Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.mips.elf

Overview

General Information

Sample name:Space.mips.elf
Analysis ID:1584407
MD5:44de196fc2d897cbd6e3961dfdfd9fea
SHA1:499a4302954bbd41c2d9a5490d4432486b3e8751
SHA256:25bf583d02fe7f11f58f4b18acc7bb0acbedf82330635c8c2c8dbfafaf4129ff
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1584407
Start date and time:2025-01-05 13:42:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mips.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.mips.elf
PID:5443
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5443.1.00007f5818400000.00007f581842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2940c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29420:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29434:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29448:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2945c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29470:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29484:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29498:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29510:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29524:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29538:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2954c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2959c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5447.1.00007f5818400000.00007f581842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2940c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29420:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29434:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29448:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2945c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29470:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29484:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29498:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29510:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29524:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29538:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2954c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2959c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5457.1.00007f5818400000.00007f581842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2940c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29420:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29434:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29448:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2945c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29470:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29484:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29498:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29510:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29524:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29538:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2954c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2959c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5445.1.00007f5818400000.00007f581842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x2940c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29420:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29434:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29448:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2945c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29470:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29484:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29498:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x294fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29510:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29524:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29538:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2954c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2959c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.mips.elf PID: 5443Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x39dd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x39f1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a05:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a19:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a2d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a41:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a55:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a69:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a7d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a91:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3aa5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ab9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3acd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ae1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3af5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b09:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b1d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b31:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b45:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b59:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b6d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.mips.elfVirustotal: Detection: 34%Perma Link
Source: Space.mips.elfReversingLabs: Detection: 36%
Source: global trafficTCP traffic: 192.168.2.13:46076 -> 79.133.46.252:3778
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: unknownTCP traffic detected without corresponding DNS query: 79.133.46.252
Source: Space.mips.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5443.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5447.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5457.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5445.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5443, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5445, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5447, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5457, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 5443.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5447.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5457.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5445.1.00007f5818400000.00007f581842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5443, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5445, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5447, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5457, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/238/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/239/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/5390/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/3095/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/241/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/1906/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/3648/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/5285/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/1482/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/1480/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/371/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/1238/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/134/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/3413/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/3776/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5443)File opened: /proc/936/statusJump to behavior
Source: Space.mips.elfSubmission file: segment LOAD with 7.9451 entropy (max. 8.0)
Source: /tmp/Space.mips.elf (PID: 5443)Queries kernel information via 'uname': Jump to behavior
Source: Space.mips.elf, 5443.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmp, Space.mips.elf, 5445.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmp, Space.mips.elf, 5447.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmp, Space.mips.elf, 5457.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmpBinary or memory string: Zl@x86_64/usr/bin/qemu-mips/tmp/Space.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mips.elf
Source: Space.mips.elf, 5443.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmp, Space.mips.elf, 5445.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmp, Space.mips.elf, 5447.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmp, Space.mips.elf, 5457.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: Space.mips.elf, 5443.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmp, Space.mips.elf, 5445.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmp, Space.mips.elf, 5447.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmp, Space.mips.elf, 5457.1.000055df2cf1b000.000055df2cfc3000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: Space.mips.elf, 5443.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmp, Space.mips.elf, 5445.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmp, Space.mips.elf, 5447.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmp, Space.mips.elf, 5457.1.00007ffe5fe87000.00007ffe5fea8000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1584407 Sample: Space.mips.elf Startdate: 05/01/2025 Architecture: LINUX Score: 60 20 79.133.46.252, 3778, 46076, 46078 AT-FIRSTCOLOAustriaAT Germany 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 Space.mips.elf 2->8         started        signatures3 process4 process5 10 Space.mips.elf 8->10         started        12 Space.mips.elf 8->12         started        14 Space.mips.elf 8->14         started        process6 16 Space.mips.elf 10->16         started        18 Space.mips.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.mips.elf35%VirustotalBrowse
Space.mips.elf37%ReversingLabsLinux.Trojan.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.mips.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    79.133.46.252
    unknownGermany
    203833AT-FIRSTCOLOAustriaATfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    79.133.46.252Space.mpsl.elfGet hashmaliciousUnknownBrowse
    • /hiddenbin/Space.mpsl
    Space.x86.elfGet hashmaliciousUnknownBrowse
    • /hiddenbin/Space.x86
    Space.mips.elfGet hashmaliciousUnknownBrowse
    • /hiddenbin/Space.mips
    Space.arm7.elfGet hashmaliciousUnknownBrowse
    • /hiddenbin/Space.arm7
    Space.arm6.elfGet hashmaliciousUnknownBrowse
    • /hiddenbin/Space.arm6
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    AT-FIRSTCOLOAustriaATSpace.m68k.elfGet hashmaliciousMiraiBrowse
    • 79.133.46.252
    Space.ppc.elfGet hashmaliciousUnknownBrowse
    • 79.133.46.252
    Space.x86.elfGet hashmaliciousUnknownBrowse
    • 79.133.46.252
    Space.x86_64.elfGet hashmaliciousUnknownBrowse
    • 79.133.46.252
    Space.arm6.elfGet hashmaliciousUnknownBrowse
    • 79.133.46.252
    Space.sh4.elfGet hashmaliciousUnknownBrowse
    • 79.133.46.252
    Space.x86.elfGet hashmaliciousMiraiBrowse
    • 79.133.46.252
    Space.arm.elfGet hashmaliciousMiraiBrowse
    • 79.133.46.252
    Space.ppc.elfGet hashmaliciousMiraiBrowse
    • 79.133.46.252
    Space.ppc.elfGet hashmaliciousMiraiBrowse
    • 79.133.46.252
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
    Entropy (8bit):7.942995259694459
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:Space.mips.elf
    File size:44'520 bytes
    MD5:44de196fc2d897cbd6e3961dfdfd9fea
    SHA1:499a4302954bbd41c2d9a5490d4432486b3e8751
    SHA256:25bf583d02fe7f11f58f4b18acc7bb0acbedf82330635c8c2c8dbfafaf4129ff
    SHA512:2d8454ad3f897e0b388ac2b4167cda9445e1acfc779228d855327e49a7ca4402ec86a7add15b8ed7e3c9ed16a7a459a6306add5c27c5764d0c33cd283a9823c8
    SSDEEP:768:P1b0VM3k+GWgdUmAIFX2VRkV+8BM3Wzfh6ugZe8V3JApJgGlzDpbuR1JV:P1b063kQqAm2UkGzMVtVSVJu/
    TLSH:C113F27C01294E9FEAE9D3F8057C878A3D94036169828D16B48CECF7558A6B17973FC4
    File Content Preview:.ELF...........................4.........4. ...(.............................................C...C......................UPX!.h.....................V.......?.E.h4...@b..) ..]....E..."B...^...l..!.D....U+o1..G..Hh.p......d..3..../^O..6.v....................

