Linux Analysis Report
4id267qj0M.elf

Overview

General Information

Sample name: 4id267qj0M.elf
renamed because original name is a hash value
Original sample name: 030d7a2075f2224c82e78c9b5e97c248.elf
Analysis ID: 1541859
MD5: 030d7a2075f2224c82e78c9b5e97c248
SHA1: f8ffa33ad8f84e8d79f3630e4efa2d324efd7bf2
SHA256: a616725e1be3ebec2834f4c2cc59c36e8e4aeb8e6856e49d45ffbc5688463fba
Tags: 32armelfmirai
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: 4id267qj0M.elf ReversingLabs: Detection: 65%
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal48.linELF@0/0@2/0
Source: /tmp/4id267qj0M.elf (PID: 5525) Queries kernel information via 'uname': Jump to behavior
Source: 4id267qj0M.elf, 5525.1.000055fa73952000.000055fa73a80000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: 4id267qj0M.elf, 5525.1.00007fffdd39d000.00007fffdd3be000.rw-.sdmp Binary or memory string: qemu: %s: %s
Source: 4id267qj0M.elf, 5525.1.00007fffdd39d000.00007fffdd3be000.rw-.sdmp Binary or memory string: leqemu: %s: %s
Source: 4id267qj0M.elf, 5525.1.000055fa73952000.000055fa73a80000.rw-.sdmp Binary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: 4id267qj0M.elf, 5525.1.000055fa73952000.000055fa73a80000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: 4id267qj0M.elf, 5525.1.00007fffdd39d000.00007fffdd3be000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: 4id267qj0M.elf, 5525.1.00007fffdd39d000.00007fffdd3be000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/4id267qj0M.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/4id267qj0M.elf
Source: 4id267qj0M.elf, 5525.1.000055fa73952000.000055fa73a80000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
No contacted IP infos