Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.mpsl.elf

Overview

General Information

Sample name:Space.mpsl.elf
Analysis ID:1580586
MD5:594b0c6dda90b4666f6cb871ef7ac269
SHA1:f3848823f183a5758e3497e8469f489e3b6fd2af
SHA256:059172ffb609f2b9842c7d75006d6290f38aa8b3226975ebacef5e0ff280637b
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580586
Start date and time:2024-12-25 11:21:14 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mpsl.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
  • VT rate limit hit for: Space.mpsl.elf
Command:/tmp/Space.mpsl.elf
PID:5529
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5533.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5531.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5545.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5529.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2739c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x273ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27400:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27414:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27428:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2743c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27450:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27464:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27478:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2748c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x274f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2752c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.mpsl.elf PID: 5529Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xce07:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xce1b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xce2f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xce43:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xce57:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xce6b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xce7f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xce93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcea7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcebb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcecf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcee3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcef7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf0b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf1f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf33:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf47:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf5b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf6f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf83:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xcf97:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.mpsl.elfAvira: detected
Source: Space.mpsl.elfReversingLabs: Detection: 50%
Source: global trafficTCP traffic: 192.168.2.15:41018 -> 154.216.20.216:3778
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: Space.mpsl.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5533.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5531.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5545.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5529.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 5529, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 5531, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 5533, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mpsl.elf PID: 5545, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 5533.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5531.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5545.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5529.1.00007f4f4c400000.00007f4f4c42a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 5529, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 5531, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 5533, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mpsl.elf PID: 5545, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1333/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1695/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/911/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1591/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1585/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/804/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/3407/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1484/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/133/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1479/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/931/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1595/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/812/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/933/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/3419/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/35/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/3310/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/260/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/261/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/262/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/142/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/263/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/264/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/265/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/145/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/266/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/267/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/268/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/3303/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/269/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1486/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/1806/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/3440/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/270/statusJump to behavior
