Linux Analysis Report
na.elf

Overview

General Information

Sample name: na.elf
Analysis ID: 1528785
MD5: 7e144659c0feb47d8b6a3180798fcc09
SHA1: 7f0a3f2a125df4f33e6aa968046b437322ac5ae8
SHA256: e86778bfb02461a8219a2d8ae1efda77ffd9d942dcff60c9eb95df537b2e14f2
Tags: elfMiraiuser-abuse_ch
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: na.elf Avira: detected
Source: na.elf ReversingLabs: Detection: 55%
Source: na.elf Virustotal: Detection: 62% Perma Link
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@2/0
Source: /tmp/na.elf (PID: 5495) Queries kernel information via 'uname': Jump to behavior
Source: na.elf, 5495.1.00007ffc304f4000.00007ffc30515000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf
Source: na.elf, 5495.1.000055df42f80000.000055df430ae000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: na.elf, 5495.1.000055df42f80000.000055df430ae000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: na.elf, 5495.1.00007ffc304f4000.00007ffc30515000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: na.elf, 5495.1.00007ffc304f4000.00007ffc30515000.rw-.sdmp Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
No contacted IP infos