Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.arm6.elf

Overview

General Information

Sample name:Space.arm6.elf
Analysis ID:1581306
MD5:bb3c48fea88d7abc045efff46b5d96e6
SHA1:446c06b0671e4324aee88035b2b07895a1853111
SHA256:6644ed14ccced606696f94783b0ae1eb8e66ddf691c8b2a80f189b2dda400c25
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581306
Start date and time:2024-12-27 10:42:42 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.arm6.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.arm6.elf
PID:5515
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5565, Parent: 3673)
  • rm (PID: 5565, Parent: 3673, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.BtSwAwO5NR /tmp/tmp.PWnM8nXojD /tmp/tmp.7F3amuIALQ
  • dash New Fork (PID: 5566, Parent: 3673)
  • cat (PID: 5566, Parent: 3673, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.BtSwAwO5NR
  • dash New Fork (PID: 5567, Parent: 3673)
  • head (PID: 5567, Parent: 3673, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5568, Parent: 3673)
  • tr (PID: 5568, Parent: 3673, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5569, Parent: 3673)
  • cut (PID: 5569, Parent: 3673, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5570, Parent: 3673)
  • cat (PID: 5570, Parent: 3673, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.BtSwAwO5NR
  • dash New Fork (PID: 5571, Parent: 3673)
  • head (PID: 5571, Parent: 3673, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5572, Parent: 3673)
  • tr (PID: 5572, Parent: 3673, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5573, Parent: 3673)
  • cut (PID: 5573, Parent: 3673, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5574, Parent: 3673)
  • rm (PID: 5574, Parent: 3673, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.BtSwAwO5NR /tmp/tmp.PWnM8nXojD /tmp/tmp.7F3amuIALQ
  • cleanup
SourceRuleDescriptionAuthorStrings
5517.1.00007f08f8017000.00007f08f802f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5519.1.00007f08f8017000.00007f08f802f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5515.1.00007f08f8017000.00007f08f802f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5533.1.00007f08f8017000.00007f08f802f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.arm6.elf PID: 5515Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x1597b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1598f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x159a3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x159b7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x159cb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x159df:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x159f3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a07:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a1b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a2f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a43:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a57:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a6b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a7f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15a93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15aa7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15abb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15acf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15ae3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15af7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15b0b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.arm6.elfVirustotal: Detection: 41%Perma Link
Source: Space.arm6.elfReversingLabs: Detection: 44%
Source: unknownHTTPS traffic detected: 54.217.10.153:443 -> 192.168.2.15:49566 version: TLS 1.2
Source: global trafficTCP traffic: 192.168.2.15:39306 -> 159.100.18.129:3778
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: Space.arm6.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 49566 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49566
Source: unknownHTTPS traffic detected: 54.217.10.153:443 -> 192.168.2.15:49566 version: TLS 1.2

System Summary

barindex
Source: 5517.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5519.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5515.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5533.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5515, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5517, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5519, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5533, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x8000
Source: 5517.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5519.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5515.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5533.1.00007f08f8017000.00007f08f802f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5515, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5517, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5519, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5533, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1333/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1695/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/911/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1591/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1585/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/804/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3407/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1484/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/133/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1479/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/931/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1595/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/812/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/933/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3419/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/35/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3673/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3310/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/260/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/261/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/262/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/142/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/263/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/264/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/265/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/145/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/266/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/267/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/268/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3303/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/269/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1486/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/1806/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3669/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5515)File opened: /proc/3440/statusJump to behavior
Source: /usr/bin/dash (PID: 5565)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.BtSwAwO5NR /tmp/tmp.PWnM8nXojD /tmp/tmp.7F3amuIALQJump to behavior
Source: /usr/bin/dash (PID: 5574)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.BtSwAwO5NR /tmp/tmp.PWnM8nXojD /tmp/tmp.7F3amuIALQJump to behavior
Source: Space.arm6.elfSubmission file: segment LOAD with 7.9738 entropy (max. 8.0)
Source: /tmp/Space.arm6.elf (PID: 5515)Queries kernel information via 'uname': Jump to behavior
Source: Space.arm6.elf, 5515.1.0000558759c8d000.0000558759e7b000.rw-.sdmp, Space.arm6.elf, 5517.1.0000558759c8d000.0000558759e7b000.rw-.sdmp, Space.arm6.elf, 5519.1.0000558759c8d000.0000558759e7b000.rw-.sdmp, Space.arm6.elf, 5533.1.0000558759c8d000.0000558759e7b000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: Space.arm6.elf, 5515.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmp, Space.arm6.elf, 5517.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmp, Space.arm6.elf, 5519.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmp, Space.arm6.elf, 5533.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/Space.arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.arm6.elf
Source: Space.arm6.elf, 5515.1.0000558759c8d000.0000558759e7b000.rw-.sdmp, Space.arm6.elf, 5517.1.0000558759c8d000.0000558759e7b000.rw-.sdmp, Space.arm6.elf, 5519.1.0000558759c8d000.0000558759e7b000.rw-.sdmp, Space.arm6.elf, 5533.1.0000558759c8d000.0000558759e7b000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: Space.arm6.elf, 5515.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmp, Space.arm6.elf, 5517.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmp, Space.arm6.elf, 5519.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmp, Space.arm6.elf, 5533.1.00007ffda36d4000.00007ffda36f5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581306 Sample: Space.arm6.elf Startdate: 27/12/2024 Architecture: LINUX Score: 60 26 159.100.18.129, 3778, 39306, 39308 DE-FIRSTCOLOwwwfirst-colonetDE Germany 2->26 28 54.217.10.153, 443, 49566 AMAZON-02US United States 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Sample is packed with UPX 2->34 8 Space.arm6.elf 2->8         started        10 dash rm 2->10         started        12 dash cat 2->12         started        14 8 other processes 2->14 signatures3 process4 process5 16 Space.arm6.elf 8->16         started        18 Space.arm6.elf 8->18         started        20 Space.arm6.elf 8->20         started        process6 22 Space.arm6.elf 16->22         started        24 Space.arm6.elf 16->24         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Space.arm6.elf41%VirustotalBrowse
Space.arm6.elf45%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.arm6.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.217.10.153
    unknownUnited States
    16509AMAZON-02USfalse
    159.100.18.129
    unknownGermany
    44066DE-FIRSTCOLOwwwfirst-colonetDEfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.217.10.153RpcSecurity.mips.elfGet hashmaliciousUnknownBrowse
      mips64.elfGet hashmaliciousMiraiBrowse
        Space.ppc.elfGet hashmaliciousMiraiBrowse
          .5r3fqt67ew531has4231.mpsl.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
            m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
              i686.elfGet hashmaliciousMirai, GafgytBrowse
                loligang.arm5.elfGet hashmaliciousMiraiBrowse
                  vqsjh4.elfGet hashmaliciousMiraiBrowse
                    x-3.2-.ISIS.elfGet hashmaliciousGafgytBrowse
                      m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                        159.100.18.129Space.mpsl.elfGet hashmaliciousUnknownBrowse
                          Space.x86_64.elfGet hashmaliciousUnknownBrowse
                            Space.m68k.elfGet hashmaliciousMiraiBrowse
                              Space.x86.elfGet hashmaliciousUnknownBrowse
                                Space.ppc.elfGet hashmaliciousUnknownBrowse
                                  Space.mips.elfGet hashmaliciousUnknownBrowse
                                    No context
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    DE-FIRSTCOLOwwwfirst-colonetDESpace.mpsl.elfGet hashmaliciousUnknownBrowse
                                    • 159.100.18.129
                                    Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                    • 159.100.18.129
                                    Space.m68k.elfGet hashmaliciousMiraiBrowse
                                    • 159.100.18.129
                                    Space.x86.elfGet hashmaliciousUnknownBrowse
                                    • 159.100.18.129
                                    Space.ppc.elfGet hashmaliciousUnknownBrowse
                                    • 159.100.18.129
                                    Space.mips.elfGet hashmaliciousUnknownBrowse
                                    • 159.100.18.129
                                    boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                    • 159.100.14.33
                                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                    • 159.100.14.33
                                    boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                    • 159.100.14.33
                                    boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                    • 159.100.14.33
                                    AMAZON-02UShttps://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                    • 52.53.112.200
                                    https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                    • 52.53.112.200
                                    https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                    • 52.53.112.200
                                    https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                                    • 52.53.112.200
                                    sh4.nn.elfGet hashmaliciousOkiruBrowse
                                    • 54.171.230.55
                                    db0fa4b8db0333367e9bda3ab68b8042.i686.elfGet hashmaliciousMirai, GafgytBrowse
                                    • 35.73.111.15
                                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                    • 54.171.230.55
                                    5935c1f1a7da8e42028da77013b80635afdd605866569.exeGet hashmaliciousUnknownBrowse
                                    • 18.167.52.240
                                    aD7D9fkpII.exeGet hashmaliciousVidarBrowse
                                    • 18.238.49.124
                                    http://www.finanzamthessen.deGet hashmaliciousUnknownBrowse
                                    • 54.75.69.192
                                    No context
                                    No context
                                    No created / dropped files found
                                    File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, no section header
                                    Entropy (8bit):7.9721474862994395
                                    TrID:
                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                    File name:Space.arm6.elf
                                    File size:44'600 bytes
                                    MD5:bb3c48fea88d7abc045efff46b5d96e6
                                    SHA1:446c06b0671e4324aee88035b2b07895a1853111
                                    SHA256:6644ed14ccced606696f94783b0ae1eb8e66ddf691c8b2a80f189b2dda400c25
                                    SHA512:bf62f7e7be38e7fbc7aadd4b1229387fc8d7e6fb12dec5807dff4251e4917def5ddaa777c4b7e982eaaa6819c368925abbc2ca898e15c09962ac503e984684d6
                                    SSDEEP:768:EnZOKj8x/QSQ3y/4qFTOdeoJWBhdYnjWcBWDW4s5GyZDa6XXbgub49q3UELF:yXwQSYPqFHI8rOjBn4+9DXZhLF
                                    TLSH:4F13F191CE067E93DC523E77EFA8958F43188EF5C27A2313AA2805BC5D93740E5E8587
                                    File Content Preview:.ELF..............(.........4...........4. ...(.........................................H...H...H...................Q.td...............................OUPX!...................._..........?.E.h;....#..$.......L..T.|..r.F..ZS..n.8.I+.e......rQN..D....I.:#/.

                                    ELF header

                                    Class:ELF32
                                    Data:2's complement, little endian
                                    Version:1 (current)
                                    Machine:ARM
                                    Version Number:0x1
                                    Type:EXEC (Executable file)
                                    OS/ABI:UNIX - Linux
                                    ABI Version:0
                                    Entry Point Address:0x11b00
                                    Flags:0x4000002
                                    ELF Header Size:52
                                    Program Header Offset:52
                                    Program Header Size:32
                                    Number of Program Headers:3
                                    Section Header Offset:0
                                    Section Header Size:40
                                    Number of Section Headers:0
                                    Header String Table Index:0
                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                    LOAD0x00x80000x80000xaced0xaced7.97380x5R E0x8000
                                    LOAD0xb480x20b480x20b480x00x00.00000x6RW 0x8000
                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                    TimestampSource PortDest PortSource IPDest IP
                                    Dec 27, 2024 10:43:26.291433096 CET393063778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:26.411133051 CET377839306159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:26.411192894 CET393063778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:26.427452087 CET393063778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:26.547122002 CET377839306159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:26.547184944 CET393063778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:26.666939020 CET377839306159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:27.717999935 CET377839306159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:27.718493938 CET393063778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:27.718493938 CET393063778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:27.722033024 CET393083778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:27.841640949 CET377839308159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:27.842077971 CET393083778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:27.843966961 CET393083778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:27.963556051 CET377839308159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:27.963963032 CET393083778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:28.083652020 CET377839308159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:29.147811890 CET377839308159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:29.147998095 CET393083778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:29.148072958 CET393083778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:29.148812056 CET393103778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:29.268423080 CET377839310159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:29.268531084 CET393103778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:29.269634962 CET393103778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:29.389209032 CET377839310159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:29.389337063 CET393103778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:29.509049892 CET377839310159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:30.528898954 CET377839310159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:30.529115915 CET393103778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:30.529227018 CET393103778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:30.529968977 CET393123778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:30.649630070 CET377839312159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:30.649816036 CET393123778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:30.651041985 CET393123778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:30.770550966 CET377839312159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:30.770713091 CET393123778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:30.890355110 CET377839312159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:31.954695940 CET377839312159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:31.954855919 CET393123778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:31.954914093 CET393123778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:31.955581903 CET393143778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.023703098 CET393163778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.075093985 CET377839314159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:32.075154066 CET393143778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.085071087 CET393143778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.143568039 CET377839316159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:32.143650055 CET393163778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.151222944 CET393163778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.204735994 CET377839314159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:32.204794884 CET393143778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.270744085 CET377839316159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:32.270803928 CET393163778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:32.324739933 CET377839314159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:32.390427113 CET377839316159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.380239010 CET377839314159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.380520105 CET393143778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.380520105 CET393143778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.381588936 CET393183778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.402724981 CET377839316159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.403069973 CET393163778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.403069973 CET393163778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.408412933 CET393203778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.501306057 CET377839318159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.501630068 CET393183778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.503570080 CET393183778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.528242111 CET377839320159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.528476000 CET393203778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.532761097 CET393203778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.623328924 CET377839318159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.623591900 CET393183778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.652569056 CET377839320159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.653754950 CET393203778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:33.743133068 CET377839318159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:33.773569107 CET377839320159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:34.808548927 CET377839318159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:34.808685064 CET393183778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:34.808737040 CET393183778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:34.809266090 CET393223778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:34.881520987 CET377839320159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:34.881669998 CET393203778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:34.881736994 CET393203778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:34.882220984 CET393243778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:34.929044008 CET377839322159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:34.929169893 CET393223778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:34.930229902 CET393223778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:35.001921892 CET377839324159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:35.002159119 CET393243778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:35.003673077 CET393243778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:35.049927950 CET377839322159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:35.050151110 CET393223778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:35.123496056 CET377839324159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:35.123652935 CET393243778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:35.169918060 CET377839322159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:35.243757963 CET377839324159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.280612946 CET377839322159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.280772924 CET393223778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.280838013 CET393223778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.281428099 CET393263778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.307311058 CET377839324159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.307535887 CET393243778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.307585001 CET393243778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.307976007 CET393283778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.401210070 CET377839326159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.401417971 CET393263778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.402453899 CET393263778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.427620888 CET377839328159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.427719116 CET393283778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.428628922 