Edit tour
Linux
Analysis Report
arc.elf
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1586636 |
Start date and time: | 2025-01-09 12:47:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | arc.elf |
Detection: | MAL |
Classification: | mal56.linELF@0/0@2/0 |
Cookbook Comments: |
|
- No process behavior to analyse as no analysis process or sample was found
Command: | /tmp/arc.elf |
PID: | 5530 |
Exit Code: | 255 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
⊘No yara matches
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | DNS traffic detected: |
Source: | .symtab present: |
Source: | Classification label: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | Direct Volume Access | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
⊘No configs have been found
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
37% | Virustotal | Browse | ||
47% | ReversingLabs | Linux.Trojan.Mirai | ||
100% | Avira | EXP/ELF.Mirai.H |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
daisy.ubuntu.com | 162.213.35.24 | true | false | high |
⊘No contacted IP infos
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
daisy.ubuntu.com | Get hash | malicious | Gafgyt | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
⊘No context
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.927731973218081 |
TrID: |
|
File name: | arc.elf |
File size: | 42'328 bytes |
MD5: | b00d1adf1347139583c76f5df80dbe76 |
SHA1: | 7b5b1b243cd5740fe04903c312cd45789626a39d |
SHA256: | f0c5e09caedea9ee5cebf2366a680ad0590cb2024e7afc062d6cdf955eec8105 |
SHA512: | e0bc36a529737ca0a0fff0abc495b359046997aedd363a4920cb8871b1681b83db0dc5948175e18bb41cd72fd43253d881c99ac4d6298194e94a5adaaef38c0e |
SSDEEP: | 768:LzU+c++Q5TjfjW3MGsjcFbJBZU/ogjlJHsBF:Hpd+0T3W88FbJBZUXQB |
TLSH: | 091308662D45B2BCDDF60078B45320A154A3453C3B8CE6F37187A87AEF75F097698E18 |
File Content Preview: | .ELF..............].....\...4...........4. ...(.........4...4...4.......................4...4...4...................................4...4........ ......D...D...D................ ......T...T...T.......................H...H...H... ... ...........Q.td....... |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 8 |
Section Header Offset: | 41448 |
Section Header Size: | 40 |
Number of Section Headers: | 22 |
Header String Table Index: | 21 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.interp | PROGBITS | 0x10134 | 0x134 | 0x14 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.note.ABI-tag | NOTE | 0x10148 | 0x148 | 0x20 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.hash | HASH | 0x10168 | 0x168 | 0x158 | 0x4 | 0x2 | A | 4 | 0 | 4 |
.dynsym | DYNSYM | 0x102c0 | 0x2c0 | 0x2f0 | 0x10 | 0x2 | A | 5 | 1 | 4 |
.dynstr | STRTAB | 0x105b0 | 0x5b0 | 0x165 | 0x0 | 0x2 | A | 0 | 0 | 1 |
.rela.plt | RELA | 0x10718 | 0x718 | 0x204 | 0xc | 0x42 | AI | 4 | 16 | 4 |
.init | PROGBITS | 0x1091c | 0x91c | 0x22 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.plt | PROGBITS | 0x10940 | 0x940 | 0x21c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x10b5c | 0xb5c | 0x7c24 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x18780 | 0x8780 | 0x16 | 0x0 | 0x6 | AX | 0 | 0 | 1 |
.rodata | PROGBITS | 0x18798 | 0x8798 | 0x598 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.eh_frame | PROGBITS | 0x18d30 | 0x8d30 | 0x4 | 0x0 | 0x2 | A | 0 | 0 | 4 |
.ctors | PROGBITS | 0x1bf44 | 0x9f44 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x1bf4c | 0x9f4c | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dynamic | DYNAMIC | 0x1bf54 | 0x9f54 | 0xa8 | 0x8 | 0x3 | WA | 5 | 0 | 4 |
.got.plt | PROGBITS | 0x1bffc | 0x9ffc | 0xb8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x1c0b4 | 0xa0b4 | 0x18 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x1c0cc | 0xa0cc | 0x308 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.comment | PROGBITS | 0x0 | 0xa0cc | 0x43 | 0x1 | 0x30 | MS | 0 | 0 | 1 |
.ARC.attributes | <unknown> | 0x0 | 0xa10f | 0x30 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0xa13f | 0xa9 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
PHDR | 0x34 | 0x10034 | 0x10034 | 0x100 | 0x100 | 2.3987 | 0x5 | R E | 0x4 | ||
INTERP | 0x134 | 0x10134 | 0x10134 | 0x14 | 0x14 | 3.6842 | 0x4 | R | 0x1 | /lib/ld-uClibc.so.0 | .interp |
LOAD | 0x0 | 0x10000 | 0x10000 | 0x8d34 | 0x8d34 | 6.4096 | 0x5 | R E | 0x2000 | .interp .note.ABI-tag .hash .dynsym .dynstr .rela.plt .init .plt .text .fini .rodata .eh_frame | |
LOAD | 0x9f44 | 0x1bf44 | 0x1bf44 | 0x188 | 0x490 | 2.6398 | 0x6 | RW | 0x2000 | .ctors .dtors .dynamic .got.plt .data .bss | |
DYNAMIC | 0x9f54 | 0x1bf54 | 0x1bf54 | 0xa8 | 0xa8 | 2.0703 | 0x6 | RW | 0x4 | .dynamic | |
NOTE | 0x148 | 0x10148 | 0x10148 | 0x20 | 0x20 | 1.4988 | 0x4 | R | 0x4 | .note.ABI-tag | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x10 | ||
GNU_RELRO | 0x9f44 | 0x1bf44 | 0x1bf44 | 0xbc | 0xbc | 2.2418 | 0x4 | R | 0x1 | .ctors .dtors .dynamic |
Type | Meta | Value | Tag |
---|---|---|---|
DT_NEEDED | sharedlib | libc.so.0 | 0x1 |
DT_INIT | value | 0x10920 | 0xc |
DT_FINI | value | 0x18784 | 0xd |
DT_HASH | value | 0x10168 | 0x4 |
DT_STRTAB | value | 0x105b0 | 0x5 |
DT_SYMTAB | value | 0x102c0 | 0x6 |
DT_STRSZ | bytes | 357 | 0xa |
