Source: na.elf |
ReversingLabs: Detection: 36% |
Source: /tmp/na.elf (PID: 5552) |
Socket: 127.0.0.1:1172 |
Jump to behavior |
Source: ELF static info symbol of initial sample |
.symtab present: no |
Source: /tmp/na.elf (PID: 5756) |
SIGKILL sent: pid: 5754, result: successful |
Jump to behavior |
Source: /tmp/na.elf (PID: 5779) |
SIGKILL sent: pid: 5777, result: successful |
Jump to behavior |
Source: classification engine |
Classification label: mal64.troj.linELF@0/0@0/0 |
Source: /tmp/na.elf (PID: 5555) |
File opened: /proc/5389/cmdline |
Jump to behavior |
Source: /tmp/na.elf (PID: 5555) |
File opened: /proc/5601/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5555) |
File opened: /proc/5603/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5555) |
File opened: /proc/5604/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5555) |
File opened: /proc/5615/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5680/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5681/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5682/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5389/cmdline |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5717/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5718/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5719/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5676/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5677/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5710/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5678/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5711/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5712/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5713/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5714/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5715/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5716/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5675/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5706/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5707/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5708/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5709/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5720/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5702/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5703/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5704/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5616) |
File opened: /proc/5705/status |
Jump to behavior |
Source: /tmp/na.elf (PID: 5756) |
Sleeps longer then 60s: 60.0s |
Jump to behavior |
Source: /tmp/na.elf (PID: 5901) |
Sleeps longer then 60s: 60.0s |
Jump to behavior |
Source: /tmp/na.elf (PID: 5779) |
Sleeps longer then 60s: 60.0s |
Jump to behavior |
Source: /tmp/na.elf (PID: 5924) |
Sleeps longer then 60s: 60.0s |
Jump to behavior |
Source: /tmp/na.elf (PID: 5552) |
Queries kernel information via 'uname': |
Jump to behavior |
Source: na.elf, 5552.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5554.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5754.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5756.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5555.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5777.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5779.1.000055dec980f000.000055dec98d9000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: na.elf, 5552.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5554.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5754.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5756.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5555.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5777.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5779.1.000055dec980f000.000055dec98d9000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/mipsel |
Source: na.elf, 5552.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5554.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5754.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5756.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5555.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5777.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5779.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mipsel |
Source: na.elf, 5552.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5554.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5754.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5756.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5555.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5777.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5779.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf |
Source: Yara match |
File source: na.elf, type: SAMPLE |
Source: Yara match |
File source: 5777.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5554.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5756.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5779.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5552.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5555.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5754.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: na.elf, type: SAMPLE |
Source: Yara match |
File source: 5777.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5554.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5756.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5779.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5552.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5555.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match |
File source: 5754.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |