Linux Analysis Report
amd64.elf

Overview

General Information

Sample name: amd64.elf
Analysis ID: 1543411
MD5: 460bfe2f3c4ec8d67282cded7ce12215
SHA1: 206da96eeae36e8133c9f459a21244693cf58b73
SHA256: 6ee4ae55ebc3cc41ecc3a0f713ef44cd680320bb8ef9916cefc9f88b61ea7724
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: amd64.elf ReversingLabs: Detection: 15%
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown TCP traffic detected without corresponding DNS query: 156.234.42.40
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39256
Source: unknown Network traffic detected: HTTP traffic on port 39256 -> 443
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal48.linELF@0/0@0/0
Source: ELF file section Submission: amd64.elf
Source: /usr/bin/dash (PID: 6276) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA Jump to behavior
Source: /usr/bin/dash (PID: 6277) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA Jump to behavior
Source: submitted sample Stderr: 2024/10/27 14:19:14 Forking2024/10/27 14:19:14 Connecting to 156.234.42.40:802024/10/27 14:19:17 Successfully connnected 156.234.42.40:80: exit code = 0
Source: /proc/self/exe (PID: 6269) Queries kernel information via 'uname': Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs