Linux
Analysis Report
morte.spc.elf
Overview
General Information
Detection
Okiru
Score: | 60 |
Range: | 0 - 100 |
Signatures
Multi AV Scanner detection for submitted file
Yara detected Okiru
Contains symbols with names commonly found in malware
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1648658 |
Start date and time: | 2025-03-26 03:53:14 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 25s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | morte.spc.elf |
Detection: | MAL |
Classification: | mal60.troj.linELF@0/0@2/0 |
Cookbook Comments: |
|
- VT rate limit hit for: http://176.65.142.252/bins/morte.%s;
- VT rate limit hit for: http://176.65.142.252/c.sh;
- VT rate limit hit for: http://176.65.142.252/w.sh;
Command: | /tmp/morte.spc.elf |
PID: | 5437 |
Exit Code: | 255 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: | /lib/ld-uClibc.so.0: No such file or directory |
- system is lnxubuntu20
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Okiru | Yara detected Okiru | Joe Security | ||
JoeSecurity_Okiru | Yara detected Okiru | Joe Security |
⊘No Suricata rule has matched
- • AV Detection
- • Spreading
- • Networking
- • System Summary
- • Malware Analysis System Evasion
- • Stealing of Sensitive Information
- • Remote Access Functionality
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: |