Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm5.elf

Overview

General Information

Sample name:arm5.elf
Analysis ID:1583605
MD5:8f395adbfcfb23406d6fe3c58faaaf5d
SHA1:7c3db438fcb3cc78cace9d96b1977484080f2872
SHA256:69b3cda867879e6e8fa8ab62402473bfb1e1fba08b9ebf93225c71e7050abb4e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583605
Start date and time:2025-01-03 07:52:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm5.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/arm5.elf
PID:5489
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • arm5.elf (PID: 5489, Parent: 5412, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm5.elf
    • arm5.elf New Fork (PID: 5491, Parent: 5489)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm5.elfReversingLabs: Detection: 21%
Source: global trafficTCP traffic: 192.168.2.14:52288 -> 85.239.34.134:31337
Source: /tmp/arm5.elf (PID: 5489)Socket: 0.0.0.0:3142Jump to behavior
Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/arm5.elf (PID: 5489)Queries kernel information via 'uname': Jump to behavior
Source: arm5.elf, 5489.1.00007ffddb4a4000.00007ffddb4c5000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm5.elf
Source: arm5.elf, 5489.1.000055d4dd558000.000055d4dd686000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: arm5.elf, 5489.1.000055d4dd558000.000055d4dd686000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm5.elf, 5489.1.00007ffddb4a4000.00007ffddb4c5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm5.elf21%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
185.125.190.26
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134arm7.elfGet hashmaliciousUnknownBrowse
    arm.elfGet hashmaliciousUnknownBrowse
      arm7.elfGet hashmaliciousUnknownBrowse
        mpsl.elfGet hashmaliciousUnknownBrowse
          arm5.elfGet hashmaliciousUnknownBrowse
            ppc.elfGet hashmaliciousUnknownBrowse
              mips.elfGet hashmaliciousUnknownBrowse
                arm6.elfGet hashmaliciousUnknownBrowse
                  m68k.elfGet hashmaliciousUnknownBrowse
                    sh4.elfGet hashmaliciousUnknownBrowse
                      185.125.190.26boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                        wind.sh4.elfGet hashmaliciousMiraiBrowse
                          wind.arc.elfGet hashmaliciousMiraiBrowse
                            DEMONS.arm5.elfGet hashmaliciousUnknownBrowse
                              DEMONS.arm7.elfGet hashmaliciousMiraiBrowse
                                powerpc.elfGet hashmaliciousUnknownBrowse
                                  gnjqwpc.elfGet hashmaliciousMiraiBrowse
                                    bot.arm5.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                      earm5.elfGet hashmaliciousUnknownBrowse
                                        earm7.elfGet hashmaliciousUnknownBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          RAINBOW-HKRainbownetworklimitedHKarm7.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          https://klickskydd.skolverket.org/?url=https%3A%2F%2Fwww.gazeta.ru%2Fpolitics%2Fnews%2F2024%2F12%2F22%2F24684722.shtml&id=71de&rcpt=upplysningstjansten@skolverket.se&tss=1735469857&msgid=b53e7603-c5d3-11ef-8a2e-0050569b0508&html=1&h=ded85c63Get hashmaliciousHTMLPhisherBrowse
                                          • 45.138.161.76
                                          https://www.gazeta.ru/politics/news/2024/12/22/24684722.shtmlGet hashmaliciousHTMLPhisherBrowse
                                          • 45.138.161.75
                                          https://www.gazeta.ru/politics/news/2024/12/22/24684854.shtmlGet hashmaliciousHTMLPhisherBrowse
                                          • 45.138.161.71
                                          arm7.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          mpsl.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          ppc.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 85.239.34.134
                                          CANONICAL-ASGBarm7.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          x86_64.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                          • 185.125.190.26
                                          arm5.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          141.11.33.73-boatnet.arm-2025-01-03T05_39_17.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          arm5.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          i.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          mpsl.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          ARMV6L.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          MIPS.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):5.55652392900169
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:arm5.elf
                                          File size:34'072 bytes
                                          MD5:8f395adbfcfb23406d6fe3c58faaaf5d
                                          SHA1:7c3db438fcb3cc78cace9d96b1977484080f2872
                                          SHA256:69b3cda867879e6e8fa8ab62402473bfb1e1fba08b9ebf93225c71e7050abb4e
                                          SHA512:aa4d8a5245453ea99847c9ee8e45f90bf8fc39309c9413684535fe89058087e00c09656546b6f2b08606c879252d9fce6df0cf9be857fcd887e5c8e3b1e48e2c
                                          SSDEEP:768:cbynQDiQwHW2kJKoC+9mU5pvSMONQd/i7VbJe0n1weC:c+nPHW2Pc9mU5pvSMO+d/i7VbwF
                                          TLSH:16E22C4AFD419F11D4D0217EFEAF524D33331B68E2EB3202AE106B246B8AD5E0F76955
                                          File Content Preview:.ELF..............(.........4...p.......4. ...(........p.q...........................................r...r.............................../..........................................Q.td..................................-...L..................@-.,@...0....S

