Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.arm.elf

Overview

General Information

Sample name:Space.arm.elf
Analysis ID:1575714
MD5:9ce6f655eedca1fd7af2e93dc59adb6c
SHA1:ed523f4251d1dc3d202f3bf338543acf4b4edb50
SHA256:413cddb4fca3a1e8f1fb2ac5ebcd161a85cda41861415f91a9c5e7f116732b70
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1575714
Start date and time:2024-12-16 08:52:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 51s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.arm.elf
Detection:MAL
Classification:mal68.troj.evad.linELF@0/0@0/0
Command:/tmp/Space.arm.elf
PID:6241
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6243.1.00007f4d40017000.00007f4d4002a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    6243.1.00007f4d40017000.00007f4d4002a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x10258:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1026c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10280:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10294:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x102a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x102bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x102d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x102e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x102f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1030c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1035c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x10398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x103ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x103c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x103d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x103e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    6245.1.00007f4d40017000.00007f4d4002a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6245.1.00007f4d40017000.00007f4d4002a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x10258:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1026c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10280:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10294:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x102f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1030c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1035c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x10398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x103e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      6241.1.00007f4d40017000.00007f4d4002a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        Click to see the 11 entries
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: Space.arm.elfReversingLabs: Detection: 31%
        Source: global trafficTCP traffic: 192.168.2.23:50948 -> 89.169.4.44:3778
        Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
        Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
        Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: Space.arm.elfString found in binary or memory: http://upx.sf.net
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

        System Summary

        barindex
        Source: 6243.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6245.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6241.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6253.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.arm.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.arm.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.arm.elf PID: 6245, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.arm.elf PID: 6253, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: LOAD without section mappingsProgram segment: 0x8000
        Source: 6243.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6245.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6241.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6253.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.arm.elf PID: 6241, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.arm.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.arm.elf PID: 6245, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.arm.elf PID: 6253, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: classification engineClassification label: mal68.troj.evad.linELF@0/0@0/0

        Data Obfuscation

        barindex
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1582/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/3088/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/230/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/110/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/231/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/111/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/232/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1579/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/112/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/233/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1699/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/113/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/234/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1335/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1698/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/114/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/235/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1334/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1576/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/2302/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/115/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/236/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/116/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/237/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/117/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/118/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/910/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/119/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/912/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/10/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/2307/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/11/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/918/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/6241/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/12/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/13/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/14/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/15/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/16/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/17/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/6247/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/18/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1594/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/120/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/121/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1349/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/122/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/243/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/123/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/2/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/124/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/3/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/4/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/125/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/126/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1344/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1465/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1586/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/127/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/6/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/248/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/128/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/249/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1463/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/800/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/9/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/801/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/20/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/21/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1900/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/22/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/23/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/24/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/25/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/26/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/27/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/28/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/29/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/491/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/250/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/130/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/251/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/252/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/132/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/253/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/254/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/255/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/256/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1599/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/257/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1477/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/379/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/258/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1476/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/259/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1475/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/936/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/30/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/2208/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/35/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1809/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/1494/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/260/statusJump to behavior
        Source: /tmp/Space.arm.elf (PID: 6241)File opened: /proc/261/statusJump to behavior
        Source: Space.arm.elfSubmission file: segment LOAD with 7.9645 entropy (max. 8.0)
        Source: /tmp/Space.arm.elf (PID: 6241)Queries kernel information via 'uname': Jump to behavior
        Source: Space.arm.elf, 6241.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmp, Space.arm.elf, 6243.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmp, Space.arm.elf, 6245.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmp, Space.arm.elf, 6253.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmpBinary or memory string: }?V!/etc/qemu-binfmt/arm
        Source: Space.arm.elf, 6241.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmp, Space.arm.elf, 6243.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmp, Space.arm.elf, 6245.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmp, Space.arm.elf, 6253.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/Space.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.arm.elf
        Source: Space.arm.elf, 6241.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmp, Space.arm.elf, 6243.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmp, Space.arm.elf, 6245.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmp, Space.arm.elf, 6253.1.0000563f7dcef000.0000563f7df3d000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
        Source: Space.arm.elf, 6241.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmp, Space.arm.elf, 6243.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmp, Space.arm.elf, 6245.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmp, Space.arm.elf, 6253.1.00007fffcee0a000.00007fffcee2b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 6243.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6245.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6241.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6253.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6241, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6243, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6245, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6253, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 6243.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6245.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6241.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6253.1.00007f4d40017000.00007f4d4002a000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6241, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6243, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6245, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.arm.elf PID: 6253, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
        Obfuscated Files or Information
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1575714 Sample: Space.arm.elf Startdate: 16/12/2024 Architecture: LINUX Score: 68 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 89.169.4.44, 3778, 50948, 50950 INF-NET-ASRU Russian Federation 2->22 24 2 other IPs or domains 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Yara detected Mirai 2->30 32 Sample is packed with UPX 2->32 8 Space.arm.elf 2->8         started        signatures3 process4 process5 10 Space.arm.elf 8->10         started        12 Space.arm.elf 8->12         started        14 Space.arm.elf 8->14         started        process6 16 Space.arm.elf 10->16         started        18 Space.arm.elf 10->18         started       
        SourceDetectionScannerLabelLink
        Space.arm.elf32%ReversingLabsLinux.Trojan.Mirai
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://upx.sf.netSpace.arm.elffalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          89.169.4.44
          unknownRussian Federation
          31514INF-NET-ASRUfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
          89.169.4.44boatnet.ppc.elfGet hashmaliciousMiraiBrowse
            boatnet.arm.elfGet hashmaliciousMiraiBrowse
              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                boatnet.mips.elfGet hashmaliciousMiraiBrowse
                  boatnet.x86.elfGet hashmaliciousMiraiBrowse
                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                      boatnet.spc.elfGet hashmaliciousMiraiBrowse
                        boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                          boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                            bot.m68k.elfGet hashmaliciousMirai, OkiruBrowse
                              91.189.91.43m68k.elfGet hashmaliciousUnknownBrowse
                                x86.elfGet hashmaliciousUnknownBrowse
                                  bin.sh.elfGet hashmaliciousMiraiBrowse
                                    .i.elfGet hashmaliciousUnknownBrowse
                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                        spc.elfGet hashmaliciousUnknownBrowse
                                          m68k.elfGet hashmaliciousUnknownBrowse
                                            mips.elfGet hashmaliciousUnknownBrowse
                                              arm.elfGet hashmaliciousUnknownBrowse
                                                x86.elfGet hashmaliciousUnknownBrowse
                                                  91.189.91.42m68k.elfGet hashmaliciousUnknownBrowse
                                                    x86.elfGet hashmaliciousUnknownBrowse
                                                      bin.sh.elfGet hashmaliciousMiraiBrowse
                                                        .i.elfGet hashmaliciousUnknownBrowse
                                                          mpsl.elfGet hashmaliciousUnknownBrowse
                                                            spc.elfGet hashmaliciousUnknownBrowse
                                                              m68k.elfGet hashmaliciousUnknownBrowse
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                  arm.elfGet hashmaliciousUnknownBrowse
                                                                    x86.elfGet hashmaliciousUnknownBrowse
                                                                      No context
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      CANONICAL-ASGBm68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      spc.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      m68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      CANONICAL-ASGBm68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      spc.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      m68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      INF-NET-ASRUjade.m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.156.74
                                                                      https://santa-secret.ru/api/verify?a=NjgyODEwNCw1bWluOHE2MHpuX3J1LC9hY2NvdW50L2JveGVzLHZsYWRpbWlyLmdsdXNoZW5rb0Bob2NobGFuZC5ydSwyNDE0MTYzMg==Get hashmaliciousUnknownBrowse
                                                                      • 87.228.10.139
                                                                      boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      INIT7CHm68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      spc.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      m68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      No context
                                                                      No context
                                                                      No created / dropped files found
                                                                      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
                                                                      Entropy (8bit):7.962510011719269
                                                                      TrID:
                                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                      File name:Space.arm.elf
                                                                      File size:36'824 bytes
                                                                      MD5:9ce6f655eedca1fd7af2e93dc59adb6c
                                                                      SHA1:ed523f4251d1dc3d202f3bf338543acf4b4edb50
                                                                      SHA256:413cddb4fca3a1e8f1fb2ac5ebcd161a85cda41861415f91a9c5e7f116732b70
                                                                      SHA512:a19fcb4690c88e560300abf678a0628a80dee48b1b450e712189e2caa62fa39ab18f932acd45d94daff2678ec2d3d6fd0be3852f006c8b09f354ce16d6bb6937
                                                                      SSDEEP:768:qQKd4TIv86wHqEGBFePMdayb0zDWX5pq2sJbBi9s3UozD:qQKSIbtYMHaDy5p/sZBiAzD
                                                                      TLSH:79F2F1213111BDF4EA20093BCF7A854AE39A41755256714D1A2847FEA0CF7C6A9BC3F3
                                                                      File Content Preview:.ELF...a..........(.....8...4...........4. ...(..........................................Y...Y...Y..................Q.td............................s.y.UPX!........@5..@5......T..........?.E.h;.}...^..........f(...j.l..0z.$..G.sB......y...G.."b..k{......0

                                                                      ELF header

                                                                      Class:ELF32
                                                                      Data:2's complement, little endian
                                                                      Version:1 (current)
                                                                      Machine:ARM
                                                                      Version Number:0x1
                                                                      Type:EXEC (Executable file)
                                                                      OS/ABI:ARM - ABI
                                                                      ABI Version:0
                                                                      Entry Point Address:0xfd38
                                                                      Flags:0x202
                                                                      ELF Header Size:52
                                                                      Program Header Offset:52
                                                                      Program Header Size:32
                                                                      Number of Program Headers:3
                                                                      Section Header Offset:0
                                                                      Section Header Size:40
                                                                      Number of Section Headers:0
                                                                      Header String Table Index:0
                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                      LOAD0x00x80000x80000x8ee70x8ee77.96450x5R E0x8000
                                                                      LOAD0x59900x259900x259900x00x00.00000x6RW 0x8000
                                                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Dec 16, 2024 08:52:57.055347919 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 08:52:58.376679897 CET509483778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:58.496556044 CET37785094889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:52:58.496611118 CET509483778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:58.529234886 CET509483778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:58.649028063 CET37785094889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:52:58.649075031 CET509483778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:58.768802881 CET37785094889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:52:59.818886995 CET37785094889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:52:59.819148064 CET509483778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:59.819222927 CET509483778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:59.820497990 CET509503778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:59.940319061 CET37785095089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:52:59.940455914 CET509503778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:52:59.941474915 CET509503778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:00.061270952 CET37785095089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:00.061414957 CET509503778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:00.181484938 CET37785095089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:01.288767099 CET37785095089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:01.288921118 CET509503778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:01.288965940 CET509503778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:01.289586067 CET509523778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:01.409329891 CET37785095289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:01.409451962 CET509523778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:01.410516024 CET509523778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:01.530270100 CET37785095289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:01.530551910 CET509523778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:01.650348902 CET37785095289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:02.686510086 CET42836443192.168.2.2391.189.91.43
                                                                      Dec 16, 2024 08:53:02.733477116 CET37785095289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:02.733771086 CET509523778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:02.733771086 CET509523778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:02.734321117 CET509543778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:02.854320049 CET37785095489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:02.854631901 CET509543778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:02.855669975 CET509543778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:02.975388050 CET37785095489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:02.975584984 CET509543778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:03.095347881 CET37785095489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:04.176393986 CET37785095489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:04.176668882 CET509543778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.176668882 CET509543778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.179079056 CET509563778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.222260952 CET4251680192.168.2.23109.202.202.202
                                                                      Dec 16, 2024 08:53:04.299264908 CET37785095689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:04.299540997 CET509563778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.301316023 CET509563778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.383841038 CET509583778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.421008110 CET37785095689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:04.421058893 CET509563778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.503729105 CET37785095889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:04.503796101 CET509583778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.516699076 CET509583778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.540946007 CET37785095689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:04.636460066 CET37785095889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:04.636503935 CET509583778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:04.756266117 CET37785095889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:05.681570053 CET37785095689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:05.681862116 CET509563778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:05.681862116 CET509563778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:05.682712078 CET509603778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:05.926378965 CET37785096089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:05.926435947 CET37785095889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:05.926501989 CET509583778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:05.926598072 CET509603778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:05.926809072 CET509583778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:05.928019047 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:05.928356886 CET509603778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:06.047796965 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:06.048067093 CET37785096089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:06.048075914 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:06.048109055 CET509603778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:06.049889088 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:06.167814970 CET37785096089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:06.169567108 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:06.169630051 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:06.289258957 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.254077911 CET37785096089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.254424095 CET509603778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.254424095 CET509603778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.255158901 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.370800972 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.370915890 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.371092081 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.371711016 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.376049042 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.376112938 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.377115011 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.491780043 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.491976023 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.493129015 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.497383118 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.497466087 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.615459919 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.615679026 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:07.618624926 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:07.737272024 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:08.701514959 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:08.701855898 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.701855898 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.702933073 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.817248106 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:08.817462921 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.817464113 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.818391085 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.822868109 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:08.822928905 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.824243069 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.938296080 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:08.938402891 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.939616919 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:08.944720030 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:08.944775105 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:09.059391975 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:09.059525967 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:09.064482927 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:09.179600000 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.145822048 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.146095037 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.146095037 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.146962881 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.262852907 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.263008118 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.263128996 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.264095068 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.268043995 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.268178940 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.269522905 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.384072065 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.384365082 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.386970997 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.390212059 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.390284061 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.508456945 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.508708000 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:10.510970116 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:10.629529953 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.593203068 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.593550920 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.593693972 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.594557047 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.714628935 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.714757919 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.716057062 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.732601881 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.732863903 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.732994080 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.733838081 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.835809946 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.835937023 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.853610039 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.853693008 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.855722904 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:11.955712080 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.975605965 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:11.975684881 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:12.095556021 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.037823915 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.038017035 