Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
nn.elf

Overview

General Information

Sample name:nn.elf
Analysis ID:1579445
MD5:29c8547d521036f275cbf709ba246e6b
SHA1:820e1777de519c3db3192a1c802c4f65f919ffd8
SHA256:cf8766321e15f41953397dcbf7fccad710d949b13bde100af94b1c1889da4b3f
Tags:elfuser-abuse_ch
Infos:

Detection

Nanominer, Xmrig
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Yara detected Nanominer
Yara detected Xmrig cryptocurrency miner
Found strings related to Crypto-Mining
Executes the "rm" command used to delete files or directories
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1579445
Start date and time:2024-12-22 12:06:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:nn.elf
Detection:MAL
Classification:mal68.mine.linELF@0/0@0/0
  • VT rate limit hit for: https://api.nanopool.org/v1/invalid
Command:/tmp/nn.elf
PID:6257
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6231, Parent: 4332)
  • rm (PID: 6231, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.wBlurrknEK /tmp/tmp.tv2Sni4a7k /tmp/tmp.FBowDQxA6f
  • dash New Fork (PID: 6232, Parent: 4332)
  • rm (PID: 6232, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.wBlurrknEK /tmp/tmp.tv2Sni4a7k /tmp/tmp.FBowDQxA6f
  • cleanup
SourceRuleDescriptionAuthorStrings
nn.elfJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    nn.elfJoeSecurity_NanominerYara detected NanominerJoe Security
      nn.elfLinux_Cryptominer_Generic_e0cca9dcunknownunknown
      • 0x1dd87e:$a: 54 24 40 48 8D 94 24 C0 00 00 00 F3 41 0F 6F 01 48 89 7C 24 50 48 89 74
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      Bitcoin Miner

      barindex
      Source: Yara matchFile source: nn.elf, type: SAMPLE
      Source: Yara matchFile source: nn.elf, type: SAMPLE
      Source: nn.elfString found in binary or memory: St22_Weak_result_type_implIM7IClientFvRKSt7variantIJ12EthashResult13StratumResult17CryptonightResult15VerusHashResultEERKS1_IJ10EthashTask12StratumInput16CryptonightInput14VerusHashInputEESt10shared_ptrI6DeviceEEE
      Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
      Source: nn.elfString found in binary or memory: https://api.github.com/repos/nanopool/nanominer/releases/latestmalformed
      Source: nn.elfString found in binary or memory: https://api.nanopool.org/v1/invalid
      Source: nn.elfString found in binary or memory: https://blockscout.com/etc/mainnet/api?module=block&action=eth_block_numbertls:
      Source: nn.elfString found in binary or memory: https://gcc.gnu.org/bugs
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
      Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

      System Summary

      barindex
      Source: nn.elf, type: SAMPLEMatched rule: Linux_Cryptominer_Generic_e0cca9dc Author: unknown
      Source: nn.elf, type: SAMPLEMatched rule: Linux_Cryptominer_Generic_e0cca9dc reference_sample = 59a1d8aa677739f2edbb8bd34f566b31f19d729b0a115fef2eac8ab1d1acc383, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Cryptominer.Generic, fingerprint = e7bc17ba356774ed10e65c95a8db3b09d3b9be72703e6daa9b601ea820481db7, id = e0cca9dc-0f3e-42d8-bb43-0625f4f9bfe1, last_modified = 2022-01-26
      Source: classification engineClassification label: mal68.mine.linELF@0/0@0/0
      Source: /usr/bin/dash (PID: 6231)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.wBlurrknEK /tmp/tmp.tv2Sni4a7k /tmp/tmp.FBowDQxA6fJump to behavior
      Source: /usr/bin/dash (PID: 6232)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.wBlurrknEK /tmp/tmp.tv2Sni4a7k /tmp/tmp.FBowDQxA6fJump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
      File Deletion
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      SourceDetectionScannerLabelLink
      nn.elf11%ReversingLabsLinux.Coinminer.Generic
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      https://api.nanopool.org/v1/invalidnn.elffalse
        unknown
        https://blockscout.com/etc/mainnet/api?module=block&action=eth_block_numbertls:nn.elffalse
          high
          https://api.github.com/repos/nanopool/nanominer/releases/latestmalformednn.elffalse
            high
            https://gcc.gnu.org/bugsnn.elffalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              54.171.230.55
              unknownUnited States
              16509AMAZON-02USfalse
              109.202.202.202
              unknownSwitzerland
              13030INIT7CHfalse
              91.189.91.43
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              91.189.91.42
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              54.171.230.55arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                  arm6.elfGet hashmaliciousMiraiBrowse
                    http://112.31.189.32:40158Get hashmaliciousMiraiBrowse
                      Aqua.mpsl.elfGet hashmaliciousMiraiBrowse
                        bot.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                          la.bot.arc.elfGet hashmaliciousMiraiBrowse
                            armv6l.elfGet hashmaliciousMiraiBrowse
                              la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                                la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                  91.189.91.43arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                    vlxx.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                      vlxx.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                        la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                          la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                            la.bot.arm5.elfGet hashmaliciousMiraiBrowse
                                              la.bot.arm.elfGet hashmaliciousMiraiBrowse
                                                la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                  la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                                                    la.bot.mips.elfGet hashmaliciousMiraiBrowse
                                                      91.189.91.42arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                        vlxx.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                          vlxx.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                            vlxx.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                              la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                                                la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                                  la.bot.arm5.elfGet hashmaliciousMiraiBrowse
                                                                    la.bot.arm.elfGet hashmaliciousMiraiBrowse
                                                                      la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                                        la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                                                                          No context
                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                          CANONICAL-ASGBarm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 185.125.190.26
                                                                          la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          CANONICAL-ASGBarm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 91.189.91.42
                                                                          vlxx.mpsl.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 185.125.190.26
                                                                          la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                                          • 91.189.91.42
                                                                          AMAZON-02USarm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 34.252.132.197
                                                                          arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 54.171.230.55
                                                                          arm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 13.236.254.247
                                                                          powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 54.154.131.169
                                                                          sparc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 108.154.170.136
                                                                          3.elfGet hashmaliciousUnknownBrowse
                                                                          • 54.97.133.72
                                                                          mips.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 18.159.41.41
                                                                          x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 3.35.124.145
                                                                          mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 18.254.104.182
                                                                          nshkppc.elfGet hashmaliciousMiraiBrowse
                                                                          • 3.193.46.42
                                                                          INIT7CHarm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                          • 109.202.202.202
                                                                          vlxx.m68k.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 109.202.202.202
                                                                          vlxx.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 109.202.202.202
                                                                          vlxx.arm.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                                          • 109.202.202.202
                                                                          la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          la.bot.arm5.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          la.bot.arm.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          la.bot.arm6.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          la.bot.sparc.elfGet hashmaliciousMiraiBrowse
                                                                          • 109.202.202.202
                                                                          No context
                                                                          No context
                                                                          No created / dropped files found
                                                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, missing section headers at 52906664
                                                                          Entropy (8bit):5.3938945379024075
                                                                          TrID:
                                                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                          File name:nn.elf
                                                                          File size:28'785'635 bytes
                                                                          MD5:29c8547d521036f275cbf709ba246e6b
                                                                          SHA1:820e1777de519c3db3192a1c802c4f65f919ffd8
                                                                          SHA256:cf8766321e15f41953397dcbf7fccad710d949b13bde100af94b1c1889da4b3f
                                                                          SHA512:0f03bd570fd6c8bedcfadb1bebd73af95c8214b8979b5409684b4811d2dfcaa6c06df28f253072f735428eb73a5c085ea5fe3ae6924bfaed4c565cc9ef7021c3
                                                                          SSDEEP:393216:Se4n2yMyec44bbt3QR68Or5CbB/yBHqjihphKmXMGDiw6l:LOQbBqBKjihlXMWiwO
                                                                          TLSH:5857BE47F59150ECC1AED13486669263BA707CA94B3037EB2B90F7792E32BE05B39354
                                                                          File Content Preview:.ELF..............>.......C.....@........A'.........@.8...@.$.#.........@.......@.@.....@.@.....0.......0.......................p.......p.@.....p.@...............................................@.......@.......t.......t....... ...............t............
                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                          Dec 22, 2024 12:06:53.813630104 CET4433360654.171.230.55192.168.2.23
                                                                          Dec 22, 2024 12:06:53.813792944 CET33606443192.168.2.2354.171.230.55
                                                                          Dec 22, 2024 12:06:53.933490992 CET4433360654.171.230.55192.168.2.23
                                                                          Dec 22, 2024 12:06:55.594907999 CET43928443192.168.2.2391.189.91.42
                                                                          Dec 22, 2024 12:07:01.226272106 CET42836443192.168.2.2391.189.91.43
                                                                          Dec 22, 2024 12:07:02.250005007 CET4251680192.168.2.23109.202.202.202
                                                                          Dec 22, 2024 12:07:17.351969004 CET43928443192.168.2.2391.189.91.42
                                                                          Dec 22, 2024 12:07:27.590528965 CET42836443192.168.2.2391.189.91.43
                                                                          Dec 22, 2024 12:07:31.685985088 CET4251680192.168.2.23109.202.202.202
                                                                          Dec 22, 2024 12:07:58.306440115 CET43928443192.168.2.2391.189.91.42

                                                                          System Behavior

                                                                          Start time (UTC):11:06:53
                                                                          Start date (UTC):22/12/2024
                                                                          Path:/usr/bin/dash
                                                                          Arguments:-
                                                                          File size:129816 bytes
                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                          Start time (UTC):11:06:53
                                                                          Start date (UTC):22/12/2024
                                                                          Path:/usr/bin/rm
                                                                          Arguments:rm -f /tmp/tmp.wBlurrknEK /tmp/tmp.tv2Sni4a7k /tmp/tmp.FBowDQxA6f
                                                                          File size:72056 bytes
                                                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                          Start time (UTC):11:06:53
                                                                          Start date (UTC):22/12/2024
                                                                          Path:/usr/bin/dash
                                                                          Arguments:-
                                                                          File size:129816 bytes
                                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                          Start time (UTC):11:06:53
                                                                          Start date (UTC):22/12/2024
                                                                          Path:/usr/bin/rm
                                                                          Arguments:rm -f /tmp/tmp.wBlurrknEK /tmp/tmp.tv2Sni4a7k /tmp/tmp.FBowDQxA6f
                                                                          File size:72056 bytes
                                                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b