Click to jump to signature section
Source: ARMV6L.elf | Virustotal: Detection: 30% | Perma Link |
Source: ARMV6L.elf | ReversingLabs: Detection: 39% |
Source: global traffic | DNS traffic detected: DNS query: daisy.ubuntu.com |
Source: LOAD without section mappings | Program segment: 0x8000 |
Source: classification engine | Classification label: mal56.linELF@0/51@2/0 |
Source: /usr/sbin/logrotate (PID: 5513) | Directory: //. | Jump to behavior |
Source: /usr/bin/find (PID: 5550) | Directory: //. | Jump to behavior |
Source: /usr/bin/mandb (PID: 5574) | Directory: /var/cache/man/.manpath | Jump to behavior |
Source: ARMV6L.elf | Submission file: segment LOAD with 7.9666 entropy (max. 8.0) |
Source: /tmp/ARMV6L.elf (PID: 5427) | Queries kernel information via 'uname': | Jump to behavior |
Source: /usr/bin/find (PID: 5550) | Queries kernel information via 'uname': | Jump to behavior |
Source: 5574.24.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 5574.24.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 5574.24.dr | Binary or memory string: qemu-or1k |
Source: 5574.24.dr | Binary or memory string: qemu-riscv64 |
Source: 5574.24.dr | Binary or memory string: qemu-arm |
Source: 5574.24.dr | Binary or memory string: (qemu |
Source: 5574.24.dr | Binary or memory string: qemu-tilegx |
Source: 5574.24.dr | Binary or memory string: qemu-hppa |
Source: 5574.24.dr | Binary or memory string: q{rqemu% |
Source: 5574.24.dr | Binary or memory string: )qemu |
Source: 5574.24.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 5574.24.dr | Binary or memory string: qemu-ppc |
Source: 5574.24.dr | Binary or memory string: Tqemu9 |
Source: ARMV6L.elf, 5427.1.00007ffd6ddb0000.00007ffd6ddd1000.rw-.sdmp | Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped |
Source: 5574.24.dr | Binary or memory string: qemu-aarch64_be |
Source: 5574.24.dr | Binary or memory string: 0qemu9 |
Source: 5574.24.dr | Binary or memory string: qemu-sparc64 |
Source: 5574.24.dr | Binary or memory string: qemu-mips64 |
Source: 5574.24.dr | Binary or memory string: vV:qemu9 |
Source: 5574.24.dr | Binary or memory string: <prezip-bin-1116269780060A--gzprefix zip delta word list compressor/decompressornameif-8815490444730A--gzname network interfaces based on MAC addressesxdg-user-dirs-update-1115483406210A--gzUpdate XDG user dir configurationip-link-8815816145190A--gznetwork device configurationhpsa-4415812813670A--gzHP Smart Array SCSI driverhd4-4415812813670A--gzMFM/IDE hard disk devicessane-canon630u-5516003468200A--gzSANE backend for the Canon 630u USB flatbed scannersg_copy_results-8815825816070A--gzsend SCSI RECEIVE COPY RESULTS command (XCOPY related)grub-macbless-8816214898500A--gzbless a mac file/directoryntfstruncate-8815568625640A-tgztruncate a file on an NTFS volumelessfile-1115936459130B--gz"input preprocessor" for less.sane-artec-5516003468200A--gzSANE backend for Artec flatbed scannersrmdir-1115676799200A--gzremove empty directoriessystemd-networkd-wait-online.service-8816268940210A--gzWait for network to come onlinemkfs.ntfs-8815568625640B-tgzcreate an NTFS file systemsg_inq-8815825816070A--gzissue SCSI INQUIRY command and/or decode its responseradattr.so-8815955079440Cpppd-radattr-gzc_rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valuestc-htb-8815816145190A--gzHierarchy Token Bucketgvfs-open-1115868766090A--gzsg_rbuf-8815825816070A--gzreads data using SCSI READ BUFFER commandglib-compile-schemas-1116155671180A--gzGSettings schema compileropenssl-srp-1ssl116164130370B--gzmaintain SRP password fileopenssl-rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valueslibvmtools-3315837702310A--gzvmware shared librarypasswd5-5515906478670A--gzthe password filenet::dbus::dumperNet::DBus::Dumper3pm315773746310A--gzStringify Net::DBus objects suitable for printingsane-hp4200-5516003468200A--gzSANE backend for Hewlett-Packard 4200 scannersposixoptions-7715812813670A--gzoptional parts of the POSIX standardnetworkmanager.confNetworkManager.conf5516002723180A--gzNetworkManager configuration fileownership-8815771238010A--gzCompaq ownership tag retrieveroakdecode-1115804162510A--gzDecode an OAKT printer stream into human readable form.gvfs-save-1115868766090A--gzmkfs.minix-8815953177680A--gzmake a Minix filesystemuri7-7715812813670A--gzuniform resource identifier (URI), including a URL or URNedit-1115714399500B--gzexecute programs via entries in the mailcap filegit-diff-files-1116148628880A--gzCompares files in the working tree and the index.ldaprc-5516136581350Cldap.conf-gzpactl-1116219586 |