Linux Analysis Report
NLHiAJgSnj.elf

Overview

General Information

Sample name: NLHiAJgSnj.elf
renamed because original name is a hash value
Original sample name: d79c81f5e8f405f76b0d77f543379653.elf
Analysis ID: 1529270
MD5: d79c81f5e8f405f76b0d77f543379653
SHA1: b67d6128d3d27de64ff29a24082bc736514b51dd
SHA256: ca8548f71a92e380a154ef983cb4d5af98f5af77537fc6522f0c41592ca0dedb
Tags: 32armelfmirai
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: NLHiAJgSnj.elf ReversingLabs: Detection: 23%

Networking

barindex
Source: global traffic TCP traffic: 154.90.62.142 ports 2,3,4,8,9,38429
Source: global traffic TCP traffic: 192.168.2.14:38794 -> 154.90.62.142:38429
Source: /tmp/NLHiAJgSnj.elf (PID: 5487) Socket: 127.0.0.1:1234 Jump to behavior
Source: unknown UDP traffic detected without corresponding DNS query: 130.61.69.123
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: krddnsnet.dyn
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) SIGKILL sent: pid: 888, result: successful Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) SIGKILL sent: pid: 1444, result: successful Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) SIGKILL sent: pid: 1610, result: successful Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) SIGKILL sent: pid: 5529, result: successful Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) SIGKILL sent: pid: 5531, result: successful Jump to behavior
Source: classification engine Classification label: mal52.troj.linELF@0/0@3/0
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1583/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1583/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/2672/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/2672/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1577/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/917/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1593/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1593/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3406/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3406/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/2/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/2/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1589/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1588/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1588/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/4/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/4/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3402/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3402/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/6/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/6/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/7/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/7/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/8/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/8/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/800/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/800/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/9/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/9/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/801/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/801/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/803/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/803/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/806/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/806/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/807/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/807/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/928/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/928/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3420/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3420/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1599/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3412/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3412/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1371/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5607/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1369/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3304/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3304/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3425/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3425/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/940/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/940/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/941/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/941/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1364/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1383/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1382/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1381/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3319/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3319/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3691/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3691/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5510/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1394/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3329/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3329/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3207/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3207/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/725/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/725/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3687/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3687/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/726/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/726/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3688/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3688/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3689/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3689/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5520/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5521/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3341/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3341/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5519/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3218/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3218/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3337/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3337/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3215/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3215/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/1399/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/853/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/853/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3213/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3213/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3212/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/3212/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5489) File opened: /proc/5511/cmdline Jump to behavior
Source: /tmp/NLHiAJgSnj.elf (PID: 5487) Queries kernel information via 'uname': Jump to behavior
Source: NLHiAJgSnj.elf, 5487.1.00007ffcfc391000.00007ffcfc3b2000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/NLHiAJgSnj.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/NLHiAJgSnj.elf
Source: NLHiAJgSnj.elf, 5487.1.00005578c7dbe000.00005578c7f0d000.rw-.sdmp Binary or memory string: xU!/etc/qemu-binfmt/arm
Source: NLHiAJgSnj.elf, 5487.1.00005578c7dbe000.00005578c7f0d000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: NLHiAJgSnj.elf, 5487.1.00007ffcfc391000.00007ffcfc3b2000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs