Linux Analysis Report
kkkarm5.elf

Overview

General Information

Sample name: kkkarm5.elf
Analysis ID: 1542902
MD5: bfa0a0c9fcbef40098d7af48243c1d30
SHA1: 3d863ebe8adfb0f3bbf067aa4903cfa213d8df1e
SHA256: 5eaf0b97c111a273e699d15568af4421f0de6751127138a3a5f77ef53b52bdaf
Tags: elfkkkMiraiuser-NDA0E
Infos:

Detection

Score: 56
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: kkkarm5.elf Avira: detected
Source: kkkarm5.elf ReversingLabs: Detection: 71%
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample .symtab present: no
Source: classification engine Classification label: mal56.linELF@0/0@2/0
Source: /tmp/kkkarm5.elf (PID: 5469) Queries kernel information via 'uname': Jump to behavior
Source: kkkarm5.elf, 5469.1.000055953e9ca000.000055953eaf8000.rw-.sdmp Binary or memory string: U!/etc/qemu-binfmt/arm
Source: kkkarm5.elf, 5469.1.00007ffc9b73c000.00007ffc9b75d000.rw-.sdmp Binary or memory string: qemu: %s: %s
Source: kkkarm5.elf, 5469.1.00007ffc9b73c000.00007ffc9b75d000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/kkkarm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/kkkarm5.elf
Source: kkkarm5.elf, 5469.1.00007ffc9b73c000.00007ffc9b75d000.rw-.sdmp Binary or memory string: leqemu: %s: %s
Source: kkkarm5.elf, 5469.1.000055953e9ca000.000055953eaf8000.rw-.sdmp Binary or memory string: Urg.qemu.gdb.arm.sys.regs">
Source: kkkarm5.elf, 5469.1.000055953e9ca000.000055953eaf8000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: kkkarm5.elf, 5469.1.00007ffc9b73c000.00007ffc9b75d000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: kkkarm5.elf, 5469.1.000055953e9ca000.000055953eaf8000.rw-.sdmp Binary or memory string: rg.qemu.gdb.arm.sys.regs">
No contacted IP infos