Linux Analysis Report
arm6.elf

Overview

General Information

Sample name: arm6.elf
Analysis ID: 1546035
MD5: 9443a535274c40b20db981a88c9ffb1a
SHA1: 7474ed01ee11bd2e6ff21eb097e8a52c52cf055c
SHA256: 9dce28d1996b3e28995d054dc2950a71ed2e85c38a295bfc77e46659282f03e2
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: arm6.elf ReversingLabs: Detection: 13%
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal48.linELF@0/0@2/0
Source: /tmp/arm6.elf (PID: 5424) Queries kernel information via 'uname': Jump to behavior
Source: arm6.elf, 5424.1.000055555fb6c000.000055555fc9a000.rw-.sdmp Binary or memory string: _UU!/etc/qemu-binfmt/arm
Source: arm6.elf, 5424.1.000055555fb6c000.000055555fc9a000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: arm6.elf, 5424.1.00007ffd40d53000.00007ffd40d74000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: arm6.elf, 5424.1.00007ffd40d53000.00007ffd40d74000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm6.elf
Source: arm6.elf, 5424.1.00007ffd40d53000.00007ffd40d74000.rw-.sdmp Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
No contacted IP infos