Edit tour

Linux Analysis Report
skid.armv7l.elf

Overview

General Information

Sample name:skid.armv7l.elf
Analysis ID:1670265
MD5:69bebc09bbfd6a5a3303bde5b1cc855d
SHA1:5bf2e3b9d54d39435936501833771f330aa0ba23
SHA256:54fef35548fda687a444bc628e7b2c5ca3da1f64e34165f67b6e778956f38e7f
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Suricata IDS alerts for network traffic
Connects to many ports of the same IP (likely port scanning)
Performs DNS TXT record lookups
Uses STUN server to do NAT traversial
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1670265
Start date and time:2025-04-21 13:08:12 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:skid.armv7l.elf
Detection:MAL
Classification:mal60.troj.evad.linELF@0/5@2/0
Command:/tmp/skid.armv7l.elf
PID:5552
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
snow slide
Standard Error:
  • system is lnxubuntu20
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-04-21T13:08:57.825436+020028120671Malware Command and Control Activity Detected192.168.2.15576028.8.8.853UDP

Click to jump to signature section

Show All Signature Results

Networking

barindex
Source: Network trafficSuricata IDS: 2812067 - Severity 1 - ETPRO MALWARE SOGU DNS CnC Channel TXT Lookup : 192.168.2.15:57602 -> 8.8.8.8:53
Source: global trafficTCP traffic: 93.95.115.22 ports 1,2,3,4,5,12345
Source: unknownDNS query: name: stun.l.google.com
Source: global trafficTCP traffic: 192.168.2.15:45408 -> 93.95.115.22:12345
Source: global trafficUDP traffic: 192.168.2.15:38915 -> 74.125.250.129:19302
Source: /tmp/skid.armv7l.elf (PID: 5554)Socket: 127.0.0.1:24676Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: unknownTCP traffic detected without corresponding DNS query: 93.95.115.22
Source: global trafficDNS traffic detected: DNS query: 6mv1eyr328y6due83u3js6whtzuxfyhw.su
Source: global trafficDNS traffic detected: DNS query: stun.l.google.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.evad.linELF@0/5@2/0
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/5389/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1333/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1695/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/911/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/914/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1591/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1585/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/3883/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/802/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/804/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/3407/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1484/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/133/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1479/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/931/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1595/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/812/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/933/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/3419/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/3310/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/262/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/142/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/263/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/264/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/265/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/145/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/266/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/267/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/268/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/3303/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/269/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1486/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/1806/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5554)File opened: /proc/3440/cmdlineJump to behavior
Source: /tmp/skid.armv7l.elf (PID: 5552)Queries kernel information via 'uname': Jump to behavior
Source: skid.armv7l.elf, 5552.1.0000555902129000.0000555902278000.rw-.sdmpBinary or memory string: YU!/etc/qemu-binfmt/arm
Source: skid.armv7l.elf, 5552.1.0000555902129000.0000555902278000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: skid.armv7l.elf, 5552.1.00007ffe5101c000.00007ffe5103d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: skid.armv7l.elf, 5552.1.00007ffe5101c000.00007ffe5103d000.rw-.sdmpBinary or memory string: $#x86_64/usr/bin/qemu-arm/tmp/skid.armv7l.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/skid.armv7l.elf

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: 6mv1eyr328y6due83u3js6whtzuxfyhw.su
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1670265 Sample: skid.armv7l.elf Startdate: 21/04/2025 Architecture: LINUX Score: 60 14 stun.l.google.com 2->14 16 6mv1eyr328y6due83u3js6whtzuxfyhw.su 2->16 18 2 other IPs or domains 2->18 20 Suricata IDS alerts for network traffic 2->20 22 Connects to many ports of the same IP (likely port scanning) 2->22 8 skid.armv7l.elf 2->8         started        signatures3 24 Uses STUN server to do NAT traversial 14->24 26 Performs DNS TXT record lookups 16->26 process4 process5 10 skid.armv7l.elf 8->10         started        process6 12 skid.armv7l.elf 10->12         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
skid.armv7l.elf8%ReversingLabsLinux.Worm.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
stun.l.google.com
74.125.250.129
truefalse
    high
    6mv1eyr328y6due83u3js6whtzuxfyhw.su
    unknown
    unknownfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      93.95.115.22
      unknownNetherlands
      35705PELICAN-ICTNLtrue
      74.125.250.129
      stun.l.google.comUnited States
      15169GOOGLEUSfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      93.95.115.22lol.armv7l.elfGet hashmaliciousUnknownBrowse
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        PELICAN-ICTNLlol.armv7l.elfGet hashmaliciousUnknownBrowse
        • 93.95.115.22
        skid.armv5l.elfGet hashmaliciousUnknownBrowse
        • 93.95.115.35
        sh4.elfGet hashmaliciousUnknownBrowse
        • 93.95.115.35
        arm7.elfGet hashmaliciousMiraiBrowse
        • 93.95.115.35
        HSBC PAYMENT CONFIRMATION COPY.PDF.exeGet hashmaliciousRemcos, GuLoaderBrowse
        • 93.95.115.2
        HSBC COPY.PDF.exeGet hashmaliciousRemcos, GuLoaderBrowse
        • 93.95.115.2
        HSBC COPY.PDF.exeGet hashmaliciousRemcos, GuLoaderBrowse
        • 93.95.115.2
        SecuriteInfo.com.Win32.Trojan.CobaltStrike.4EYNH5.5772.17622.dllGet hashmaliciousCobaltStrikeBrowse
        • 93.95.115.21
        No context
        No context
        Process:/tmp/skid.armv7l.elf
        File Type:ASCII text, with no line terminators
        Category:dropped
        Size (bytes):21
        Entropy (8bit):4.011365041826379
        Encrypted:false
        SSDEEP:3:TgJuEtgl:Tg5tgl
        MD5:A4CE74F8268011D2644AF20AB79E7627
        SHA1:13CE4F7675DB3BD073DDA202B1E329F079FC6BB6
        SHA-256:DC2D298D3317A53FBB7F28632793EEEF7EAF2FB7CF8B1186DF97BF4AFE816EA0
        SHA-512:004FBC3D639FDF61C61A765759A1D7E989ADF2347BC54A454314C5738DE49210F6FB44CC6D718D5105D62E1B2E4E0A2E0C34F1020A09262D39A6CCBC831AE557
        Malicious:false
        Reputation:low
        Preview:/tmp/skid.armv7l.elf.
        Process:/tmp/skid.armv7l.elf
        File Type:ASCII text, with no line terminators
        Category:dropped
        Size (bytes):21
        Entropy (8bit):4.011365041826379
        Encrypted:false
        SSDEEP:3:TgJuEtgl:Tg5tgl
        MD5:A4CE74F8268011D2644AF20AB79E7627
        SHA1:13CE4F7675DB3BD073DDA202B1E329F079FC6BB6
        SHA-256:DC2D298D3317A53FBB7F28632793EEEF7EAF2FB7CF8B1186DF97BF4AFE816EA0
        SHA-512:004FBC3D639FDF61C61A765759A1D7E989ADF2347BC54A454314C5738DE49210F6FB44CC6D718D5105D62E1B2E4E0A2E0C34F1020A09262D39A6CCBC831AE557
        Malicious:false
        Reputation:low
        Preview:/tmp/skid.armv7l.elf.
        Process:/tmp/skid.armv7l.elf
        File Type:ASCII text, with no line terminators
        Category:dropped
        Size (bytes):21
        Entropy (8bit):4.011365041826379
        Encrypted:false
        SSDEEP:3:TgJuEtgl:Tg5tgl
        MD5:A4CE74F8268011D2644AF20AB79E7627
        SHA1:13CE4F7675DB3BD073DDA202B1E329F079FC6BB6
        SHA-256:DC2D298D3317A53FBB7F28632793EEEF7EAF2FB7CF8B1186DF97BF4AFE816EA0
        SHA-512:004FBC3D639FDF61C61A765759A1D7E989ADF2347BC54A454314C5738DE49210F6FB44CC6D718D5105D62E1B2E4E0A2E0C34F1020A09262D39A6CCBC831AE557
        Malicious:false
        Reputation:low
        Preview:/tmp/skid.armv7l.elf.
        Process:/tmp/skid.armv7l.elf
        File Type:ASCII text, with no line terminators
        Category:dropped
        Size (bytes):21
        Entropy (8bit):4.011365041826379
        Encrypted:false
        SSDEEP:3:TgJuEtgl:Tg5tgl
        MD5:A4CE74F8268011D2644AF20AB79E7627
        SHA1:13CE4F7675DB3BD073DDA202B1E329F079FC6BB6
        SHA-256:DC2D298D3317A53FBB7F28632793EEEF7EAF2FB7CF8B1186DF97BF4AFE816EA0
        SHA-512:004FBC3D639FDF61C61A765759A1D7E989ADF2347BC54A454314C5738DE49210F6FB44CC6D718D5105D62E1B2E4E0A2E0C34F1020A09262D39A6CCBC831AE557
        Malicious:false
        Reputation:low
        Preview:/tmp/skid.armv7l.elf.
        Process:/tmp/skid.armv7l.elf
        File Type:ASCII text, with no line terminators
        Category:dropped
        Size (bytes):21
        Entropy (8bit):4.011365041826379
        Encrypted:false
        SSDEEP:3:TgJuEtgl:Tg5tgl
        MD5:A4CE74F8268011D2644AF20AB79E7627
        SHA1:13CE4F7675DB3BD073DDA202B1E329F079FC6BB6
        SHA-256:DC2D298D3317A53FBB7F28632793EEEF7EAF2FB7CF8B1186DF97BF4AFE816EA0
        SHA-512:004FBC3D639FDF61C61A765759A1D7E989ADF2347BC54A454314C5738DE49210F6FB44CC6D718D5105D62E1B2E4E0A2E0C34F1020A09262D39A6CCBC831AE557
        Malicious:false
        Reputation:low
        Preview:/tmp/skid.armv7l.elf.
        File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
        Entropy (8bit):6.142589189167621
        TrID:
        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
        File name:skid.armv7l.elf
        File size:122'660 bytes
        MD5:69bebc09bbfd6a5a3303bde5b1cc855d
        SHA1:5bf2e3b9d54d39435936501833771f330aa0ba23
        SHA256:54fef35548fda687a444bc628e7b2c5ca3da1f64e34165f67b6e778956f38e7f
        SHA512:8d0836f20895c98f082e46e67a31056600113d269dc611ca89a275950d8b1585ee96ec6f2ddd26772c98856cebde404baab3b54b123bab867a63b855311d1b94
        SSDEEP:3072:TmY6ih2Oz3Y2E0zyaSGqJ3frU00npCxcyIQXu3:Tyd2E9dGUr/0npCxcnQe3
        TLSH:51C31A4DE892AB15C1DA25BAFE5E448D330717FCD3EA71158C111B61A38F94E0F3EA86
        File Content Preview:.ELF..............(.........4...........4. ...(........p.....X...X..(...(................................................................1..........................................Q.td..................................-...L..................G.F.G.F.G.F.G.

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:ARM
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:UNIX - System V
        ABI Version:0
        Entry Point Address:0x81d0
        Flags:0x4000002
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:5
        Section Header Offset:122020
        Section Header Size:40
        Number of Section Headers:16
        Header String Table Index:15
        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .initPROGBITS0x80d40xd40x100x00x6AX004
        .textPROGBITS0x80f00xf00x1d0740x00x6AX0016
        .finiPROGBITS0x251640x1d1640x100x00x6AX004
        .rodataPROGBITS0x251740x1d1740x7400x00x2A004
        .ARM.extabPROGBITS0x258b40x1d8b40x180x00x2A004
        .ARM.exidxARM_EXIDX0x258cc0x1d8cc0x1280x00x82AL204
        .eh_framePROGBITS0x2d9f40x1d9f40x40x00x3WA004
        .tbssNOBITS0x2d9f80x1d9f80x80x00x403WAT004
        .init_arrayINIT_ARRAY0x2d9f80x1d9f80x40x00x3WA004
        .fini_arrayFINI_ARRAY0x2d9fc0x1d9fc0x40x00x3WA004
        .gotPROGBITS0x2da040x1da040xac0x40x3WA004
        .dataPROGBITS0x2dab00x1dab00x1580x00x3WA004
        .bssNOBITS0x2dc080x1dc080x2ef00x00x3WA008
        .ARM.attributesARM_ATTRIBUTES0x00x1dc080x160x00x0001
        .shstrtabSTRTAB0x00x1dc1e0x830x00x0001
        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        EXIDX0x1d8cc0x258cc0x258cc0x1280x1284.59520x4R 0x4.ARM.exidx
        LOAD0x00x80000x80000x1d9f40x1d9f46.15520x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
        LOAD0x1d9f40x2d9f40x2d9f40x2140x31042.62710x6RW 0x8000.eh_frame .tbss .init_array .fini_array .got .data .bss
        TLS0x1d9f80x2d9f80x2d9f80x00x80.00000x4R 0x4.tbss
        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

        Download Network PCAP: filteredfull

        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
        2025-04-21T13:08:57.825436+02002812067ETPRO MALWARE SOGU DNS CnC Channel TXT Lookup1192.168.2.15576028.8.8.853UDP
        • Total Packets: 29
        • 19302 undefined
        • 12345 undefined
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Apr 21, 2025 13:08:58.026567936 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:58.301913023 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:08:58.303328037 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:58.303328037 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:58.578685045 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:08:58.578743935 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:58.853902102 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:08:58.853920937 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:08:58.854677916 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:58.856081009 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:59.172319889 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:08:59.172482967 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:59.447796106 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:08:59.447813034 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:08:59.448725939 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:08:59.835774899 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:00.151492119 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:00.151642084 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:00.427567005 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:00.427717924 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:00.427762985 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:13.857280016 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:13.857345104 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:13.857620001 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:14.173155069 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:14.173218012 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:14.448064089 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:33.562630892 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:33.562789917 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:48.971982002 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:48.972162008 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:50.235038996 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:50.235229969 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:50.235500097 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:50.510668039 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:09:50.510945082 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:09:50.787431955 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:05.803035021 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:05.803160906 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:10:22.239372969 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:22.239656925 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:10:24.466995001 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:24.467173100 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:10:24.744319916 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:24.744379044 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:10:25.019489050 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:40.550187111 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:40.550328970 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:10:56.549591064 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:10:56.549701929 CEST4540812345192.168.2.1593.95.115.22
        Apr 21, 2025 13:11:01.890486002 CEST123454540893.95.115.22192.168.2.15
        Apr 21, 2025 13:11:01.890738010 CEST4540812345192.168.2.1593.95.115.22
        TimestampSource PortDest PortSource IPDest IP
        Apr 21, 2025 13:08:57.825436115 CEST5760253192.168.2.158.8.8.8
        Apr 21, 2025 13:08:58.024715900 CEST53576028.8.8.8192.168.2.15
        Apr 21, 2025 13:08:59.448741913 CEST4934953192.168.2.158.8.8.8
        Apr 21, 2025 13:08:59.649529934 CEST53493498.8.8.8192.168.2.15
        Apr 21, 2025 13:08:59.649909973 CEST3891519302192.168.2.1574.125.250.129
        Apr 21, 2025 13:08:59.835058928 CEST193023891574.125.250.129192.168.2.15
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 21, 2025 13:08:57.825436115 CEST192.168.2.158.8.8.80x2eb6Standard query (0)6mv1eyr328y6due83u3js6whtzuxfyhw.su16IN (0x0001)false
        Apr 21, 2025 13:08:59.448741913 CEST192.168.2.158.8.8.80x1f85Standard query (0)stun.l.google.comA (IP address)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 21, 2025 13:08:58.024715900 CEST8.8.8.8192.168.2.150x2eb6No error (0)6mv1eyr328y6due83u3js6whtzuxfyhw.suTXT (Text strings)IN (0x0001)false
        Apr 21, 2025 13:08:58.024715900 CEST8.8.8.8192.168.2.150x2eb6No error (0)6mv1eyr328y6due83u3js6whtzuxfyhw.suTXT (Text strings)IN (0x0001)false
        Apr 21, 2025 13:08:58.024715900 CEST8.8.8.8192.168.2.150x2eb6No error (0)6mv1eyr328y6due83u3js6whtzuxfyhw.suTXT (Text strings)IN (0x0001)false
        Apr 21, 2025 13:08:58.024715900 CEST8.8.8.8192.168.2.150x2eb6No error (0)6mv1eyr328y6due83u3js6whtzuxfyhw.suTXT (Text strings)IN (0x0001)false
        Apr 21, 2025 13:08:58.024715900 CEST8.8.8.8192.168.2.150x2eb6No error (0)6mv1eyr328y6due83u3js6whtzuxfyhw.suTXT (Text strings)IN (0x0001)false
        Apr 21, 2025 13:08:58.024715900 CEST8.8.8.8192.168.2.150x2eb6No error (0)6mv1eyr328y6due83u3js6whtzuxfyhw.suTXT (Text strings)IN (0x0001)false
        Apr 21, 2025 13:08:58.024715900 CEST8.8.8.8192.168.2.150x2eb6No error (0)6mv1eyr328y6due83u3js6whtzuxfyhw.suTXT (Text strings)IN (0x0001)false
        Apr 21, 2025 13:08:59.649529934 CEST8.8.8.8192.168.2.150x1f85No error (0)stun.l.google.com74.125.250.129A (IP address)IN (0x0001)false

        System Behavior

        Start time (UTC):11:08:55
        Start date (UTC):21/04/2025
        Path:/tmp/skid.armv7l.elf
        Arguments:/tmp/skid.armv7l.elf
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

        Start time (UTC):11:08:57
        Start date (UTC):21/04/2025
        Path:/tmp/skid.armv7l.elf
        Arguments:-
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

        Start time (UTC):11:08:57
        Start date (UTC):21/04/2025
        Path:/tmp/skid.armv7l.elf
        Arguments:-
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1