Linux
Analysis Report
3c7b9bc6218d4b893cd7
Overview
General Information
Sample Name: | 3c7b9bc6218d4b893cd7 |
Analysis ID: | 894128 |
MD5: | 302dcb8461e20a77f171f52c51a47f5e |
SHA1: | 70f8080535b2f83663dba711cd7bb6ede0e49351 |
SHA256: | 49c2fec28e35fbc0cc01e0df686a57c0bf2c6dde67bdad28db15b665d25d0f40 |
Infos: |
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample scans a subnet
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
ELF contains segments with high entropy indicating compressed/encrypted content
Classification
Analysis Advice
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work. |
Non-zero exit code suggests an error during the execution. Lookup the error code for hints. |
Joe Sandbox Version: | 37.1.0 Beryl |
Analysis ID: | 894128 |
Start date and time: | 2023-06-25 18:21:27 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 5m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample file name: | 3c7b9bc6218d4b893cd7 |
Detection: | MAL |
Classification: | mal56.spre.evad.lin@0/0@0/0 |
- Report size exceeded maximum capacity and may have missing network information.
Command: | /tmp/3c7b9bc6218d4b893cd7 |
PID: | 6229 |
Exit Code: | 1 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
⊘No yara matches
⊘No Snort rule has matched
- • AV Detection
- • Networking
- • System Summary
- • Hooking and other Techniques for Hiding and Protection
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Networking |
---|
Source: | Subnet 192.168.31.0/24: |