Source: /tmp/Space.mpsl.elf (PID: 5529)File opened: /proc/271/statusJump to behavior
Source: Space.mpsl.elfSubmission file: segment LOAD with 7.9458 entropy (max. 8.0)
Source: /tmp/Space.mpsl.elf (PID: 5529)Queries kernel information via 'uname': Jump to behavior
Source: Space.mpsl.elf, 5529.1.000055d269b97000.000055d269c3f000.rw-.sdmp, Space.mpsl.elf, 5531.1.000055d269b97000.000055d269c3f000.rw-.sdmp, Space.mpsl.elf, 5533.1.000055d269b97000.000055d269c3f000.rw-.sdmp, Space.mpsl.elf, 5545.1.000055d269b97000.000055d269c3f000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: Space.mpsl.elf, 5529.1.000055d269b97000.000055d269c3f000.rw-.sdmp, Space.mpsl.elf, 5531.1.000055d269b97000.000055d269c3f000.rw-.sdmp, Space.mpsl.elf, 5533.1.000055d269b97000.000055d269c3f000.rw-.sdmp, Space.mpsl.elf, 5545.1.000055d269b97000.000055d269c3f000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: Space.mpsl.elf, 5529.1.00007ffc5939d000.00007ffc593be000.rw-.sdmp, Space.mpsl.elf, 5531.1.00007ffc5939d000.00007ffc593be000.rw-.sdmp, Space.mpsl.elf, 5533.1.00007ffc5939d000.00007ffc593be000.rw-.sdmp, Space.mpsl.elf, 5545.1.00007ffc5939d000.00007ffc593be000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/Space.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mpsl.elf
Source: Space.mpsl.elf, 5529.1.00007ffc5939d000.00007ffc593be000.rw-.sdmp, Space.mpsl.elf, 5531.1.00007ffc5939d000.00007ffc593be000.rw-.sdmp, Space.mpsl.elf, 5533.1.00007ffc5939d000.00007ffc593be000.rw-.sdmp, Space.mpsl.elf, 5545.1.00007ffc5939d000.00007ffc593be000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1580586 Sample: Space.mpsl.elf Startdate: 25/12/2024 Architecture: LINUX Score: 68 20 154.216.20.216, 3778, 41018, 41020 SKHT-ASShenzhenKatherineHengTechnologyInformationCo Seychelles 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 26 Multi AV Scanner detection for submitted file 2->26 28 Sample is packed with UPX 2->28 8 Space.mpsl.elf 2->8         started        signatures3 process4 process5 10 Space.mpsl.elf 8->10         started        12 Space.mpsl.elf 8->12         started        14 Space.mpsl.elf 8->14         started        process6 16 Space.mpsl.elf 10->16         started        18 Space.mpsl.elf 10->18         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Space.mpsl.elf50%ReversingLabsLinux.Trojan.Mirai
Space.mpsl.elf100%AviraEXP/ELF.Agent.M.28
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.mpsl.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    154.216.20.216
    unknownSeychelles
    135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    154.216.20.216Space.m68k.elfGet hashmaliciousMiraiBrowse
      Space.i686.elfGet hashmaliciousUnknownBrowse
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        SKHT-ASShenzhenKatherineHengTechnologyInformationCoSpace.m68k.elfGet hashmaliciousMiraiBrowse
        • 154.216.20.216
        Space.i686.elfGet hashmaliciousUnknownBrowse
        • 154.216.20.216
        byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
        • 154.216.19.138
        zerarm7.elfGet hashmaliciousUnknownBrowse
        • 154.216.16.250
        nabm68k.elfGet hashmaliciousUnknownBrowse
        • 154.216.16.244
        nabarm.elfGet hashmaliciousUnknownBrowse
        • 154.216.16.244
        zerppc.elfGet hashmaliciousUnknownBrowse
        • 154.216.16.250
        zerarm5.elfGet hashmaliciousUnknownBrowse
        • 154.216.16.244
        nabx86.elfGet hashmaliciousUnknownBrowse
        • 154.216.16.244
        nabsh4.elfGet hashmaliciousUnknownBrowse
        • 154.216.16.244
        No context
        No context
        No created / dropped files found
        File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
        Entropy (8bit):7.9431631400512765
        TrID:
        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
        File name:Space.mpsl.elf
        File size:44'352 bytes
        MD5:594b0c6dda90b4666f6cb871ef7ac269
        SHA1:f3848823f183a5758e3497e8469f489e3b6fd2af
        SHA256:059172ffb609f2b9842c7d75006d6290f38aa8b3226975ebacef5e0ff280637b
        SHA512:5a1a1d931bd0c434e98d80d36da42e91ad4cb9e5ea6aa2ed0e3e66d90eec043d627e8acca0fd148997e3b8b7c9996e423f3966cf96cde1ee0b6cb54cddc0ec92
        SSDEEP:768:4QdzLFMbXkqyyxwmGFm3qsSPhkj96MiKrecs6cDtyO5XnQDh3nWN:nPmwqBOc31LNrecs6KtPXQDa
        TLSH:6E13E14D9BA2ED56CCCF583970CD13B50E9371C124171FDCA359AC8CA961C8ABCCA8B5
        File Content Preview:.ELF........................4...........4. ...(...............................................C...C.....................UPX!d...................V..........?.E.h;....#......b.L#>g7.9f......1....F.....f.u.(L.X.Ak..8......~.Dl0..Wl../... ..il...&..........p?