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.038079977 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.039450884 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.159231901 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.159394026 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.161169052 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.177268028 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.177350044 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.177382946 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.177982092 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.280838013 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.281174898 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.297619104 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.297720909 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.299995899 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.400918961 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.419645071 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:13.419763088 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:13.539604902 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.486569881 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.486869097 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.486869097 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.487734079 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.607517004 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.607664108 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.609591007 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.622806072 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.622891903 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.622977018 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.623820066 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.729370117 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.729506969 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.743541956 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.743633032 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.745513916 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.849304914 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.865216970 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:14.865319967 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:14.985023975 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:15.935436010 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:15.935781956 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:15.935867071 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:15.936845064 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.056652069 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:16.056880951 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.058547020 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.078193903 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:16.078295946 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.078392029 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.079083920 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.178298950 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:16.178594112 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.198781013 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:16.198932886 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.200645924 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.298780918 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:16.320429087 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:16.320560932 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:16.440378904 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.381793976 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.382117987 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.382215977 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.383122921 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.502898932 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.503004074 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.504056931 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.522588015 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.522651911 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.522686958 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.523293018 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.623855114 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.624037027 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.643060923 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.643203974 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.644702911 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.743834019 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.764477015 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:17.764601946 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:17.788410902 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 08:53:17.884325027 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:18.835520983 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:18.835866928 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:18.835866928 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:18.836541891 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:18.956249952 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:18.956474066 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:18.957667112 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:18.962879896 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:18.962939024 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:18.963093042 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:18.963865995 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:19.077666998 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:19.077868938 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:19.083658934 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:19.083800077 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:19.086384058 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:19.197556019 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:19.205997944 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:19.206096888 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:19.325751066 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:20.304342031 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:20.304491997 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:20.304577112 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:20.305514097 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:20.426124096 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:20.426259995 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:20.428196907 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:20.548181057 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:20.548374891 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:20.668056965 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:21.757014990 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:21.757180929 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:21.757230043 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:21.757884026 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:21.877492905 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:21.877615929 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:21.879739046 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:21.999445915 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:21.999582052 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:22.119404078 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:23.204006910 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:23.204297066 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:23.204332113 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:23.205090046 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:23.324920893 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:23.325088978 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:23.326656103 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:23.446386099 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:23.446500063 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:23.566450119 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:24.650015116 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:24.650279045 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:24.650368929 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:24.651122093 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:24.770997047 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:24.771289110 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:24.773094893 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:24.894023895 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:24.894469023 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:25.014445066 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:26.100296974 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:26.100610018 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:26.100708961 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:26.101630926 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:26.221470118 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:26.221605062 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:26.223050117 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:26.344434977 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:26.344676971 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:26.464468002 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:29.095598936 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:29.215356112 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:29.530354023 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:29.530813932 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:30.074773073 CET42836443192.168.2.2391.189.91.43
                                                                      Dec 16, 2024 08:53:34.170365095 CET4251680192.168.2.23109.202.202.202
                                                                      Dec 16, 2024 08:53:36.232198954 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:36.352121115 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:36.665839911 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:53:36.666028023 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:53:58.743009090 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 08:54:29.577186108 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:54:29.696918011 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:54:30.011630058 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:54:30.011796951 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:54:36.713610888 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:54:36.833751917 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:54:37.147658110 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:54:37.147790909 CET510083778192.168.2.2389.169.4.44

                                                                      System Behavior

                                                                      Start time (UTC):07:52:57
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.arm.elf
                                                                      Arguments:/tmp/Space.arm.elf
                                                                      File size:4956856 bytes
                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                      Start time (UTC):07:52:57
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.arm.elf
                                                                      Arguments:-
                                                                      File size:4956856 bytes
                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                      Start time (UTC):07:52:57
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.arm.elf
                                                                      Arguments:-
                                                                      File size:4956856 bytes
                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                      Start time (UTC):07:52:57
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.arm.elf
                                                                      Arguments:-
                                                                      File size:4956856 bytes
                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                      Start time (UTC):07:53:03
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.arm.elf
                                                                      Arguments:-
                                                                      File size:4956856 bytes
                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                      Start time (UTC):07:53:03
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.arm.elf
                                                                      Arguments:-
                                                                      File size:4956856 bytes
                                                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1