Edit tour

Linux Analysis Report
linux.elf

Overview

General Information

Sample name:linux.elf
Analysis ID:1674634
MD5:3214e7da3a50b13260b5f9c24556ae46
SHA1:bc7ee9e5bb27cfaa3f7c3231222fb56efa36e9b4
SHA256:e6bbc3fe61ccb51576d7786b8f5d68d3adf8355684a033bbb41d14a99ade5b56
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Sample is packed with UPX
Creates hidden files and/or directories
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1674634
Start date and time:2025-04-26 07:08:17 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:linux.elf
Detection:MAL
Classification:mal52.evad.linELF@0/0@0/0
Command:/tmp/linux.elf
PID:6242
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • linux.elf (PID: 6242, Parent: 6167, MD5: 3214e7da3a50b13260b5f9c24556ae46) Arguments: /tmp/linux.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: linux.elfVirustotal: Detection: 21%Perma Link
Source: linux.elfReversingLabs: Detection: 41%
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: linux.elfString found in binary or memory: http://upx.sf.net
Source: linux.elf, 6243.1.0000000000400000.0000000000b74000.r-x.sdmpString found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support/dev/urandom
Source: linux.elf, 6242.1.0000000000400000.0000000000b74000.r-x.sdmp, linux.elf, 6243.1.0000000000400000.0000000000b74000.r-x.sdmpString found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support/dev/urandom/dev/randomMalformed
Source: linux.elf, 6242.1.0000000000400000.0000000000b74000.r-x.sdmp, linux.elf, 6243.1.0000000000400000.0000000000b74000.r-x.sdmpString found in binary or memory: https://docs.rs/getrandom#nodejs-es-module-support/dev/urandom/dev/randomlenBadOffsetIOMalformedScro
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: LOAD without section mappingsProgram segment: 0x400000
Source: classification engineClassification label: mal52.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 4.02 Copyright (C) 1996-2023 the UPX Team. All Rights Reserved. $
Source: /tmp/linux.elf (PID: 6243)Directory: /proc/.Jump to behavior
Source: /tmp/linux.elf (PID: 6243)Directory: /proc/6243/.Jump to behavior
Source: linux.elfSubmission file: segment LOAD with 7.5961 entropy (max. 8.0)
Source: linux.elfSubmission file: segment LOAD with 7.9491 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
Obfuscated Files or Information
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1674634 Sample: linux.elf Startdate: 26/04/2025 Architecture: LINUX Score: 52 11 109.202.202.202, 80 INIT7CH Switzerland 2->11 13 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->13 15 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 Sample is packed with UPX 2->19 7 linux.elf 2->7         started        signatures3 process4 process5 9 linux.elf 7->9         started       
SourceDetectionScannerLabelLink
linux.elf22%VirustotalBrowse
linux.elf42%ReversingLabsLinux.Trojan.Multiverze
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netlinux.elffalse
    high
    https://docs.rs/getrandom#nodejs-es-module-support/dev/urandom/dev/randomMalformedlinux.elf, 6242.1.0000000000400000.0000000000b74000.r-x.sdmp, linux.elf, 6243.1.0000000000400000.0000000000b74000.r-x.sdmpfalse
      high
      https://docs.rs/getrandom#nodejs-es-module-support/dev/urandom/dev/randomlenBadOffsetIOMalformedScrolinux.elf, 6242.1.0000000000400000.0000000000b74000.r-x.sdmp, linux.elf, 6243.1.0000000000400000.0000000000b74000.r-x.sdmpfalse
        high
        https://docs.rs/getrandom#nodejs-es-module-support/dev/urandomlinux.elf, 6243.1.0000000000400000.0000000000b74000.r-x.sdmpfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
          91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              S95baby.sh.elfGet hashmaliciousUnknownBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  S95baby.sh.elfGet hashmaliciousUnknownBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                  No context
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  S95baby.sh.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 185.125.190.26
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 185.125.190.26
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  S95baby.sh.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 185.125.190.26
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 185.125.190.26
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 91.189.91.42
                                                  INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  S95baby.sh.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  na.elfGet hashmaliciousPrometeiBrowse
                                                  • 109.202.202.202
                                                  No context
                                                  No context
                                                  No created / dropped files found
                                                  File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                  Entropy (8bit):7.949072039275612
                                                  TrID:
                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                  File name:linux.elf
                                                  File size:3'610'344 bytes
                                                  MD5:3214e7da3a50b13260b5f9c24556ae46
                                                  SHA1:bc7ee9e5bb27cfaa3f7c3231222fb56efa36e9b4
                                                  SHA256:e6bbc3fe61ccb51576d7786b8f5d68d3adf8355684a033bbb41d14a99ade5b56
                                                  SHA512:d3ad5ce2f66227c864cfc03af34efc0328d9c4b9e7323630e9d0e7355302345084a865b36fd6ba265d2d3bf5ea35b27fd56f7702a73af3d8f0168e5882fd324b
                                                  SSDEEP:98304:bD/5IVaPY06J3Rh3Vc4smM/THIVvcDUh6+8zgNmHaZ2FTi:P5IVaq3rVamM/jPzgU1Ti
                                                  TLSH:75F533EC8EBE6AE9341CC7BC35B8534075A86C7A09DC48D16BBEC6071631AD5A7C2371
                                                  File Content Preview:.ELF..............>.....89......@...................@.8...........................@.......@..............................................0.......0........7.......7.............Q.td....................................................#...UPX!..........~..4w