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:ARM
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x8194
                                          Flags:0x4000002
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:5
                                          Section Header Offset:33392
                                          Section Header Size:40
                                          Number of Section Headers:17
                                          Header String Table Index:16
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x80d40xd40x100x00x6AX004
                                          .textPROGBITS0x80f00xf00x6d000x00x6AX0016
                                          .finiPROGBITS0xedf00x6df00x100x00x6AX004
                                          .rodataPROGBITS0xee000x6e000x3a00x00x2A004
                                          .ARM.extabPROGBITS0xf1a00x71a00x180x00x2A004
                                          .ARM.exidxARM_EXIDX0xf1b80x71b80x1080x00x82AL204
                                          .eh_framePROGBITS0x100000x80000x40x00x3WA004
                                          .tbssNOBITS0x100040x80040x80x00x403WAT004
                                          .init_arrayINIT_ARRAY0x100040x80040x40x00x3WA004
                                          .fini_arrayFINI_ARRAY0x100080x80080x40x00x3WA004
                                          .jcrPROGBITS0x1000c0x800c0x40x00x3WA004
                                          .gotPROGBITS0x100100x80100x940x40x3WA004
                                          .dataPROGBITS0x100a40x80a40x12c0x00x3WA004
                                          .bssNOBITS0x101d00x81d00x2db40x00x3WA004
                                          .ARM.attributesARM_ATTRIBUTES0x00x81d00x160x00x0001
                                          .shstrtabSTRTAB0x00x81e60x880x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          EXIDX0x71b80xf1b80xf1b80x1080x1084.46670x4R 0x4.ARM.exidx
                                          LOAD0x00x80000x80000x72c00x72c06.00230x5R E0x1000.init .text .fini .rodata .ARM.extab .ARM.exidx
                                          LOAD0x80000x100000x100000x1d00x2f842.31850x6RW 0x1000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
                                          TLS0x80040x100040x100040x00x80.00000x4R 0x4.tbss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                          TimestampSource PortDest PortSource IPDest IP
                                          Jan 3, 2025 07:52:56.011900902 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:52:56.017919064 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:52:56.017981052 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:52:56.018443108 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:52:56.024722099 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:52:56.748712063 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:52:56.748873949 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:52:56.749106884 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:52:56.753813028 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:52:56.972450972 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:52:56.972517014 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:06.159692049 CET46540443192.168.2.14185.125.190.26
                                          Jan 3, 2025 07:53:06.982433081 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:06.987391949 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:07.229846954 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:07.230061054 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:07.230196953 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:07.234895945 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:17.239912033 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:17.244793892 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:17.463270903 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:17.463447094 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:27.473346949 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:27.478271961 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:27.741271019 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:27.741482973 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:37.742392063 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:37.747246981 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:37.902163029 CET46540443192.168.2.14185.125.190.26
                                          Jan 3, 2025 07:53:37.965688944 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:37.965754032 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:47.975675106 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:47.980928898 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:48.230215073 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:48.230494022 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:58.240076065 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:53:58.244963884 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:58.464941978 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:53:58.465030909 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:08.474803925 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:08.479640961 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:08.698052883 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:08.698172092 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:18.707842112 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:18.712636948 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:18.931143045 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:18.931215048 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:28.940947056 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:28.945961952 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:29.164208889 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:29.164300919 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:39.174005985 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:39.178880930 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:39.397377014 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:39.397547960 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:49.407205105 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:49.412153006 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:49.631074905 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:49.631328106 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:59.641036987 CET5228831337192.168.2.1485.239.34.134
                                          Jan 3, 2025 07:54:59.645899057 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:59.864377975 CET313375228885.239.34.134192.168.2.14
                                          Jan 3, 2025 07:54:59.864525080 CET5228831337192.168.2.1485.239.34.134

                                          System Behavior

                                          Start time (UTC):06:52:54
                                          Start date (UTC):03/01/2025
                                          Path:/tmp/arm5.elf
                                          Arguments:/tmp/arm5.elf
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                          Start time (UTC):06:52:54
                                          Start date (UTC):03/01/2025
                                          Path:/tmp/arm5.elf
                                          Arguments:-
                                          File size:4956856 bytes
                                          MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1