Linux Analysis Report
SecuriteInfo.com.Trojan.Linux.Generic.23983.22081.elf

Overview

General Information

Sample name: SecuriteInfo.com.Trojan.Linux.Generic.23983.22081.elf
Analysis ID: 1531111
MD5: 3739084706d8decc84e4fda6844769bb
SHA1: 742750211a32a79392d6ae008069319ccacd5622
SHA256: 39a16f216420b04becc39d9b6d9c50c521490f097e6bd7df9e5dd9c0255e65f9
Tags: elf
Infos:

Detection

Score: 1
Range: 0 - 100
Whitelisted: false

Signatures

Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)

Classification

Source: global traffic TCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknown TCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknown TCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: unknown Network traffic detected: HTTP traffic on port 48202 -> 443
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: clean1.linELF@0/0@2/0
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs