Linux Analysis Report
Aqua.arm6.elf

Overview

General Information

Sample name: Aqua.arm6.elf
Analysis ID: 1580695
MD5: 938e11dd094940d5e2e1bf11405a5800
SHA1: 98c91d05241ba68e0be1fa121a0bb4accce15a02
SHA256: cd48dd5da6a760c74076810a542c0002e0eb4603a621e5415f67978dbfef5682
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: Aqua.arm6.elf Avira: detected
Source: Aqua.arm6.elf Virustotal: Detection: 30% Perma Link
Source: Aqua.arm6.elf ReversingLabs: Detection: 36%
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@2/0
Source: /tmp/Aqua.arm6.elf (PID: 5529) Queries kernel information via 'uname': Jump to behavior
Source: Aqua.arm6.elf, 5529.1.000055e450866000.000055e450994000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: Aqua.arm6.elf, 5529.1.00007ffd982c4000.00007ffd982e5000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/Aqua.arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Aqua.arm6.elf
Source: Aqua.arm6.elf, 5529.1.000055e450866000.000055e450994000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: Aqua.arm6.elf, 5529.1.00007ffd982c4000.00007ffd982e5000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: Aqua.arm6.elf, 5529.1.00007ffd982c4000.00007ffd982e5000.rw-.sdmp Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
No contacted IP infos