42AI3214
                                                                                    .pltPROGBITS0x6d00x6d00x1100x40x6AX0016
                                                                                    .textPROGBITS0x7e00x7e00x66c0x00x6AX0016
                                                                                    .rodataPROGBITS0xe4c0xe4c0xd70x10x32AMS001
                                                                                    .eh_framePROGBITS0xf240xf240x13c0x00x2A004
                                                                                    .eh_frame_hdrPROGBITS0x10600x10600x440x00x2A004
                                                                                    .data.rel.roPROGBITS0x2e8c0x1e8c0x40x00x3WA004
                                                                                    .fini_arrayFINI_ARRAY0x2e900x1e900x80x40x3WA004
                                                                                    .dynamicDYNAMIC0x2e980x1e980x1180x80x3WA404
                                                                                    .gotPROGBITS0x2fb00x1fb00x40x00x3WA004
                                                                                    .got.pltPROGBITS0x2fb40x1fb40x4c0x00x3WA004
                                                                                    .commentPROGBITS0x00x20000xb60x10x30MS001
                                                                                    .note.gnu.gold-versionNOTE0x00x20b80x1c0x00x0004
                                                                                    .shstrtabSTRTAB0x00x20d40xff0x00x0001
                                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                    PHDR0x340x340x340x1000x1002.32770x4R 0x4
                                                                                    LOAD0x00x00x00x10a40x10a45.34370x5R E0x1000.note.android.ident .note.gnu.build-id .dynsym .dynstr .gnu.hash .hash .gnu.version .gnu.version_d .gnu.version_r .rel.dyn .rel.plt .plt .text .rodata .eh_frame .eh_frame_hdr
                                                                                    LOAD0x1e8c0x2e8c0x2e8c0x1740x1742.88460x6RW 0x1000.data.rel.ro .fini_array .dynamic .got .got.plt
                                                                                    DYNAMIC0x1e980x2e980x2e980x1180x1182.60080x6RW 0x4.dynamic
                                                                                    NOTE0x1340x1340x1340xbc0xbc2.16710x4R 0x4.note.android.ident .note.gnu.build-id
                                                                                    GNU_EH_FRAME0x10600x10600x10600x440x443.10400x4R 0x4.eh_frame_hdr
                                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                                    GNU_RELRO0x1e8c0x2e8c0x2e8c0x1740x1742.88460x6RW 0x4.data.rel.ro .fini_array .dynamic .got .got.plt
                                                                                    TypeMetaValueTag
                                                                                    DT_PLTGOTvalue0x2fb40x3
                                                                                    DT_PLTRELSZbytes1280x2
                                                                                    DT_JMPRELvalue0x64c0x17
                                                                                    DT_PLTRELpltrelDT_REL0x14
                                                                                    DT_RELvalue0x62c0x11
                                                                                    DT_RELSZbytes320x12
                                                                                    DT_RELENTbytes80x13
                                                                                    DT_RELCOUNTvalue30x6ffffffa
                                                                                    DT_SYMTABvalue0x1f00x6
                                                                                    DT_SYMENTbytes160xb
                                                                                    DT_STRTABvalue0x3700x5
                                                                                    DT_STRSZbytes3450xa
                                                                                    DT_GNU_HASHvalue0x4cc0x6ffffef5
                                                                                    DT_HASHvalue0x5140x4
                                                                                    DT_NEEDEDsharedlibliblog.so0x1
                                                                                    DT_NEEDEDsharedliblibc.so0x1
                                                                                    DT_NEEDEDsharedliblibm.so0x1
                                                                                    DT_NEEDEDsharedliblibstdc++.so0x1
                                                                                    DT_NEEDEDsharedliblibdl.so0x1
                                                                                    DT_SONAMEsonamelibrska.so0xe
                                                                                    DT_FINI_ARRAYvalue0x2e900x1a
                                                                                    DT_FINI_ARRAYSZbytes80x1c
                                                                                    DT_FLAGSvalue0x80x1e
                                                                                    DT_FLAGS_1value0x10x6ffffffb
                                                                                    DT_VERSYMvalue0x5c00x6ffffff0
                                                                                    DT_VERDEFvalue0x5f00x6ffffffc
                                                                                    DT_VERDEFNUMvalue10x6ffffffd
                                                                                    DT_VERNEEDvalue0x60c0x6ffffffe
                                                                                    DT_VERNEEDNUMvalue10x6fffffff
                                                                                    DT_NULLvalue0x00x0
                                                                                    NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                                    .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                    Java_cn_rs_keepalive_NativeWatcher_startWatch.dynsym0xc50505FUNC<unknown>DEFAULT13
                                                                                    __android_log_print.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    __bss_start.dynsym0x30000NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                    __cxa_atexitLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    __cxa_finalizeLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    __stack_chk_failLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    __stack_chk_guardLIBClibc.so.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                                    _edata.dynsym0x30000NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                    _end.dynsym0x30000NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                    do_daemon.dynsym0xa40390FUNC<unknown>DEFAULT13
                                                                                    exitLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    flockLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    forkLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    java_callback.dynsym0x9e091FUNC<unknown>DEFAULT13
                                                                                    lock_file.dynsym0x930161FUNC<unknown>DEFAULT13
                                                                                    notify_and_waitfor.dynsym0x8a0129FUNC<unknown>DEFAULT13
                                                                                    openLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    removeLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    set_process_name.dynsym0xbd0127FUNC<unknown>DEFAULT13
                                                                                    strcpyLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    strlenLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    usleepLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                    waitpidLIBClibc.so.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF

                                                                                    Download Network PCAP: filteredfull

                                                                                    • Total Packets: 6
                                                                                    • 443 (HTTPS)
                                                                                    • 80 (HTTP)
                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                    Jul 18, 2023 21:16:04.325567007 CEST42836443192.168.2.2391.189.91.43
                                                                                    Jul 18, 2023 21:16:04.581543922 CEST4251680192.168.2.23109.202.202.202
                                                                                    Jul 18, 2023 21:16:19.428803921 CEST43928443192.168.2.2391.189.91.42
                                                                                    Jul 18, 2023 21:16:31.716214895 CEST42836443192.168.2.2391.189.91.43
                                                                                    Jul 18, 2023 21:16:35.811847925 CEST4251680192.168.2.23109.202.202.202
                                                                                    Jul 18, 2023 21:17:00.386822939 CEST43928443192.168.2.2391.189.91.42

                                                                                    System Behavior

                                                                                    Start time:21:16:05
                                                                                    Start date:18/07/2023
                                                                                    Path:/tmp/SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf
                                                                                    Arguments:/tmp/SecuriteInfo.com.HEUR.Trojan-Dropper.AndroidOS.Wroba.p.8145.3782.elf
                                                                                    File size:9660 bytes
                                                                                    MD5 hash:2f6409ac30ccc8ae7dcce576a05422a4