    ELF header

    Class:ELF32
    Data:2's complement, big endian
    Version:1 (current)
    Machine:MIPS R3000
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x109980
    Flags:0x1007
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:2
    Section Header Offset:0
    Section Header Size:40
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x1000000x1000000xacc40xacc47.94510x5R E0x10000
    LOAD0xcffc0x43cffc0x43cffc0x00x00.00000x6RW 0x10000
    TimestampSource PortDest PortSource IPDest IP
    Jan 5, 2025 13:42:55.545901060 CET460763778192.168.2.1379.133.46.252
    Jan 5, 2025 13:42:55.550869942 CET37784607679.133.46.252192.168.2.13
    Jan 5, 2025 13:42:55.550921917 CET460763778192.168.2.1379.133.46.252
    Jan 5, 2025 13:42:55.600797892 CET460763778192.168.2.1379.133.46.252
    Jan 5, 2025 13:42:55.605653048 CET37784607679.133.46.252192.168.2.13
    Jan 5, 2025 13:42:55.605706930 CET460763778192.168.2.1379.133.46.252
    Jan 5, 2025 13:42:55.610538960 CET37784607679.133.46.252192.168.2.13
    Jan 5, 2025 13:43:01.335690975 CET460783778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:01.340631008 CET37784607879.133.46.252192.168.2.13
    Jan 5, 2025 13:43:01.340725899 CET460783778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:01.354881048 CET460783778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:01.359658003 CET37784607879.133.46.252192.168.2.13
    Jan 5, 2025 13:43:01.359702110 CET460783778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:01.364538908 CET37784607879.133.46.252192.168.2.13
    Jan 5, 2025 13:43:05.611551046 CET460763778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:05.616379023 CET37784607679.133.46.252192.168.2.13
    Jan 5, 2025 13:43:11.361090899 CET460783778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:11.365931988 CET37784607879.133.46.252192.168.2.13
    Jan 5, 2025 13:43:16.937302113 CET37784607679.133.46.252192.168.2.13
    Jan 5, 2025 13:43:16.937731981 CET460763778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:16.942589998 CET37784607679.133.46.252192.168.2.13
    Jan 5, 2025 13:43:17.941612005 CET460803778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:17.946474075 CET37784608079.133.46.252192.168.2.13
    Jan 5, 2025 13:43:17.946544886 CET460803778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:17.947444916 CET460803778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:17.952239037 CET37784608079.133.46.252192.168.2.13
    Jan 5, 2025 13:43:17.952280045 CET460803778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:17.956988096 CET37784608079.133.46.252192.168.2.13
    Jan 5, 2025 13:43:22.720477104 CET37784607879.133.46.252192.168.2.13
    Jan 5, 2025 13:43:22.721580029 CET460783778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:22.726342916 CET37784607879.133.46.252192.168.2.13
    Jan 5, 2025 13:43:23.723588943 CET460823778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:23.728445053 CET37784608279.133.46.252192.168.2.13
    Jan 5, 2025 13:43:23.728512049 CET460823778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:23.729110003 CET460823778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:23.733839035 CET37784608279.133.46.252192.168.2.13
    Jan 5, 2025 13:43:23.733887911 CET460823778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:23.738742113 CET37784608279.133.46.252192.168.2.13
    Jan 5, 2025 13:43:39.330493927 CET37784608079.133.46.252192.168.2.13
    Jan 5, 2025 13:43:39.330995083 CET460803778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:39.335800886 CET37784608079.133.46.252192.168.2.13
    Jan 5, 2025 13:43:40.333923101 CET460843778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:40.338788033 CET37784608479.133.46.252192.168.2.13
    Jan 5, 2025 13:43:40.338901043 CET460843778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:40.340228081 CET460843778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:40.345026016 CET37784608479.133.46.252192.168.2.13
    Jan 5, 2025 13:43:40.345112085 CET460843778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:40.349946976 CET37784608479.133.46.252192.168.2.13
    Jan 5, 2025 13:43:45.141501904 CET37784608279.133.46.252192.168.2.13
    Jan 5, 2025 13:43:45.141850948 CET460823778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:45.146882057 CET37784608279.133.46.252192.168.2.13
    Jan 5, 2025 13:43:46.143975019 CET460863778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:46.148825884 CET37784608679.133.46.252192.168.2.13
    Jan 5, 2025 13:43:46.148921967 CET460863778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:46.149960995 CET460863778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:46.154690027 CET37784608679.133.46.252192.168.2.13
    Jan 5, 2025 13:43:46.154763937 CET460863778192.168.2.1379.133.46.252
    Jan 5, 2025 13:43:46.159589052 CET37784608679.133.46.252192.168.2.13
    Jan 5, 2025 13:44:01.703959942 CET37784608479.133.46.252192.168.2.13
    Jan 5, 2025 13:44:01.704221964 CET460843778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:01.709044933 CET37784608479.133.46.252192.168.2.13
    Jan 5, 2025 13:44:02.706368923 CET460883778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:02.711296082 CET37784608879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:02.711360931 CET460883778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:02.712219000 CET460883778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:02.716989040 CET37784608879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:02.717041016 CET460883778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:02.721822977 CET37784608879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:07.499203920 CET37784608679.133.46.252192.168.2.13
    Jan 5, 2025 13:44:07.499557972 CET460863778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:07.504411936 CET37784608679.133.46.252192.168.2.13
    Jan 5, 2025 13:44:08.501533031 CET460903778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:08.506510019 CET37784609079.133.46.252192.168.2.13
    Jan 5, 2025 13:44:08.506572962 CET460903778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:08.507586956 CET460903778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:08.512356043 CET37784609079.133.46.252192.168.2.13
    Jan 5, 2025 13:44:08.512408018 CET460903778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:08.517249107 CET37784609079.133.46.252192.168.2.13
    Jan 5, 2025 13:44:12.722652912 CET460883778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:12.727504969 CET37784608879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:18.518093109 CET460903778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:18.523469925 CET37784609079.133.46.252192.168.2.13
    Jan 5, 2025 13:44:24.130347967 CET37784608879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:24.130647898 CET460883778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:24.136363983 CET37784608879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:25.133207083 CET460923778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:25.138196945 CET37784609279.133.46.252192.168.2.13
    Jan 5, 2025 13:44:25.138273001 CET460923778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:25.139516115 CET460923778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:25.144349098 CET37784609279.133.46.252192.168.2.13
    Jan 5, 2025 13:44:25.144426107 CET460923778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:25.149192095 CET37784609279.133.46.252192.168.2.13
    Jan 5, 2025 13:44:29.907756090 CET37784609079.133.46.252192.168.2.13
    Jan 5, 2025 13:44:29.908055067 CET460903778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:29.914333105 CET37784609079.133.46.252192.168.2.13
    Jan 5, 2025 13:44:30.909815073 CET460943778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:30.914680004 CET37784609479.133.46.252192.168.2.13
    Jan 5, 2025 13:44:30.914746046 CET460943778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:30.915334940 CET460943778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:30.920133114 CET37784609479.133.46.252192.168.2.13
    Jan 5, 2025 13:44:30.920186043 CET460943778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:30.925017118 CET37784609479.133.46.252192.168.2.13
    Jan 5, 2025 13:44:46.516628027 CET37784609279.133.46.252192.168.2.13
    Jan 5, 2025 13:44:46.516879082 CET460923778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:46.522017002 CET37784609279.133.46.252192.168.2.13
    Jan 5, 2025 13:44:47.518812895 CET460963778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:47.525262117 CET37784609679.133.46.252192.168.2.13
    Jan 5, 2025 13:44:47.525350094 CET460963778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:47.526467085 CET460963778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:47.531203032 CET37784609679.133.46.252192.168.2.13
    Jan 5, 2025 13:44:47.531264067 CET460963778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:47.536102057 CET37784609679.133.46.252192.168.2.13
    Jan 5, 2025 13:44:52.282488108 CET37784609479.133.46.252192.168.2.13
    Jan 5, 2025 13:44:52.282650948 CET460943778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:52.287448883 CET37784609479.133.46.252192.168.2.13
    Jan 5, 2025 13:44:53.284243107 CET460983778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:53.289231062 CET37784609879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:53.289302111 CET460983778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:53.289891005 CET460983778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:53.294687033 CET37784609879.133.46.252192.168.2.13
    Jan 5, 2025 13:44:53.294749975 CET460983778192.168.2.1379.133.46.252
    Jan 5, 2025 13:44:53.299530983 CET37784609879.133.46.252192.168.2.13

    System Behavior

    Start time (UTC):12:42:54
    Start date (UTC):05/01/2025
    Path:/tmp/Space.mips.elf
    Arguments:/tmp/Space.mips.elf
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:42:54
    Start date (UTC):05/01/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:42:54
    Start date (UTC):05/01/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:42:54
    Start date (UTC):05/01/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:43:00
    Start date (UTC):05/01/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:43:00
    Start date (UTC):05/01/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c