Linux Analysis Report
aisuru.i686.elf

Overview

General Information

Sample name: aisuru.i686.elf
Analysis ID: 1502207
MD5: 753260e6e64b1936a1f486cce4a3a9c5
SHA1: 715ab9a6a3d1799c8b5b935a2a5726114c08a279
SHA256: 29695f49ecf815061171a5f826c91361238d0648f86b24151e5f43a032fdfbc6
Tags: aisuruelf
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Yara signature match

Classification

AV Detection

barindex
Source: aisuru.i686.elf Virustotal: Detection: 7% Perma Link
Source: aisuru.i686.elf Joe Sandbox ML: detected
Source: global traffic DNS traffic detected: DNS query: g.dvrinside.digital

System Summary

barindex
Source: aisuru.i686.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: 5628.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: ELF static info symbol of initial sample .symtab present: no
Source: aisuru.i686.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: 5628.1.0000000008048000.0000000008058000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: classification engine Classification label: mal60.linELF@0/0@1/0
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3760/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3760/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1583/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1583/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/2672/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/2672/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/110/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3759/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3759/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/111/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/112/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/113/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/234/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1577/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1577/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/114/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/235/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/235/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/115/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/115/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/116/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/116/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/117/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/117/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/118/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/118/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/119/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/119/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3873/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3873/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3757/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3757/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/10/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/10/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/917/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3758/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3758/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/11/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/11/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/12/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/12/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/13/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/13/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/14/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/14/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/15/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/15/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/16/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/16/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/17/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/17/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/18/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/18/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/19/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/19/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1593/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1593/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/240/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/240/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/120/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/120/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3094/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3094/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/121/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/121/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/242/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/242/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3406/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3406/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5706/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5706/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/122/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/122/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/243/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/243/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5707/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5707/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/2/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/2/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/123/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/123/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/244/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/244/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1589/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1589/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5708/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5708/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/3/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/124/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/124/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/245/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/245/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1588/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/1588/cmdline Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5709/maps Jump to behavior
Source: /tmp/aisuru.i686.elf (PID: 5644) File opened: /proc/5709/cmdline Jump to behavior
Source: submitted sample Stderr: Segmentation fault: exit code = 0
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs