Source: na.elf |
ReversingLabs: Detection: 28% |
Source: global traffic |
TCP traffic: 192.168.2.14:38832 -> 152.136.107.163:3232 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.136.107.163 |
Source: global traffic |
DNS traffic detected: DNS query: daisy.ubuntu.com |
Source: na.elf |
String found in binary or memory: http://upx.sf.net |
Source: LOAD without section mappings |
Program segment: 0x400000 |
Source: classification engine |
Classification label: mal52.evad.linELF@0/0@2/0 |
Source: initial sample |
String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample |
String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample |
String containing UPX found: $Id: UPX 3.96 Copyright (C) 1996-2020 the UPX Team. All Rights Reserved. $ |
Source: submitted sample |
Stderr: 2024/10/06 16:01:51 Forking2024/10/06 16:01:51 Connecting to 152.136.107.163:32322024/10/06 16:01:54 Successfully
connnected 152.136.107.163:32322024/10/06 16:01:55 [client] INFO global.go:118 RegisterChannelCallbacks() : Handling channel:
jump2024/10/06 16:01:57 [152.136.107.163:3232] INFO jumphost.go:52 func1() : New SSH connection, version SSH-2.0-paramiko_3.0.02024/10/06
16:01:58 [152.136.107.163:3232] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: session2024/10/06 16:01:59
[152.136.107.163:3232] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: session2024/10/06 16:02:00 [152.136.107.163:3232]
INFO session.go:57 Session() : Session got request: "exec"2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:109 Session()
: Session disconnected2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:157 Session() : Session disconnected2024/10/06
16:02:00 [client] ERROR jumphost.go:97 func1() : Channel call back error: connection terminated: exit code = 0 |
Source: na.elf |
Submission file: segment LOAD with 7.8829 entropy (max. 8.0) |
Source: /proc/self/exe (PID: 5642) |
Queries kernel information via 'uname': |
Jump to behavior |