CET393283778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.522095919 CET377839326159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.522258997 CET393263778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.548392057 CET377839328159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.548523903 CET393283778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:36.642108917 CET377839326159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:36.668292046 CET377839328159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:37.707727909 CET377839326159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:37.708091974 CET393263778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.708091974 CET393263778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.708622932 CET393303778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.733501911 CET377839328159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:37.733607054 CET393283778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.733772039 CET393283778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.734031916 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.828195095 CET377839330159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:37.828393936 CET393303778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.829262018 CET393303778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.853727102 CET377839332159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:37.853799105 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:37.948769093 CET377839330159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:37.948877096 CET393303778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:38.068604946 CET377839330159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:38.764564037 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:38.884327888 CET377839332159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:38.884535074 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:38.885838032 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.005331039 CET377839332159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:39.005568027 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.125478029 CET377839332159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:39.180284023 CET377839330159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:39.180567026 CET393303778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.180567026 CET393303778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.181222916 CET393343778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.300687075 CET377839334159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:39.300822020 CET393343778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.301728010 CET393343778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.421266079 CET377839334159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:39.421490908 CET393343778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:39.541060925 CET377839334159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.190011978 CET377839332159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.190304041 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.190304041 CET393323778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.190887928 CET393363778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.310502052 CET377839336159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.310621023 CET393363778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.311578989 CET393363778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.431113005 CET377839336159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.431286097 CET393363778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.551079988 CET377839336159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.715974092 CET377839334159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.716191053 CET393343778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.716191053 CET393343778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.716923952 CET393383778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.836441040 CET377839338159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.836661100 CET393383778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.837634087 CET393383778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:40.957160950 CET377839338159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:40.957345963 CET393383778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:41.076884031 CET377839338159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:41.662226915 CET377839336159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:41.662544966 CET393363778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:41.662545919 CET393363778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:41.663654089 CET393403778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:41.783282042 CET377839340159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:41.783550978 CET393403778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:41.785052061 CET393403778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:41.905738115 CET377839340159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:41.905919075 CET393403778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:42.027124882 CET377839340159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:42.096610069 CET377839338159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:42.096834898 CET393383778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:42.096923113 CET393383778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:42.098114014 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:42.217699051 CET377839342159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:42.217947006 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:42.219651937 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:42.339286089 CET377839342159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:42.339441061 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:42.459095001 CET377839342159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:43.090094090 CET377839340159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:43.090399981 CET393403778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:43.090569019 CET393403778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:43.091352940 CET393443778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:43.211158991 CET377839344159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:43.211349964 CET393443778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:43.212625027 CET393443778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:43.332062006 CET377839344159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:43.332262993 CET393443778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:43.451838970 CET377839344159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:51.677031040 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:51.677076101 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:51.677088976 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:51.677370071 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:51.677370071 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:51.678138018 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:51.797724009 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:52.082470894 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:52.082592010 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:52.082874060 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:52.202366114 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:52.229655027 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:52.349376917 CET377839342159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:52.636732101 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:52.637068987 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:52.638556957 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:52.641287088 CET377839342159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:52.641360044 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:52.758557081 CET4434956654.217.10.153192.168.2.15
                                    Dec 27, 2024 10:43:52.758605957 CET49566443192.168.2.1554.217.10.153
                                    Dec 27, 2024 10:43:53.223107100 CET393443778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:43:53.342941999 CET377839344159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:53.633148909 CET377839344159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:43:53.633622885 CET393443778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:44:52.692687988 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:44:52.812427044 CET377839342159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:44:53.102745056 CET377839342159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:44:53.102890015 CET393423778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:44:53.679754972 CET393443778192.168.2.15159.100.18.129
                                    Dec 27, 2024 10:44:53.799447060 CET377839344159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:44:54.089626074 CET377839344159.100.18.129192.168.2.15
                                    Dec 27, 2024 10:44:54.089899063 CET393443778192.168.2.15159.100.18.129
                                    TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                    Dec 27, 2024 10:43:51.677088976 CET54.217.10.153443192.168.2.1549566CN=motd.ubuntu.com CN=R11, O=Let's Encrypt, C=USCN=R11, O=Let's Encrypt, C=US CN=ISRG Root X1, O=Internet Security Research Group, C=USMon Oct 21 10:21:37 CEST 2024 Wed Mar 13 01:00:00 CET 2024Sun Jan 19 09:21:36 CET 2025 Sat Mar 13 00:59:59 CET 2027
                                    CN=R11, O=Let's Encrypt, C=USCN=ISRG Root X1, O=Internet Security Research Group, C=USWed Mar 13 01:00:00 CET 2024Sat Mar 13 00:59:59 CET 2027

