Click to jump to signature section
Source: na.elf | ReversingLabs: Detection: 36% |
Source: /tmp/na.elf (PID: 5552) | Socket: 127.0.0.1:1172 | Jump to behavior |
Source: ELF static info symbol of initial sample | .symtab present: no |
Source: /tmp/na.elf (PID: 5756) | SIGKILL sent: pid: 5754, result: successful | Jump to behavior |
Source: /tmp/na.elf (PID: 5779) | SIGKILL sent: pid: 5777, result: successful | Jump to behavior |
Source: classification engine | Classification label: mal64.troj.linELF@0/0@0/0 |
Source: /tmp/na.elf (PID: 5555) | File opened: /proc/5389/cmdline | Jump to behavior |
Source: /tmp/na.elf (PID: 5555) | File opened: /proc/5601/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5555) | File opened: /proc/5603/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5555) | File opened: /proc/5604/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5555) | File opened: /proc/5615/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5680/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5681/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5682/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5389/cmdline | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5717/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5718/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5719/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5676/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5677/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5710/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5678/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5711/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5712/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5713/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5714/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5715/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5716/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5675/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5706/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5707/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5708/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5709/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5720/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5702/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5703/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5704/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5616) | File opened: /proc/5705/status | Jump to behavior |
Source: /tmp/na.elf (PID: 5756) | Sleeps longer then 60s: 60.0s | Jump to behavior |
Source: /tmp/na.elf (PID: 5901) | Sleeps longer then 60s: 60.0s | Jump to behavior |
Source: /tmp/na.elf (PID: 5779) | Sleeps longer then 60s: 60.0s | Jump to behavior |
Source: /tmp/na.elf (PID: 5924) | Sleeps longer then 60s: 60.0s | Jump to behavior |
Source: /tmp/na.elf (PID: 5552) | Queries kernel information via 'uname': | Jump to behavior |
Source: na.elf, 5552.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5554.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5754.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5756.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5555.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5777.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5779.1.000055dec980f000.000055dec98d9000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: na.elf, 5552.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5554.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5754.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5756.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5555.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5777.1.000055dec980f000.000055dec98d9000.rw-.sdmp, na.elf, 5779.1.000055dec980f000.000055dec98d9000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/mipsel |
Source: na.elf, 5552.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5554.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5754.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5756.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5555.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5777.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5779.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-mipsel |
Source: na.elf, 5552.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5554.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5754.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5756.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5555.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5777.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp, na.elf, 5779.1.00007ffe4d407000.00007ffe4d428000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf |
Source: Yara match | File source: na.elf, type: SAMPLE |
Source: Yara match | File source: 5777.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5554.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5756.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5779.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5552.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5555.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5754.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: na.elf, type: SAMPLE |
Source: Yara match | File source: 5777.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5554.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5756.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5779.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5552.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5555.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5754.1.00007fcd44400000.00007fcd4441a000.r-x.sdmp, type: MEMORY |