Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1528913
MD5:d910d780d44f45c5b9ce6032699f820e
SHA1:8aae92edcf4138a3c89b6ae5ffc13450899db3c5
SHA256:e0d8562ac8223ff01d99dd52225966150785e1021ec63b7ab44b01f04471b149
Tags:elfuser-abuse_ch
Errors
  • No process behavior to analyse as no analysis process or sample was found

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample has stripped symbol table

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528913
Start date and time:2024-10-08 13:02:07 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
  • No process behavior to analyse as no analysis process or sample was found
Command:/tmp/na.elf
PID:5644
Exit Code:255
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: na.elfVirustotal: Detection: 7%Perma Link
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
No Mitre Att&ck techniques found
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
na.elf11%ReversingLabsLinux.Backdoor.Mirai
na.elf8%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
No context
No context
No context
No context
No context
No created / dropped files found
File type:ELF 32-bit LSB executable, Synopsys ARCompact ARC700 cores, version 1 (SYSV), statically linked, stripped
Entropy (8bit):6.40170162459827
TrID:
  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
File name:na.elf
File size:124'088 bytes
MD5:d910d780d44f45c5b9ce6032699f820e
SHA1:8aae92edcf4138a3c89b6ae5ffc13450899db3c5
SHA256:e0d8562ac8223ff01d99dd52225966150785e1021ec63b7ab44b01f04471b149
SHA512:b148c4b307d9acc65331904cb2df1f0852c3fa3d8730bd50043adf3853684693d2a105607d7313c5f222538ac3083311ae00b2c4c76938a657628a6b5aa43f90
SSDEEP:1536:gQTF0nkjipFHRYrFJ2UIU2Vbl3vi3Rsof2Ut3ealMjVUb/ZlgD/LW:grkjinqZJNIP3vq+U/t0jVUb/ZlgDq
TLSH:6AC3AD87F24B5990C82502F05BC75BEC1EA331126E1FD8F76C1D663B1A7A4CF1A0A792
File Content Preview:.ELF..............].........4...`.......4. ...(.................................. .......................?....... ..................................................................Q.td.......................................................................

ELF header

Class:ELF32
Data:2's complement, little endian
Version:1 (current)
Machine:<unknown>
Version Number:0x1
Type:EXEC (Executable file)
OS/ABI:UNIX - System V
ABI Version:0
Entry Point Address:0x1068c
Flags:0x403
ELF Header Size:52
Program Header Offset:52
Program Header Size:32
Number of Program Headers:5
Section Header Offset:123488
Section Header Size:40
Number of Section Headers:15
Header String Table Index:14
NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
NULL0x00x00x00x00x0000
.initPROGBITS0x101140x1140x220x00x6AX001
.textPROGBITS0x101380x1380x144640x00x6AX004
.finiPROGBITS0x2459c0x1459c0x160x00x6AX001
.rodataPROGBITS0x245b40x145b40x7d2c0x00x2A004
.eh_framePROGBITS0x2c2e00x1c2e00x4100x00x2A004
.tbssNOBITS0x2ffe00x1dfe00x80x00x403WAT004
.fini_arrayFINI_ARRAY0x2ffe00x1dfe00x40x40x3WA004
.ctorsPROGBITS0x2ffe40x1dfe40x80x00x3WA004
.dtorsPROGBITS0x2ffec0x1dfec0x80x00x3WA004
.gotPROGBITS0x2fff40x1dff40x80x00x3WA004
.dataPROGBITS0x300080x1e0080x1b40x00x3WA004
.bssNOBITS0x301bc0x1e1bc0x3dcc0x00x3WA004
.ARC.attributes<unknown>0x00x1e1bc0x320x00x0001
.shstrtabSTRTAB0x00x1e1ee0x6f0x00x0001
TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
LOAD0x00x100000x100000x1c6f00x1c6f06.64290x5R E0x2000.init .text .fini .rodata .eh_frame
LOAD0x1dfe00x2ffe00x2ffe00x1dc0x3fa82.50530x6RW 0x2000.tbss .fini_array .ctors .dtors .got .data .bss
NOTE0x00x00x00x00x00.00000x4R 0x4
TLS0x1dfe00x2ffe00x2ffe00x00x80.00000x4R 0x4.tbss
GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
No network behavior found

System Behavior