Edit tour

Linux Analysis Report
ddc.elf

Overview

General Information

Sample name:ddc.elf
Analysis ID:1649029
MD5:c5d3dd6cdd487416c2ade9fb118e8de8
SHA1:d21cecf489c3251c5c8569f9b6f7e006cd39f526
SHA256:a15c649bcb75ae8b2636d7c00ec4666c6f5b177deeed2fd46dc5851ffc253e01
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Contains symbols related to standard C library sleeps (sometimes used to evade sandboxing)
Sample has stripped symbol table

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1649029
Start date and time:2025-03-26 12:48:32 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 10m 28s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ddc.elf
Detection:MAL
Classification:mal48.linELF@0/0@2/0
Cookbook Comments:
  • Analysis time extended to 480s due to sleep detection in submitted sample
Command:/tmp/ddc.elf
PID:5431
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:

Standard Error:/tmp/ddc.elf: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.32' not found (required by /tmp/ddc.elf)
/tmp/ddc.elf: /lib/x86_64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found (required by /tmp/ddc.elf)
  • system is lnxubuntu20
  • ddc.elf (PID: 5431, Parent: 5354, MD5: c5d3dd6cdd487416c2ade9fb118e8de8) Arguments: /tmp/ddc.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ddc.elfVirustotal: Detection: 10%Perma Link
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ddc.elfELF static info symbol of initial sample: freeaddrinfo
Source: ddc.elfELF static info symbol of initial sample: gai_strerror
Source: ddc.elfELF static info symbol of initial sample: getaddrinfo
Source: ddc.elfELF static info symbol of initial sample: getnameinfo
Source: ddc.elfString found in binary or memory: http://fontello.com
Source: ddc.elfString found in binary or memory: https://github.com/quic-go/quic-go/wiki/Loggingx509:
Source: ddc.elfString found in binary or memory: https://github.com/quic-go/quic-go/wiki/UDP-Receive-Buffer-Size
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@2/0
Source: ELF file sectionSubmission: ddc.elf
Source: ELF symbol in initial sampleSymbol name: nanosleep
Source: ddc.elfBinary or memory string: Subject: AMDisbetter!AuthenticAMDBidi_ControlCIDR addressCONTINUATIONCentaurHaulsContent-TypeCookie.ValueDoing 0-RTT.Duration: %vECDSA-SHA256ECDSA-SHA384ECDSA-SHA512Genuine RDCGenuineIntelGenuineTMx86Geode by NSCHygonGenuineI'm a teapotI/O possibleInstAltMatchJoin_ControlKVMKVMKVMKVMLittleEndianMax-ForwardsMeetei_MayekMicrosoft HvMime-VersionMulti-StatusNot ExtendedNot ModifiedPUSH_PROMISEPahawh_HmongRCPT TO:<%s>RCodeRefusedRCodeSuccessRiseRiseRiseSERIALNUMBERSSL_CERT_DIRSiS SiS SiS Sora_SompengSyloti_NagriThe field: 'Token: %#x, TransmetaCPUUnauthorizedVIA VIA VIA VMwareVMwareVortex86 SoCX-ImforwardsX-Powered-ByXenVMMXenVMM^(37)?\d{4}$^(?:\d{5})?$^(BB\d{5})?$^[0-9]{1,6}$abi mismatchaccess_tokenalphaunicodealtmatch -> anynotnl -> avx5124fmapsavx512bitalgbad flushGenbad g statusbad recoverybhyve bhyve block clausec ap trafficc hs trafficcaller errorcan't happencas64 failedchan receivecheck failedchild exitedclose notifycontainsrunecontent-typecontext.TODOcountry_codedata_on_idledumping heapdup_trailersecho requestempty packetend tracegc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1649029 Sample: ddc.elf Startdate: 26/03/2025 Architecture: LINUX Score: 48 8 daisy.ubuntu.com 2->8 10 Multi AV Scanner detection for submitted file 2->10 6 ddc.elf 2->6         started        signatures3 process4
SourceDetectionScannerLabelLink
ddc.elf11%VirustotalBrowse
ddc.elf11%ReversingLabsLinux.PUA.Generic
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    https://github.com/quic-go/quic-go/wiki/UDP-Receive-Buffer-Sizeddc.elffalse
      high
      https://github.com/quic-go/quic-go/wiki/Loggingx509:ddc.elffalse
        high
        http://fontello.comddc.elffalse
          high
          No contacted IP infos
          No context
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          daisy.ubuntu.comGoldAge3ATOmpsl.elfGet hashmaliciousUnknownBrowse
          • 162.213.35.25
          frosty.m68k.elfGet hashmaliciousUnknownBrowse
          • 162.213.35.25
          frosty.arm6.elfGet hashmaliciousUnknownBrowse
          • 162.213.35.24
          frosty.arm7.elfGet hashmaliciousUnknownBrowse
          • 162.213.35.24
          GoldAge3ATOppc.elfGet hashmaliciousUnknownBrowse
          • 162.213.35.25
          GoldAge3ATOx86.elfGet hashmaliciousUnknownBrowse
          • 162.213.35.25
          GoldAge3ATOx64.elfGet hashmaliciousUnknownBrowse
          • 162.213.35.24
          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
          • 162.213.35.25
          boatnet.m68k.elfGet hashmaliciousMiraiBrowse
          • 162.213.35.24
          boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
          • 162.213.35.25
          No context
          No context
          No context
          No created / dropped files found
          File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, Go BuildID=jB66tSXV3gevZsUtvoah/I3AggyZzHsCv2WpTHvL0/tp-ye0tEpSGPzJ5yXsdQ/Pj5AXBmoVfJmKpEPZIu4, stripped
          Entropy (8bit):6.311042270282006
          TrID:
          • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
          • ELF Executable and Linkable format (generic) (4004/1) 49.46%
          • Lumena CEL bitmap (63/63) 0.78%
          File name:ddc.elf
          File size:12'992'512 bytes
          MD5:c5d3dd6cdd487416c2ade9fb118e8de8
          SHA1:d21cecf489c3251c5c8569f9b6f7e006cd39f526
          SHA256:a15c649bcb75ae8b2636d7c00ec4666c6f5b177deeed2fd46dc5851ffc253e01
          SHA512:457444c19826e277b22b9e475992895031f45d7c7f00c433433748eea556fc252807a262247f97dd15295039024f6504eca2d1fecb500c32f440a3c5aea94d9d
          SSDEEP:98304:15QN78PULUo30FFpG8OICTEOF76QvWfHsAmV6PSLh:15QNFQCQXjO4QWHsAm0PSLh
          TLSH:E1D65A43F85190E8C1AED170C6669293BB707C895B3167D33B20F6B92B72BD46B7A350
          File Content Preview:.ELF..............>..... .F.....@.......p...........@.8...@.............@.......@.@.....@.@.....0.......0.................................@.......@...............................................@.......@.....d.......d.................................@....

          ELF header

          Class:ELF64
          Data:2's complement, little endian
          Version:1 (current)
          Machine:Advanced Micro Devices X86-64
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - System V
          ABI Version:0
          Entry Point Address:0x46e620
          Flags:0x0
          ELF Header Size:64
          Program Header Offset:64
          Program Header Size:56
          Number of Program Headers:10
          Section Header Offset:624
          Section Header Size:64
          Number of Section Headers:27
          Header String Table Index:9
          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
          NULL0x00x00x00x00x0000
          .textPROGBITS0x4010000x10000x5a23680x00x6AX0032
          .pltPROGBITS0x9a33800x5a33800x2200x100x6AX0016
          .rodataPROGBITS0x9a40000x5a40000x320ae00x00x2A0032
          .relaRELA0xcc4ae00x8c4ae00x180x180x2A1108
          .rela.pltRELA0xcc4af80x8c4af80x3180x180x2A1128
          .gnu.versionVERSYM0xcc4e200x8c4e200x4c0x20x2A1102
          .gnu.version_rVERNEED0xcc4e800x8c4e800x500x00x2A1018
          .hashHASH0xcc4ee00x8c4ee00xbc0x40x2A1108
          .shstrtabSTRTAB0x00x8c4fa00x1050x00x0001
          .dynstrSTRTAB0xcc50c00x8c50c00x2090x00x2A001
          .dynsymDYNSYM0xcc52e00x8c52e00x3900x180x2A1018
          .typelinkPROGBITS0xcc56800x8c56800x3fac0x00x2A0032
          .itablinkPROGBITS0xcc96400x8c96400x17180x00x2A0032
          .gosymtabPROGBITS0xccad580x8cad580x00x00x2A001
          .gopclntabPROGBITS0xccad600x8cad600x3362c80x00x2A0032
          .go.buildinfoPROGBITS0x10020000xc020000xd900x00x3WA0016
          .dynamicDYNAMIC0x1002da00xc02da00x1200x100x3WA1008
          .got.pltPROGBITS0x1002ec00xc02ec00x1200x80x3WA008
          .gotPROGBITS0x1002fe00xc02fe00x80x80x3WA008
          .noptrdataPROGBITS0x10030000xc030000x4f2400x00x3WA0032
          .dataPROGBITS0x10522400xc522400x112f00x00x3WA0032
          .bssNOBITS0x10635400xc635400x347000x00x3WA0032
          .noptrbssNOBITS0x1097c400xc97c400xf4300x00x3WA0032
          .tbssNOBITS0x00x00x80x00x403WAT008
          .interpPROGBITS0x400fe40xfe40x1c0x00x2A001
          .note.go.buildidNOTE0x400f800xf800x640x00x2A004
          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          PHDR0x400x4000400x4000400x2300x2301.63960x4R 0x1000
          INTERP0xfe40x400fe40x400fe40x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
          NOTE0xf800x400f800x400f800x640x645.20570x4R 0x4.note.go.buildid
          LOAD0x00x4000000x4000000x5a35a00x5a35a06.14130x5R E0x1000.text .plt .interp .note.go.buildid
          LOAD0x5a40000x9a40000x9a40000x65d0280x65d0285.84560x4R 0x1000.rodata .rela .rela.plt .gnu.version .gnu.version_r .hash .dynstr .dynsym .typelink .itablink .gosymtab .gopclntab
          LOAD0xc020000x10020000x10020000x615400xa50705.71070x6RW 0x1000.go.buildinfo .dynamic .got.plt .got .noptrdata .data .bss .noptrbss
          DYNAMIC0xc02da00x1002da00x1002da00x1200x1201.69690x6RW 0x8.dynamic
          TLS0x00x00x00x00x80.00000x4R 0x8.tbss
          GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
          LOOS+50415800x00x00x00x00x00.00000x2a00 0x8
          TypeMetaValueTag
          DT_HASHvalue0xcc4ee00x4
          DT_SYMTABvalue0xcc52e00x6
          DT_SYMENTbytes240xb
          DT_STRTABvalue0xcc50c00x5
          DT_STRSZbytes5210xa
          DT_RELAvalue0xcc4ae00x7
          DT_RELASZbytes240x8
          DT_RELAENTbytes240x9
          DT_PLTGOTvalue0x1002ec00x3
          DT_DEBUGvalue0x00x15
          DT_NEEDEDsharedliblibc.so.60x1
          DT_VERNEEDvalue0xcc4e800x6ffffffe
          DT_VERNEEDNUMvalue10x6fffffff
          DT_VERSYMvalue0xcc4e200x6ffffff0
          DT_PLTRELpltrelDT_RELA0x14
          DT_PLTRELSZbytes7920x2
          DT_JMPRELvalue0xcc4af80x17
          DT_NULLvalue0x00x0
          NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