                                    System Behavior

                                    Start time (UTC):09:43:24
                                    Start date (UTC):27/12/2024
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:/tmp/Space.arm6.elf
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):09:43:24
                                    Start date (UTC):27/12/2024
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):09:43:24
                                    Start date (UTC):27/12/2024
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):09:43:24
                                    Start date (UTC):27/12/2024
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):09:43:30
                                    Start date (UTC):27/12/2024
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):09:43:30
                                    Start date (UTC):27/12/2024
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/rm
                                    Arguments:rm -f /tmp/tmp.BtSwAwO5NR /tmp/tmp.PWnM8nXojD /tmp/tmp.7F3amuIALQ
                                    File size:72056 bytes
                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/cat
                                    Arguments:cat /tmp/tmp.BtSwAwO5NR
                                    File size:43416 bytes
                                    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/head
                                    Arguments:head -n 10
                                    File size:47480 bytes
                                    MD5 hash:fd96a67145172477dd57131396fc9608

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/tr
                                    Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                    File size:51544 bytes
                                    MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/cut
                                    Arguments:cut -c -80
                                    File size:47480 bytes
                                    MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/cat
                                    Arguments:cat /tmp/tmp.BtSwAwO5NR
                                    File size:43416 bytes
                                    MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/head
                                    Arguments:head -n 10
                                    File size:47480 bytes
                                    MD5 hash:fd96a67145172477dd57131396fc9608

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/tr
                                    Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                    File size:51544 bytes
                                    MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/cut
                                    Arguments:cut -c -80
                                    File size:47480 bytes
                                    MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):09:43:51
                                    Start date (UTC):27/12/2024
                                    Path:/usr/bin/rm
                                    Arguments:rm -f /tmp/tmp.BtSwAwO5NR /tmp/tmp.PWnM8nXojD /tmp/tmp.7F3amuIALQ
                                    File size:72056 bytes
                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b