Edit tour
Linux
Analysis Report
linux_mips64el.elf
Overview
General Information
Detection
Chaos
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Yara detected Chaos
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1562733 |
Start date and time: | 2024-11-25 23:46:17 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 29s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | linux_mips64el.elf |
Detection: | MAL |
Classification: | mal48.troj.linELF@0/6@0/0 |
- VT rate limit hit for: linux_mips64el.elf
Command: | /tmp/linux_mips64el.elf |
PID: | 5531 |
Exit Code: | 2 |
Exit Code Info: | |
Killed: | False |
Standard Output: | |
Standard Error: | fatal error: sigaction failed runtime stack: runtime.throw({0x39ae60, 0x10}) /usr/lib/go-1.18/src/runtime/panic.go:992 +0x6c runtime.sysSigaction.func1() /usr/lib/go-1.18/src/runtime/os_linux.go:529 +0x4c runtime.sysSigaction(0x41, 0x4000800bc0, 0x0) /usr/lib/go-1.18/src/runtime/os_linux.go:528 +0x88 runtime.sigaction(0x41, 0x4000800bc0, 0x0) /usr/lib/go-1.18/src/runtime/sigaction.go:15 +0x28 runtime.setsig(0x41, 0x6ecf0) /usr/lib/go-1.18/src/runtime/os_linux.go:478 +0xb0 runtime.initsig(0x0) /usr/lib/go-1.18/src/runtime/signal_unix.go:147 +0x348 runtime.mstartm0() /usr/lib/go-1.18/src/runtime/proc.go:1442 +0x78 runtime.mstart1() /usr/lib/go-1.18/src/runtime/proc.go:1414 +0x94 runtime.mstart0() /usr/lib/go-1.18/src/runtime/proc.go:1376 +0x74 runtime.mstart() /usr/lib/go-1.18/src/runtime/asm_mips64x.s:88 +0x10 goroutine 1 [runnable]: runtime.main() /usr/lib/go-1.18/src/runtime/proc.go:145 runtime.goexit() /usr/lib/go-1.18/src/runtime/asm_mips64x.s:617 +0x4 |
- system is lnxubuntu20
- sshd New Fork (PID: 5539, Parent: 933)
- sshd New Fork (PID: 5549, Parent: 933)
- sshd New Fork (PID: 5550, Parent: 933)
- sshd New Fork (PID: 5551, Parent: 5550)
- sshd New Fork (PID: 5563, Parent: 933)
- sshd New Fork (PID: 5564, Parent: 5563)
- sshd New Fork (PID: 5565, Parent: 933)
- sshd New Fork (PID: 5566, Parent: 5565)
- sshd New Fork (PID: 5570, Parent: 933)
- sshd New Fork (PID: 5571, Parent: 933)
- sshd New Fork (PID: 5572, Parent: 5571)
- sshd New Fork (PID: 5573, Parent: 933)
- sshd New Fork (PID: 5574, Parent: 5573)
- sshd New Fork (PID: 5577, Parent: 933)
- sshd New Fork (PID: 5578, Parent: 5577)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Chaos | Multi-functional malware written in Go, targeting both Linux and Windows, evolved from elf.kaiji. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_ChaosGo | Yara detected Chaos | Joe Security |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Source: | String found in binary or memory: |