                                                  ELF header

                                                  Class:ELF64
                                                  Data:2's complement, little endian
                                                  Version:1 (current)
                                                  Machine:Advanced Micro Devices X86-64
                                                  Version Number:0x1
                                                  Type:EXEC (Executable file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x1163938
                                                  Flags:0x0
                                                  ELF Header Size:64
                                                  Program Header Offset:64
                                                  Program Header Size:56
                                                  Number of Program Headers:3
                                                  Section Header Offset:0
                                                  Section Header Size:0
                                                  Number of Section Headers:0
                                                  Header String Table Index:0
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  LOAD0x00x4000000x4000000x10000x9f2ed87.59610x6RW 0x1000
                                                  LOAD0x00xdf30000xdf30000x3713fe0x3713fe7.94910x5R E0x1000
                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x10

                                                  Download Network PCAP: filteredfull

                                                  • Total Packets: 8
                                                  • 443 (HTTPS)
                                                  • 80 (HTTP)
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Apr 26, 2025 07:09:05.094111919 CEST43928443192.168.2.2391.189.91.42
                                                  Apr 26, 2025 07:09:10.725298882 CEST42836443192.168.2.2391.189.91.43
                                                  Apr 26, 2025 07:09:11.749114990 CEST4251680192.168.2.23109.202.202.202
                                                  Apr 26, 2025 07:09:26.339008093 CEST43928443192.168.2.2391.189.91.42
                                                  Apr 26, 2025 07:09:36.577548981 CEST42836443192.168.2.2391.189.91.43
                                                  Apr 26, 2025 07:09:42.720690012 CEST4251680192.168.2.23109.202.202.202
                                                  Apr 26, 2025 07:10:07.293107986 CEST43928443192.168.2.2391.189.91.42
                                                  Apr 26, 2025 07:10:27.770087957 CEST42836443192.168.2.2391.189.91.43

                                                  System Behavior

                                                  Start time (UTC):05:09:02
                                                  Start date (UTC):26/04/2025
                                                  Path:/tmp/linux.elf
                                                  Arguments:/tmp/linux.elf
                                                  File size:3610344 bytes
                                                  MD5 hash:3214e7da3a50b13260b5f9c24556ae46

                                                  Start time (UTC):05:09:02
                                                  Start date (UTC):26/04/2025
                                                  Path:/tmp/linux.elf
                                                  Arguments:-
                                                  File size:3610344 bytes
                                                  MD5 hash:3214e7da3a50b13260b5f9c24556ae46