DT_SYMENT | bytes | 16 | 0xb |
DT_INIT | value | 0x10920 | 0xc |
DT_FINI | value | 0x18784 | 0xd |
DT_DEBUG | value | 0x0 | 0x15 |
DT_PLTGOT | value | 0x10940 | 0x3 |
DT_PLTRELSZ | bytes | 516 | 0x2 |
DT_PLTREL | pltrel | DT_RELA | 0x14 |
DT_JMPREL | value | 0x10718 | 0x17 |
DT_NULL | value | 0x0 | 0x0 |
Name | Version Info Name | Version Info File Name | Section Name | Value | Size | Symbol Type | Symbol Bind | Symbol Visibility | Ndx |
---|---|---|---|---|---|---|---|---|---|
.dynsym | 0x0 | 0 | NOTYPE | <unknown> | DEFAULT | SHN_UNDEF | |||
__bss_start | .dynsym | 0x1c0cc | 0 | NOTYPE | <unknown> | DEFAULT | 18 | ||
__errno_location | .dynsym | 0x10ae4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
__uClibc_main | .dynsym | 0x10a90 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
_edata | .dynsym | 0x1c0cc | 0 | NOTYPE | <unknown> | DEFAULT | 17 | ||
_end | .dynsym | 0x1c3d4 | 0 | NOTYPE | <unknown> | DEFAULT | 18 | ||
bind | .dynsym | 0x10a0c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
calloc | .dynsym | 0x109f4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
clock | .dynsym | 0x10b08 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
close | .dynsym | 0x10b2c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
connect | .dynsym | 0x10970 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
exit | .dynsym | 0x10af0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fcntl | .dynsym | 0x10b20 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
fork | .dynsym | 0x10a84 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
free | .dynsym | 0x10b38 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getpid | .dynsym | 0x10994 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getppid | .dynsym | 0x10ab4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockname | .dynsym | 0x10b50 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
getsockopt | .dynsym | 0x10acc | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
htonl | .dynsym | 0x10a54 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
htons | .dynsym | 0x10ad8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
inet_addr | .dynsym | 0x10a18 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
kill | .dynsym | 0x10a00 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
listen | .dynsym | 0x10a78 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
malloc | .dynsym | 0x109ac | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memmove | .dynsym | 0x10988 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
memset | .dynsym | 0x10a9c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ntohl | .dynsym | 0x10a24 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
ntohs | .dynsym | 0x10aa8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
open | .dynsym | 0x10afc | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
prctl | .dynsym | 0x109a0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
printf | .dynsym | 0x10958 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
read | .dynsym | 0x10a48 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
realloc | .dynsym | 0x10a6c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
recv | .dynsym | 0x10964 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
select | .dynsym | 0x109d0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
send | .dynsym | 0x109e8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sendto | .dynsym | 0x10a60 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsid | .dynsym | 0x10b14 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
setsockopt | .dynsym | 0x10a30 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigaddset | .dynsym | 0x109dc | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigemptyset | .dynsym | 0x1097c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
signal | .dynsym | 0x10a3c | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sigprocmask | .dynsym | 0x10b44 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
sleep | .dynsym | 0x109b8 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
socket | .dynsym | 0x109c4 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF | ||
time | .dynsym | 0x10ac0 | 0 | FUNC | <unknown> | DEFAULT | SHN_UNDEF |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 9, 2025 12:50:45.940762997 CET | 45624 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 9, 2025 12:50:45.940843105 CET | 57773 | 53 | 192.168.2.15 | 8.8.8.8 |
Jan 9, 2025 12:50:45.947073936 CET | 53 | 45624 | 8.8.8.8 | 192.168.2.15 |
Jan 9, 2025 12:50:45.947123051 CET | 53 | 57773 | 8.8.8.8 | 192.168.2.15 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 9, 2025 12:50:45.940762997 CET | 192.168.2.15 | 8.8.8.8 | 0x7754 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 9, 2025 12:50:45.940843105 CET | 192.168.2.15 | 8.8.8.8 | 0x11e9 | Standard query (0) | 28 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 9, 2025 12:50:45.947073936 CET | 8.8.8.8 | 192.168.2.15 | 0x7754 | No error (0) | 162.213.35.24 | A (IP address) | IN (0x0001) | false | ||
Jan 9, 2025 12:50:45.947073936 CET | 8.8.8.8 | 192.168.2.15 | 0x7754 | No error (0) | 162.213.35.25 | A (IP address) | IN (0x0001) | false |