Edit tour
Linux
Analysis Report
linux_arm5.elf
Overview
General Information
Sample name: | linux_arm5.elf |
Analysis ID: | 1546423 |
MD5: | ccd26ce76ba241bb57206af170add530 |
SHA1: | 0456caf337158a5cda120d85133296cf4ffe373a |
SHA256: | 4f45461d708ccdeb18646b2f7a6003f4f1bf513e86f3a2ea7846ac2f14194c90 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Chaos
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Yara detected Chaos
Drops files in suspicious directories
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Uses known network protocols on non-standard ports
Writes identical ELF files to multiple locations
Creates hidden files and/or directories
Creates hidden files without content (potentially used as a mutex)
Detected TCP or UDP traffic on non-standard ports
Drops files with innocent-looking names
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "kill" or "pkill" command typically used to terminate processes
Executes the "sleep" command used to delay execution and potentially evade sandboxes
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads CPU information from /sys indicative of miner or evasive malware
Reads the 'hosts' file potentially containing internal network hosts
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Writes shell script file to disk with an unusual file extension
Writes shell script files to disk
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1546423 |
Start date and time: | 2024-10-31 21:41:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | linux_arm5.elf |
Detection: | MAL |
Classification: | mal80.spre.troj.evad.linELF@0/138@4/0 |
- Report size exceeded maximum capacity and may have missing behavior information.
- VT rate limit hit for: linux_arm5.elf
Command: | /tmp/linux_arm5.elf |
PID: | 6255 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: |
- system is lnxubuntu20
- linux_arm5.elf New Fork (PID: 6260, Parent: 6255)
- linux_arm5.elf New Fork (PID: 6266, Parent: 6255)
- service New Fork (PID: 6274, Parent: 6266)
- service New Fork (PID: 6275, Parent: 6266)
- service New Fork (PID: 6277, Parent: 6266)
- linux_arm5.elf New Fork (PID: 6271, Parent: 6255)
- linux_arm5.elf New Fork (PID: 6287, Parent: 6271)
- update-rc.d New Fork (PID: 6303, Parent: 6287)
- linux_arm5.elf New Fork (PID: 6330, Parent: 6271)
- bash New Fork (PID: 6332, Parent: 6330)
- bash New Fork (PID: 6354, Parent: 6330)
- bash New Fork (PID: 6363, Parent: 6330)
- bash New Fork (PID: 6530, Parent: 6330)
- linux_arm5.elf New Fork (PID: 6576, Parent: 6271)
- bash New Fork (PID: 6581, Parent: 6576)
- bash New Fork (PID: 6582, Parent: 6576)
- bash New Fork (PID: 6583, Parent: 6576)
- linux_arm5.elf New Fork (PID: 6654, Parent: 6271)
- linux_arm5.elf New Fork (PID: 6687, Parent: 6271)
- linux_arm5.elf New Fork (PID: 6689, Parent: 6271)
- linux_arm5.elf New Fork (PID: 6715, Parent: 6271)
- service New Fork (PID: 6720, Parent: 6715)
- service New Fork (PID: 6721, Parent: 6715)
- service New Fork (PID: 6722, Parent: 6715)
- linux_arm5.elf New Fork (PID: 6763, Parent: 6271)
- systemd New Fork (PID: 6305, Parent: 6304)
- systemd New Fork (PID: 6352, Parent: 6351)
- systemd New Fork (PID: 6361, Parent: 6360)
- systemd New Fork (PID: 6365, Parent: 1)
- System.img.config New Fork (PID: 6372, Parent: 6365)
- System.img.config New Fork (PID: 6512, Parent: 6365)
- sh New Fork (PID: 6523, Parent: 6512)
- 32678 New Fork (PID: 6541, Parent: 6523)
- 32678 New Fork (PID: 6742, Parent: 6523)
- id.services.conf New Fork (PID: 6747, Parent: 6742)
- id.services.conf New Fork (PID: 6776, Parent: 6742)
- id.services.conf New Fork (PID: 6782, Parent: 6742)
- service New Fork (PID: 6793, Parent: 6782)
- service New Fork (PID: 6795, Parent: 6782)
- service New Fork (PID: 6796, Parent: 6782)
- id.services.conf New Fork (PID: 6788, Parent: 6742)
- System.img.config New Fork (PID: 6518, Parent: 6365)
- service New Fork (PID: 6538, Parent: 6518)
- service New Fork (PID: 6546, Parent: 6518)
- service New Fork (PID: 6547, Parent: 6518)
- System.img.config New Fork (PID: 6524, Parent: 6365)
- sshd New Fork (PID: 6375, Parent: 936)
- sshd New Fork (PID: 6376, Parent: 936)
- sshd New Fork (PID: 6378, Parent: 6376)
- sshd New Fork (PID: 6460, Parent: 936)
- sshd New Fork (PID: 6478, Parent: 6460)
- udisksd New Fork (PID: 6703, Parent: 799)
- systemd New Fork (PID: 6752, Parent: 1)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Chaos | Multi-functional malware written in Go, targeting both Linux and Windows, evolved from elf.kaiji. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_ChaosGo | Yara detected Chaos | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_ChaosGo | Yara detected Chaos | Joe Security | ||
JoeSecurity_ChaosGo | Yara detected Chaos | Joe Security | ||
JoeSecurity_ChaosGo | Yara detected Chaos | Joe Security | ||
JoeSecurity_ChaosGo | Yara detected Chaos | Joe Security | ||
JoeSecurity_ChaosGo | Yara detected Chaos | Joe Security | ||
Click to see the 7 entries |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: |
Networking |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic: |
Source: | Reads hosts file: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |