Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
criptonize.arc700.elf

Overview

General Information

Sample name:criptonize.arc700.elf
Analysis ID:1500283
MD5:922797db0e0e3ef07b7d56948c7c9df9
SHA1:19abfa4c86ae3544960c0e0e649971a3f6849455
SHA256:1cd93e1c674d08f1f28eab3b06a564674f60712c264ba60e8b7e2da8e2ec9d41
Tags:criptonizeelf
Errors
  • No process behavior to analyse as no analysis process or sample was found

Detection

Score:0
Range:0 - 100
Whitelisted:false

Signatures

Sample has stripped symbol table

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1500283
Start date and time:2024-08-28 07:28:51 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:criptonize.arc700.elf
Detection:UNKNOWN
Classification:unknown0.linELF@0/0@0/0
  • No process behavior to analyse as no analysis process or sample was found
Command:/tmp/criptonize.arc700.elf
PID:5478
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: unknown0.linELF@0/0@0/0
No Mitre Att&ck techniques found
No configs have been found
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
No context
No context
No context
No context
No context
No created / dropped files found
File type:ELF 32-bit LSB executable, Synopsys ARCompact ARC700 cores, version 1 (SYSV), statically linked, stripped
Entropy (8bit):6.369023213755074
TrID:
  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
File name:criptonize.arc700.elf
File size:132'584 bytes
MD5:922797db0e0e3ef07b7d56948c7c9df9
SHA1:19abfa4c86ae3544960c0e0e649971a3f6849455
SHA256:1cd93e1c674d08f1f28eab3b06a564674f60712c264ba60e8b7e2da8e2ec9d41
SHA512:3cd4a36b60244ba2e8619a0e5c879040f5e927bcd67e0c6dff3c70f61be7f05dcff854daf813517afce40ff92f79a48a5ae447f64a1a3ceab53e83bf2cf4e28b
SSDEEP:3072:2kEOX/ohDPd99g38xOMdIOtdqTaQCwhgBCUuqYYFHNq:bCdDgMxO0v0/X+CUvYgq
TLSH:00D3AEABB20F1461C82507F51BCF9B6D2A2325018D6B92E77D5E373F2A335EA58053D2
File Content Preview:.ELF..............].........4...h.......4. ...(..................... ... ........ .......................`....... ..................................................................Q.td.......................................................................

ELF header

Class:ELF32
Data:2's complement, little endian
Version:1 (current)
Machine:<unknown>
Version Number:0x1
Type:EXEC (Executable file)
OS/ABI:UNIX - System V
ABI Version:0
Entry Point Address:0x102e4
Flags:0x403
ELF Header Size:52
Program Header Offset:52
Program Header Size:32
Number of Program Headers:5
Section Header Offset:131944
Section Header Size:40
Number of Section Headers:16
Header String Table Index:15
NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
NULL0x00x00x00x00x0000
.initPROGBITS0x101140x1140x220x00x6AX001
.textPROGBITS0x101380x1380x150880x00x6AX004
.finiPROGBITS0x251c00x151c00x160x00x6AX001
.rodataPROGBITS0x251d80x151d80x7f580x00x2A004
.eh_framePROGBITS0x2d1300x1d1300x11f00x00x2A004
.tdataPROGBITS0x31fd00x1ffd00x40x00x403WAT004
.tbssNOBITS0x31fd40x1ffd40x80x00x403WAT004
.fini_arrayFINI_ARRAY0x31fd40x1ffd40x40x40x3WA004
.ctorsPROGBITS0x31fd80x1ffd80x80x00x3WA004
.dtorsPROGBITS0x31fe00x1ffe00x80x00x3WA004
.gotPROGBITS0x31fe80x1ffe80x140x00x3WA004
.dataPROGBITS0x320080x200080x2b80x00x3WA004
.bssNOBITS0x322c00x202c00x5dc40x00x3WA004
.ARC.attributes<unknown>0x00x202c00x320x00x0001
.shstrtabSTRTAB0x00x202f20x760x00x0001
TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
LOAD0x00x100000x100000x1e3200x1e3206.63120x5R E0x2000.init .text .fini .rodata .eh_frame
LOAD0x1ffd00x31fd00x31fd00x2f00x60b43.68010x6RW 0x2000.tdata .tbss .fini_array .ctors .dtors .got .data .bss
NOTE0x00x00x00x00x00.00000x4R 0x4
TLS0x1ffd00x31fd00x31fd00x40xc2.00000x4R 0x4.tdata .tbss
GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
No network behavior found

System Behavior