          .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
          __errno_locationGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          _cgo_panic.dynsym0x5b56c055FUNC<unknown>DEFAULT1
          _cgo_topofstack.dynsym0x46cee025FUNC<unknown>DEFAULT1
          abortGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          crosscall2.dynsym0x5b570099FUNC<unknown>DEFAULT1
          fprintfGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          fputcGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          freeGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          freeaddrinfoGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          fwriteGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          gai_strerrorGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          getaddrinfoGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          getnameinfoGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          mallocGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          mmapGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          munmapGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          nanosleepGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_attr_destroyGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_attr_getstacksizeGLIBC_2.34libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_attr_initGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_cond_broadcastGLIBC_2.3.2libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_cond_waitGLIBC_2.3.2libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_createGLIBC_2.34libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_detachGLIBC_2.34libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_mutex_lockGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_mutex_unlockGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          pthread_sigmaskGLIBC_2.32libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          setenvGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          sigactionGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          sigaddsetGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          sigemptysetGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          sigfillsetGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          sigismemberGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          stderrGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          strerrorGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          unsetenvGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
          vfprintfGLIBC_2.2.5libc.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF

          Download Network PCAP: filteredfull

          TimestampSource PortDest PortSource IPDest IP
          Mar 26, 2025 12:51:59.212387085 CET3846553192.168.2.131.1.1.1
          Mar 26, 2025 12:51:59.214183092 CET5084853192.168.2.131.1.1.1
          Mar 26, 2025 12:51:59.309936047 CET53384651.1.1.1192.168.2.13
          Mar 26, 2025 12:51:59.314057112 CET53508481.1.1.1192.168.2.13
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Mar 26, 2025 12:51:59.212387085 CET192.168.2.131.1.1.10xfa1bStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
          Mar 26, 2025 12:51:59.214183092 CET192.168.2.131.1.1.10x5b74Standard query (0)daisy.ubuntu.com28IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Mar 26, 2025 12:51:59.309936047 CET1.1.1.1192.168.2.130xfa1bNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
          Mar 26, 2025 12:51:59.309936047 CET1.1.1.1192.168.2.130xfa1bNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

          System Behavior

          Start time (UTC):11:49:14
          Start date (UTC):26/03/2025
          Path:/tmp/ddc.elf
          Arguments:/tmp/ddc.elf
          File size:12992512 bytes
          MD5 hash:c5d3dd6cdd487416c2ade9fb118e8de8