Linux Analysis Report
na.elf

Overview

General Information

Sample name: na.elf
Analysis ID: 1532161
MD5: ca93506ec6906b5f283b176d252e7be3
SHA1: dc2a03f83f4c73e10a21c292ef8828973eaa6b49
SHA256: 69eda3598d6c05afec8d70ace706ffa3920d261309cacf52da2679a72971868f
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: na.elf Avira: detected
Source: na.elf ReversingLabs: Detection: 65%
Source: na.elf Virustotal: Detection: 58% Perma Link
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@2/0
Source: /tmp/na.elf (PID: 5545) Queries kernel information via 'uname': Jump to behavior
Source: na.elf, 5545.1.00007ffd6c5b7000.00007ffd6c5d8000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf
Source: na.elf, 5545.1.0000556cdabb4000.0000556cdace2000.rw-.sdmp Binary or memory string: lU!/etc/qemu-binfmt/arm
Source: na.elf, 5545.1.00007ffd6c5b7000.00007ffd6c5d8000.rw-.sdmp Binary or memory string: qemu: %s: %s
Source: na.elf, 5545.1.00007ffd6c5b7000.00007ffd6c5d8000.rw-.sdmp Binary or memory string: leqemu: %s: %s
Source: na.elf, 5545.1.0000556cdabb4000.0000556cdace2000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: na.elf, 5545.1.00007ffd6c5b7000.00007ffd6c5d8000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: na.elf, 5545.1.0000556cdabb4000.0000556cdace2000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
Source: na.elf, 5545.1.0000556cdabb4000.0000556cdace2000.rw-.sdmp Binary or memory string: lUrg.qemu.gdb.arm.sys.regs">
No contacted IP infos