Linux Analysis Report
CwJ4wKfQcgGNj

Overview

General Information

Sample name: CwJ4wKfQcgGNj
Analysis ID: 1560410
MD5: 379dca5f10a3967381ba47e47a4a20ed
SHA1: 6e069ade70cdfed84d0acbffc71f45e9f44d0521
SHA256: 91f66ba1ad49d3062afdcc80e54da0807207d80a1b539edcdbd6e1bf99e7a2ca

Detection

Score: 20
Range: 0 - 100
Whitelisted: false

Signatures

Sample deletes itself
Sample has stripped symbol table

Classification

Source: CwJ4wKfQcgGNj String found in binary or memory: http:///cargo/registry/src/index.crates.io-6f17d22bba15001f/reqwest-0.11.27/src/proxy.rssocks5socks5
Source: CwJ4wKfQcgGNj String found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-supportCalling
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: sus20.evad.lin@0/0@0/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/CwJ4wKfQcgGNj (PID: 4698) File: /tmp/CwJ4wKfQcgGNj Jump to behavior
No contacted IP infos