Linux Analysis Report
Josho.arm6.elf

Overview

General Information

Sample name: Josho.arm6.elf
Analysis ID: 1546921
MD5: 8d2674b8f87a0a8eeb096aa8ccf37c0c
SHA1: 1f03eaa5ce101663a36b0330cf0c1868ca170ac9
SHA256: bead2443ef5b7ba3740bb08c6e93894da6dc2f24731fcdb166b45666cf3a12a0
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: Josho.arm6.elf Avira: detected
Source: Josho.arm6.elf ReversingLabs: Detection: 68%
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@2/0
Source: /tmp/Josho.arm6.elf (PID: 5432) Queries kernel information via 'uname': Jump to behavior
Source: Josho.arm6.elf, 5432.1.00005590e93cd000.00005590e94fb000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: Josho.arm6.elf, 5432.1.00007ffcd0e84000.00007ffcd0ea5000.rw-.sdmp Binary or memory string: sTx86_64/usr/bin/qemu-arm/tmp/Josho.arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Josho.arm6.elf
Source: Josho.arm6.elf, 5432.1.00005590e93cd000.00005590e94fb000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: Josho.arm6.elf, 5432.1.00007ffcd0e84000.00007ffcd0ea5000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: Josho.arm6.elf, 5432.1.00007ffcd0e84000.00007ffcd0ea5000.rw-.sdmp Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
No contacted IP infos