Linux Analysis Report
8RFfyRrdWT.elf

Overview

General Information

Sample name: 8RFfyRrdWT.elf
renamed because original name is a hash value
Original sample name: 72e2005ca58f9bafb342fff906042766.elf
Analysis ID: 1545507
MD5: 72e2005ca58f9bafb342fff906042766
SHA1: cefb9aea7f27bb907a79a401a986619997d1983b
SHA256: f60766a94bbda92a2bab16cc02733929bd837fe67f36ed02cf73abeac2b40a31
Tags: 32elfmiraisparc
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

AV Detection

barindex
Source: 8RFfyRrdWT.elf ReversingLabs: Detection: 42%
Source: /tmp/8RFfyRrdWT.elf (PID: 5412) Socket: 127.0.0.1:46157 Jump to behavior
Source: unknown DNS traffic detected: query: 154.216.20.94 replaycode: Name error (3)
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknown TCP traffic detected without corresponding DNS query: 217.32.184.17
Source: global traffic DNS traffic detected: DNS query: 154.216.20.94

System Summary

barindex
Source: 8RFfyRrdWT.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5412.1.00007f94ac02c000.00007f94ac02d000.rw-.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5412.1.00007f94ac011000.00007f94ac01d000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: 8RFfyRrdWT.elf PID: 5412, type: MEMORYSTR Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample .symtab present: no
Source: 8RFfyRrdWT.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5412.1.00007f94ac02c000.00007f94ac02d000.rw-.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5412.1.00007f94ac011000.00007f94ac01d000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: 8RFfyRrdWT.elf PID: 5412, type: MEMORYSTR Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engine Classification label: mal56.linELF@0/0@75/0
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/235/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/115/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/236/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/116/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/237/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/117/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/238/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/118/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/239/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/119/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/914/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/10/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/11/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/12/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/13/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/14/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/15/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/5397/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/16/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/3770/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/5398/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/17/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/18/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/19/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/240/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/3095/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/120/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/241/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/121/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/242/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/1/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/122/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/243/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/2/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/123/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/244/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/3/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/124/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/245/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/1588/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/125/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/4/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/246/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/126/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/5/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/247/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/127/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/6/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/248/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/128/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/7/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/249/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/129/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/8/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/800/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/9/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/1906/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/802/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/803/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/20/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/21/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/22/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/23/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/24/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/25/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/5044/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/26/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/27/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/28/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/29/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/3420/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/1482/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/490/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/1480/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/250/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/371/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/130/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/251/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/131/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/252/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/132/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/253/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/254/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/1238/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/134/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/255/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/256/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/257/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/378/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/3413/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/258/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/259/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/1475/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418) File opened: /proc/936/cmdline Jump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5412) Queries kernel information via 'uname': Jump to behavior
Source: 8RFfyRrdWT.elf, 5412.1.0000561048241000.00005610482a6000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/sparc
Source: 8RFfyRrdWT.elf, 5412.1.0000561048241000.00005610482a6000.rw-.sdmp Binary or memory string: V!/etc/qemu-binfmt/sparc
Source: 8RFfyRrdWT.elf, 5412.1.00007ffd1afe4000.00007ffd1b005000.rw-.sdmp Binary or memory string: A=Dx86_64/usr/bin/qemu-sparc/tmp/8RFfyRrdWT.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/8RFfyRrdWT.elf
Source: 8RFfyRrdWT.elf, 5412.1.00007ffd1afe4000.00007ffd1b005000.rw-.sdmp Binary or memory string: /usr/bin/qemu-sparc
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs