Linux Analysis Report
dlr.arm.elf

Overview

General Information

Sample name: dlr.arm.elf
Analysis ID: 1546731
MD5: be7c90ac4bb096ba24326520ca92edb9
SHA1: 49c2f56cefc4ef4c64dcf2f729df877bbceef26d
SHA256: 5a9e878eedeaa18fe096470997614b3e49351d19a02de3a29748508ea256060a
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: dlr.arm.elf ReversingLabs: Detection: 44%
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal48.linELF@0/0@2/0
Source: /tmp/dlr.arm.elf (PID: 5490) Queries kernel information via 'uname': Jump to behavior
Source: dlr.arm.elf, 5490.1.000055ffc2f33000.000055ffc303f000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: dlr.arm.elf, 5490.1.00007ffc3126c000.00007ffc3128d000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/dlr.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.arm.elf
Source: dlr.arm.elf, 5490.1.000055ffc2f33000.000055ffc303f000.rw-.sdmp Binary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: dlr.arm.elf, 5490.1.000055ffc2f33000.000055ffc303f000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: dlr.arm.elf, 5490.1.00007ffc3126c000.00007ffc3128d000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: dlr.arm.elf, 5490.1.000055ffc2f33000.000055ffc303f000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
No contacted IP infos