Linux Analysis Report
na.elf

Overview

General Information

Sample name: na.elf
Analysis ID: 1533026
MD5: 5d2fe62daf581be2533ff153dfb51690
SHA1: 22b47572bbdc44d768e98bdc254791d73d69ce2b
SHA256: dbdfcc8a0ab879dd282d0f27edd574b9dd99f9a90775d01646ee597be0f5b470
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false

Signatures

Multi AV Scanner detection for submitted file
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads system version information
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: na.elf Virustotal: Detection: 22% Perma Link
Source: na.elf ReversingLabs: Detection: 15%
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: classification engine Classification label: mal48.linELF@0/0@2/0
Source: /usr/lib/snapd/snap-failure (PID: 5807) Systemctl executable: /usr/bin/systemctl -> systemctl stop snapd.socket Jump to behavior
Source: /usr/lib/snapd/snap-failure (PID: 5794) Reads version info: /proc/version Jump to behavior
Source: /tmp/na.elf (PID: 5725) Queries kernel information via 'uname': Jump to behavior
Source: na.elf, 5725.1.000055b69e6e9000.000055b69e7f5000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: na.elf, 5725.1.000055b69e6e9000.000055b69e7f5000.rw-.sdmp Binary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: na.elf, 5725.1.000055b69e6e9000.000055b69e7f5000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: na.elf, 5725.1.00007ffd5c181000.00007ffd5c1a2000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: na.elf, 5725.1.00007ffd5c181000.00007ffd5c1a2000.rw-.sdmp Binary or memory string: YEB\x86_64/usr/bin/qemu-arm/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf
Source: na.elf, 5725.1.000055b69e6e9000.000055b69e7f5000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
No contacted IP infos