Linux Analysis Report
mips.elf

Overview

General Information

Sample name: mips.elf
Analysis ID: 1541831
MD5: 697f179d49ef3b5fe5c8a4f3df0d9592
SHA1: 334fb962203b9819cc0303237b9d938a2f3e34cb
SHA256: bce751aa17d8e5cda2d82408d8c296f9de9e8ce9283c1bf0a7f777f34a33e0c5
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: mips.elf Avira: detected
Source: mips.elf Virustotal: Detection: 7% Perma Link
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@0/0
Source: /usr/bin/dash (PID: 5416) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.WC8v2L67nm /tmp/tmp.okaodldQhL /tmp/tmp.qkDyzY2OYS Jump to behavior
Source: /usr/bin/dash (PID: 5425) Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.WC8v2L67nm /tmp/tmp.okaodldQhL /tmp/tmp.qkDyzY2OYS Jump to behavior
Source: /tmp/mips.elf (PID: 5451) Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 5451.1.0000562faa289000.0000562faa310000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 5451.1.00007ffe4eac3000.00007ffe4eae4000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mips
Source: mips.elf, 5451.1.00007ffe4eac3000.00007ffe4eae4000.rw-.sdmp Binary or memory string: ,0+x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 5451.1.0000562faa289000.0000562faa310000.rw-.sdmp Binary or memory string: /V!/etc/qemu-binfmt/mips
No contacted IP infos