Edit tour

Linux Analysis Report
gigab.sh4.elf

Overview

General Information

Sample name:gigab.sh4.elf
Analysis ID:1644026
MD5:04b75dd7d7a0124f93cbe5a4cf1cf7f2
SHA1:8b31115e0cf85aadaca631af22206704087a3506
SHA256:61ccdc4ed2ada027ced0a00075bfbfb4851f6882e795fde97c9e7cdb46384abe
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1644026
Start date and time:2025-03-20 10:20:47 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:gigab.sh4.elf
Detection:MAL
Classification:mal52.spre.linELF@0/0@0/0
Command:/tmp/gigab.sh4.elf
PID:6274
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • gigab.sh4.elf (PID: 6274, Parent: 6194, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/gigab.sh4.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: gigab.sh4.elfVirustotal: Detection: 28%Perma Link
Source: gigab.sh4.elfReversingLabs: Detection: 30%

Spreading

barindex
Source: /tmp/gigab.sh4.elf (PID: 6274)Opens: /proc/net/routeJump to behavior
Source: global trafficTCP traffic: 192.168.2.23:47560 -> 37.44.238.66:666
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.66
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: classification engineClassification label: mal52.spre.linELF@0/0@0/0
Source: /tmp/gigab.sh4.elf (PID: 6274)Queries kernel information via 'uname': Jump to behavior
Source: gigab.sh4.elf, 6274.1.00007ffea09a9000.00007ffea09ca000.rw-.sdmp, gigab.sh4.elf, 6276.1.00007ffea09a9000.00007ffea09ca000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: gigab.sh4.elf, 6274.1.0000559ef1c96000.0000559ef1cf9000.rw-.sdmp, gigab.sh4.elf, 6276.1.0000559ef1c96000.0000559ef1cf9000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: gigab.sh4.elf, 6274.1.0000559ef1c96000.0000559ef1cf9000.rw-.sdmp, gigab.sh4.elf, 6276.1.0000559ef1c96000.0000559ef1cf9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: gigab.sh4.elf, 6274.1.00007ffea09a9000.00007ffea09ca000.rw-.sdmp, gigab.sh4.elf, 6276.1.00007ffea09a9000.00007ffea09ca000.rw-.sdmpBinary or memory string: d1x86_64/usr/bin/qemu-sh4/tmp/gigab.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/gigab.sh4.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Remote System Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1644026 Sample: gigab.sh4.elf Startdate: 20/03/2025 Architecture: LINUX Score: 52 15 109.202.202.202, 80 INIT7CH Switzerland 2->15 17 37.44.238.66, 47560, 666 HARMONYHOSTING-ASFR France 2->17 19 2 other IPs or domains 2->19 21 Multi AV Scanner detection for submitted file 2->21 8 gigab.sh4.elf 2->8         started        signatures3 process4 signatures5 23 Opens /proc/net/* files useful for finding connected devices and routers 8->23 11 gigab.sh4.elf 8->11         started        process6 process7 13 gigab.sh4.elf 11->13         started       
SourceDetectionScannerLabelLink
gigab.sh4.elf29%VirustotalBrowse
gigab.sh4.elf31%ReversingLabsLinux.Backdoor.Bashlite
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
37.44.238.66
unknownFrance
49434HARMONYHOSTING-ASFRfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
37.44.238.66gigab.m68.elfGet hashmaliciousUnknownBrowse
    gigab.arm5.elfGet hashmaliciousUnknownBrowse
      gigab.mips.elfGet hashmaliciousUnknownBrowse
        gigab.mips.elfGet hashmaliciousGafgytBrowse
          gigab.spc.elfGet hashmaliciousGafgytBrowse
            gigab.arm5.elfGet hashmaliciousGafgytBrowse
              gigab.arm4.elfGet hashmaliciousGafgytBrowse
                gigab.x86.elfGet hashmaliciousGafgytBrowse
                  gigab.ppc.elfGet hashmaliciousGafgytBrowse
                    gigab.sh4.elfGet hashmaliciousGafgytBrowse
                      91.189.91.43gigab.ppc.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                Aqua.m68k.elfGet hashmaliciousUnknownBrowse
                                  hiss.arm5.elfGet hashmaliciousUnknownBrowse
                                    boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                      boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                        boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                          91.189.91.42gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                                    Aqua.m68k.elfGet hashmaliciousUnknownBrowse
                                                      hiss.arm5.elfGet hashmaliciousUnknownBrowse
                                                        boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              HARMONYHOSTING-ASFRgigab.m68.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              spim.elfGet hashmaliciousMiraiBrowse
                                                              • 37.44.238.92
                                                              686i.elfGet hashmaliciousMiraiBrowse
                                                              • 37.44.238.88
                                                              gigab.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 37.44.238.66
                                                              l7vmra.elfGet hashmaliciousMiraiBrowse
                                                              • 37.44.238.92
                                                              gigab.mips.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.spc.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.arm5.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              gigab.arm4.elfGet hashmaliciousGafgytBrowse
                                                              • 37.44.238.66
                                                              CANONICAL-ASGBhiss.arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Aqua.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              hiss.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              CANONICAL-ASGBhiss.arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              gigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Aqua.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              hiss.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              INIT7CHgigab.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Aqua.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              hiss.arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, not stripped
                                                              Entropy (8bit):6.882292880364253
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:gigab.sh4.elf
                                                              File size:76'480 bytes
                                                              MD5:04b75dd7d7a0124f93cbe5a4cf1cf7f2
                                                              SHA1:8b31115e0cf85aadaca631af22206704087a3506
                                                              SHA256:61ccdc4ed2ada027ced0a00075bfbfb4851f6882e795fde97c9e7cdb46384abe
                                                              SHA512:1c5c05f1ba670b35dc89bc4704a7bf41eb6a74a423a0d0f10777e66db2e3429c8a1d7f29bd1dc7daa13bd24a238c98ebb2108ac5e43a729b746494c60ffdfbc6
                                                              SSDEEP:768:AE/ykbKJp1YNeQgVDnJUgfd5ZpiQTlAVqVGgTNBtJwflo5ZtsFMynWADPI8:NbKJp1Wwxf7iQhTGCBtilo5rsFMwH
                                                              TLSH:9B733A868A71AEB3C003E8B434FA99740B167D61571E1EA4503ADBE4034FDCAF58EB75
                                                              File Content Preview:.ELF..............*.......@.4....%......4. ...(...............@...@...........................B...B......s..............$...$.B.$.B.................Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l.............................

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 18
                                                              • 666 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Mar 20, 2025 10:21:47.318087101 CET43928443192.168.2.2391.189.91.42
                                                              Mar 20, 2025 10:21:48.590595961 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:21:48.755677938 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:21:48.755846977 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:21:48.757101059 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:21:48.924283981 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:21:49.621889114 CET4251680192.168.2.23109.202.202.202
                                                              Mar 20, 2025 10:21:52.949443102 CET42836443192.168.2.2391.189.91.43
                                                              Mar 20, 2025 10:22:07.283374071 CET43928443192.168.2.2391.189.91.42
                                                              Mar 20, 2025 10:22:12.507019997 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:22:12.507122993 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:22:12.671108961 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:22:12.671195984 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:22:19.569776058 CET42836443192.168.2.2391.189.91.43
                                                              Mar 20, 2025 10:22:19.569830894 CET4251680192.168.2.23109.202.202.202
                                                              Mar 20, 2025 10:22:48.237873077 CET43928443192.168.2.2391.189.91.42
                                                              Mar 20, 2025 10:23:12.512608051 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:23:12.513010025 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:23:12.678306103 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:23:12.678633928 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:24:12.515429974 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:24:12.515646935 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:24:12.685609102 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:24:12.685924053 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:25:12.520566940 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:25:12.520888090 CET47560666192.168.2.2337.44.238.66
                                                              Mar 20, 2025 10:25:12.686425924 CET6664756037.44.238.66192.168.2.23
                                                              Mar 20, 2025 10:25:12.686644077 CET47560666192.168.2.2337.44.238.66

                                                              System Behavior

                                                              Start time (UTC):09:21:47
                                                              Start date (UTC):20/03/2025
                                                              Path:/tmp/gigab.sh4.elf
                                                              Arguments:/tmp/gigab.sh4.elf
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):09:21:47
                                                              Start date (UTC):20/03/2025
                                                              Path:/tmp/gigab.sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                              Start time (UTC):09:21:47
                                                              Start date (UTC):20/03/2025
                                                              Path:/tmp/gigab.sh4.elf
                                                              Arguments:-
                                                              File size:4139976 bytes
                                                              MD5 hash:8943e5f8f8c280467b4472c15ae93ba9