Linux Analysis Report
kkkarm6.elf

Overview

General Information

Sample name: kkkarm6.elf
Analysis ID: 1542901
MD5: 0344060bfb0939831762bfb5c89ab750
SHA1: 052faee403e945d8381ba6577dab997c212c8ac7
SHA256: 76eee62e2e2555ed98c6c9d8e1f5ac5f06babe85c2a3a673d9fe97b97868801a
Tags: elfkkkMiraiuser-NDA0E
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: kkkarm6.elf Avira: detected
Source: kkkarm6.elf ReversingLabs: Detection: 73%
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@2/0
Source: /tmp/kkkarm6.elf (PID: 5531) Queries kernel information via 'uname': Jump to behavior
Source: kkkarm6.elf, 5531.1.00005598d96a4000.00005598d97d2000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: kkkarm6.elf, 5531.1.00007ffef04b0000.00007ffef04d1000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/kkkarm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/kkkarm6.elf
Source: kkkarm6.elf, 5531.1.00005598d96a4000.00005598d97d2000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: kkkarm6.elf, 5531.1.00007ffef04b0000.00007ffef04d1000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: kkkarm6.elf, 5531.1.00007ffef04b0000.00007ffef04d1000.rw-.sdmp Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
No contacted IP infos