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:MIPS R3000
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:UNIX - System V
        ABI Version:0
        Entry Point Address:0x1098d8
        Flags:0x1007
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:2
        Section Header Offset:0
        Section Header Size:40
        Number of Section Headers:0
        Header String Table Index:0
        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x1000000x1000000xac150xac157.94580x5R E0x10000
        LOAD0xaffc0x43affc0x43affc0x00x00.00000x6RW 0x10000
        TimestampSource PortDest PortSource IPDest IP
        Dec 25, 2024 11:22:04.271991968 CET410183778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:04.391901970 CET377841018154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:04.391978979 CET410183778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:04.397672892 CET410183778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:04.517297983 CET377841018154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:04.517354012 CET410183778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:04.636962891 CET377841018154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:05.688980103 CET377841018154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:05.689141989 CET410183778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:05.689392090 CET410183778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:05.689990044 CET410203778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:05.809614897 CET377841020154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:05.809804916 CET410203778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:05.810606003 CET410203778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:05.930200100 CET377841020154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:05.930613041 CET410203778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:06.050242901 CET377841020154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:07.107481003 CET377841020154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:07.107731104 CET410203778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:07.107808113 CET410203778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:07.108391047 CET410223778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:07.228055954 CET377841022154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:07.228291035 CET410223778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:07.229322910 CET410223778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:07.348982096 CET377841022154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:07.349328041 CET410223778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:07.468880892 CET377841022154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:08.529612064 CET377841022154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:08.529933929 CET410223778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:08.529934883 CET410223778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:08.530571938 CET410243778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:08.650196075 CET377841024154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:08.650357962 CET410243778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:08.651348114 CET410243778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:08.770899057 CET377841024154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:08.771109104 CET410243778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:08.890794992 CET377841024154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:09.948637962 CET377841024154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:09.948940039 CET410243778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:09.948940039 CET410243778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:09.949681997 CET410263778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.069226027 CET377841026154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:10.069492102 CET410263778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.070453882 CET410263778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.190138102 CET377841026154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:10.190265894 CET410263778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.309856892 CET377841026154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:10.533216953 CET410283778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.653275967 CET377841028154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:10.653363943 CET410283778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.668076992 CET410283778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.787789106 CET377841028154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:10.787849903 CET410283778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:10.907577991 CET377841028154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:11.370410919 CET377841026154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:11.370714903 CET410263778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.370714903 CET410263778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.371773005 CET410303778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.491522074 CET377841030154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:11.491760969 CET410303778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.492903948 CET410303778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.612479925 CET377841030154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:11.612598896 CET410303778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.732599974 CET377841030154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:11.951543093 CET377841028154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:11.951908112 CET410283778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.952241898 CET410283778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:11.953748941 CET410323778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.073364973 CET377841032154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:12.073599100 CET410323778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.075967073 CET410323778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.195512056 CET377841032154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:12.195687056 CET410323778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.315426111 CET377841032154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:12.792129993 CET377841030154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:12.792444944 CET410303778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.792444944 CET410303778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.793092012 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.912858963 CET377841034154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:12.913116932 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:12.913777113 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.033433914 CET377841034154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:13.033508062 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.153213024 CET377841034154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:13.375389099 CET377841032154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:13.375595093 CET410323778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.375595093 CET410323778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.376143932 CET410363778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.495719910 CET377841036154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:13.495937109 CET410363778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.496892929 CET410363778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.616501093 CET377841036154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:13.616615057 CET410363778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:13.736301899 CET377841036154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:14.797286034 CET377841036154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:14.797625065 CET410363778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:14.797626019 CET410363778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:14.798166037 CET410383778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:14.917690039 CET377841038154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:14.917859077 CET410383778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:14.918610096 CET410383778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:15.038178921 CET377841038154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:15.038269997 CET410383778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:15.157984972 CET377841038154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:16.217946053 CET377841038154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:16.218080044 CET410383778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:16.218126059 CET410383778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:16.218679905 CET410403778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:16.338238001 CET377841040154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:16.338336945 CET410403778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:16.339421034 CET410403778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:16.458901882 CET377841040154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:16.459000111 CET410403778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:16.578624964 CET377841040154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:17.637669086 CET377841040154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:17.637979984 CET410403778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:17.637979984 CET410403778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:17.638478994 CET410423778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:17.758021116 CET377841042154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:17.758482933 CET410423778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:17.759771109 CET410423778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:17.879585028 CET377841042154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:17.879709005 CET410423778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:17.999372005 CET377841042154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:19.060623884 CET377841042154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:19.060762882 CET410423778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:19.060986996 CET410423778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:19.061574936 CET410443778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:19.182257891 CET377841044154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:19.182473898 CET410443778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:19.183908939 CET410443778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:19.304371119 CET377841044154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:19.304744959 CET410443778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:19.424623013 CET377841044154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:20.480688095 CET377841044154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:20.481096983 CET410443778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:20.481235981 CET410443778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:20.482083082 CET410463778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:20.601726055 CET377841046154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:20.601944923 CET410463778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:20.602777958 CET410463778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:20.722417116 CET377841046154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:20.722610950 CET410463778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:20.842262030 CET377841046154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:21.902679920 CET377841046154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:21.903044939 CET410463778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:21.903126955 CET410463778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:21.903815985 CET410483778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:22.023471117 CET377841048154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:22.023689032 CET410483778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:22.024981022 CET410483778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:22.144531965 CET377841048154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:22.144831896 CET410483778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:22.264589071 CET377841048154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:22.916807890 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.037229061 CET377841034154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:23.326687098 CET377841048154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:23.326859951 CET410483778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.326936007 CET410483778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.327831030 CET410503778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.338155031 CET377841034154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:23.338210106 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.447783947 CET377841050154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:23.448014975 CET410503778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.449395895 CET410503778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.569011927 CET377841050154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:23.569156885 CET410503778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:23.689106941 CET377841050154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:24.746972084 CET377841050154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:24.747242928 CET410503778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:24.747549057 CET410503778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:24.748420000 CET410523778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:24.868046045 CET377841052154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:24.868371964 CET410523778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:24.869575977 CET410523778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:24.989355087 CET377841052154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:24.989661932 CET410523778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:25.110064030 CET377841052154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:26.167251110 CET377841052154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:26.167450905 CET410523778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:26.167618990 CET410523778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:26.168365002 CET410543778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:26.287898064 CET377841054154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:26.288265944 CET410543778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:26.289438009 CET410543778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:26.409122944 CET377841054154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:26.409416914 CET410543778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:26.529225111 CET377841054154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:27.597634077 CET377841054154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:27.597799063 CET410543778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:27.597845078 CET410543778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:27.598381996 CET410563778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:27.717995882 CET377841056154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:27.718197107 CET410563778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:27.718784094 CET410563778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:27.838305950 CET377841056154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:27.838563919 CET410563778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:27.958395958 CET377841056154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:29.021167040 CET377841056154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:29.021322966 CET410563778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:29.021410942 CET410563778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:29.021982908 CET410583778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:29.141563892 CET377841058154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:29.141802073 CET410583778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:29.143075943 CET410583778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:29.262610912 CET377841058154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:29.262737036 CET410583778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:29.382410049 CET377841058154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:30.440845966 CET377841058154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:30.441061020 CET410583778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:30.441194057 CET410583778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:30.442061901 CET410603778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:30.561633110 CET377841060154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:30.562083960 CET410603778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:30.563081026 CET410603778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:30.682604074 CET377841060154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:30.682867050 CET410603778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:30.802561998 CET377841060154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:31.858865023 CET377841060154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:31.859154940 CET410603778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:31.859155893 CET410603778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:31.859941006 CET410623778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:31.979521036 CET377841062154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:31.979860067 CET410623778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:31.980984926 CET410623778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:32.100667000 CET377841062154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:32.100805998 CET410623778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:32.220518112 CET377841062154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:33.277221918 CET377841062154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:33.277542114 CET410623778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:33.277542114 CET410623778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:33.278414965 CET410643778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:33.397978067 CET377841064154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:33.398125887 CET410643778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:33.399251938 CET410643778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:33.518762112 CET377841064154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:33.518834114 CET410643778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:33.638461113 CET377841064154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:34.694428921 CET377841064154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:34.694714069 CET410643778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:34.694756985 CET410643778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:34.695540905 CET410663778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:34.815257072 CET377841066154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:34.815418005 CET410663778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:34.816597939 CET410663778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:34.936119080 CET377841066154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:34.936248064 CET410663778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:35.055855036 CET377841066154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:36.114805937 CET377841066154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:36.115030050 CET410663778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:36.115320921 CET410663778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:36.116296053 CET410683778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:36.235970020 CET377841068154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:36.236241102 CET410683778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:36.237695932 CET410683778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:36.357227087 CET377841068154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:36.357511044 CET410683778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:36.477211952 CET377841068154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:46.247761011 CET410683778192.168.2.15154.216.20.216
        Dec 25, 2024 11:22:46.367692947 CET377841068154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:46.669884920 CET377841068154.216.20.216192.168.2.15
        Dec 25, 2024 11:22:46.670048952 CET410683778192.168.2.15154.216.20.216
        Dec 25, 2024 11:23:23.389287949 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:23:23.509133101 CET377841034154.216.20.216192.168.2.15
        Dec 25, 2024 11:23:23.810606003 CET377841034154.216.20.216192.168.2.15
        Dec 25, 2024 11:23:23.810817957 CET410343778192.168.2.15154.216.20.216
        Dec 25, 2024 11:23:46.728403091 CET410683778192.168.2.15154.216.20.216
        Dec 25, 2024 11:23:46.848299026 CET377841068154.216.20.216192.168.2.15
        Dec 25, 2024 11:23:47.151302099 CET377841068154.216.20.216192.168.2.15
        Dec 25, 2024 11:23:47.151671886 CET410683778192.168.2.15154.216.20.216

        System Behavior

        Start time (UTC):10:22:03
        Start date (UTC):25/12/2024
        Path:/tmp/Space.mpsl.elf
        Arguments:/tmp/Space.mpsl.elf
        File size:5773336 bytes
        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

        Start time (UTC):10:22:03
        Start date (UTC):25/12/2024
        Path:/tmp/Space.mpsl.elf
        Arguments:-
        File size:5773336 bytes
        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

        Start time (UTC):10:22:03
        Start date (UTC):25/12/2024
        Path:/tmp/Space.mpsl.elf
        Arguments:-
        File size:5773336 bytes
        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

        Start time (UTC):10:22:03
        Start date (UTC):25/12/2024
        Path:/tmp/Space.mpsl.elf
        Arguments:-
        File size:5773336 bytes
        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

        Start time (UTC):10:22:09
        Start date (UTC):25/12/2024
        Path:/tmp/Space.mpsl.elf
        Arguments:-
        File size:5773336 bytes
        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

        Start time (UTC):10:22:09
        Start date (UTC):25/12/2024
        Path:/tmp/Space.mpsl.elf
        Arguments:-
        File size:5773336 bytes
        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9