Linux Analysis Report
SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf

Overview

General Information

Sample name: SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf
Analysis ID: 1527609
MD5: efe38c3fad71cb6b9e154e8ba077722e
SHA1: fb506f7ac533717af974bbff7cd3e49aad2feb52
SHA256: 0f591b615a8c8d91187b374971b1d861391db9bcda95a052f13448608de0d13b
Tags: elf

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf Virustotal: Detection: 15% Perma Link
Source: SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf ReversingLabs: Detection: 13%
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal48.linELF@0/0@0/0
Source: /tmp/SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf (PID: 5515) Queries kernel information via 'uname': Jump to behavior
Source: SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf, 5515.1.00007ffdb9356000.00007ffdb9377000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf
Source: SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf, 5515.1.0000560b19c7b000.0000560b19da9000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf, 5515.1.0000560b19c7b000.0000560b19da9000.rw-.sdmp Binary or memory string: V!/etc/qemu-binfmt/arm
Source: SecuriteInfo.com.ELF.Mirai-COW.30071.12978.elf, 5515.1.00007ffdb9356000.00007ffdb9377000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
No contacted IP infos