Linux Analysis Report
foxhAjDt.elf

Overview

General Information

Sample Name: foxhAjDt.elf
Analysis ID: 829688
MD5: 7de222fa7927d27a83d855608d8f9e6f
SHA1: 15404b19eda9a90043316ba255811e84bbb221b8
SHA256: d9bd1932dad08061e9cfecdc42bc4cbb3eec506ab54f4d889d6ae523d8249324
Tags: elf
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false

Signatures

Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:36344 -> 193.35.18.163:2137
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 193.35.18.163
Source: unknown TCP traffic detected without corresponding DNS query: 193.35.18.163
Source: unknown TCP traffic detected without corresponding DNS query: 193.35.18.163
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 193.35.18.163
Source: unknown TCP traffic detected without corresponding DNS query: 193.35.18.163
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 193.35.18.163
Source: unknown TCP traffic detected without corresponding DNS query: 193.35.18.163
Source: foxhAjDt.elf String found in binary or memory: http://www.debian.org/Bugs/
Source: foxhAjDt.elf String found in binary or memory: https://gcc.gnu.org/bugs/):
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: clean2.linELF@0/0@0/0
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/6231/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1582/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/3088/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/230/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/110/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/231/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/111/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/232/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1579/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/112/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/233/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1699/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/113/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/234/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1335/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1698/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/114/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/235/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1334/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1576/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/2302/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/115/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/236/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/116/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/237/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/117/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/118/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/910/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/119/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/912/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/10/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/2307/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/11/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/918/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/12/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/13/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/14/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/15/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/16/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/17/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/18/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1594/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/120/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/121/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1349/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/122/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/243/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/123/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/2/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/124/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/3/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/4/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/125/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/126/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1344/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1465/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1586/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/127/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/6/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/248/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/128/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/249/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1463/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/800/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/9/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/801/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/20/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/21/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1900/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/22/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/23/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/24/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/25/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/26/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/27/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/28/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/29/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/491/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/250/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/130/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/251/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/252/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/132/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/253/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/254/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/255/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/256/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1599/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/257/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1477/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/379/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/258/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1476/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/259/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1475/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/936/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/30/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/2208/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/35/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1809/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/1494/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/260/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/261/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6229) File opened: /proc/141/maps Jump to behavior
Source: /tmp/foxhAjDt.elf (PID: 6227) Queries kernel information via 'uname': Jump to behavior
Source: foxhAjDt.elf, 6227.1.00007ffe758bf000.00007ffe758e0000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/foxhAjDt.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/foxhAjDt.elf
Source: foxhAjDt.elf, 6227.1.00005619c9449000.00005619c9597000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: foxhAjDt.elf, 6227.1.00005619c9449000.00005619c9597000.rw-.sdmp Binary or memory string: V!/etc/qemu-binfmt/arm
Source: foxhAjDt.elf, 6227.1.00007ffe758bf000.00007ffe758e0000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs