Edit tour

Linux Analysis Report
Space.arm6.elf

Overview

General Information

Sample name:Space.arm6.elf
Analysis ID:1644272
MD5:ddf4f9c9b60d35817ac87dc6fbbf7967
SHA1:5b12170410fb389dddbd70b0a4afaff4db03425c
SHA256:d6ec0ab27eca71ef8f9afa1589738fe98ec71bf5b29f5e1b2701e6c9a2ff8669
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1644272
Start date and time:2025-03-20 13:58:57 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.arm6.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.arm6.elf
PID:5481
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5562, Parent: 3632)
  • rm (PID: 5562, Parent: 3632, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.GBuXLr4p9L /tmp/tmp.I4Svy2tUug /tmp/tmp.0PVSgapK0c
  • dash New Fork (PID: 5563, Parent: 3632)
  • rm (PID: 5563, Parent: 3632, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.GBuXLr4p9L /tmp/tmp.I4Svy2tUug /tmp/tmp.0PVSgapK0c
  • cleanup
SourceRuleDescriptionAuthorStrings
5481.1.00007fe794017000.00007fe79402f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5501.1.00007fe794017000.00007fe79402f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5485.1.00007fe794017000.00007fe79402f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5483.1.00007fe794017000.00007fe79402f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.arm6.elf PID: 5481Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x14da9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14dbd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14dd1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14de5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14df9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e0d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e21:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e35:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e49:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e5d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e71:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e85:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14e99:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14ead:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14ec1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14ed5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14ee9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14efd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14f11:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14f25:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14f39:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.arm6.elfVirustotal: Detection: 37%Perma Link
Source: Space.arm6.elfReversingLabs: Detection: 41%
Source: global trafficTCP traffic: 192.168.2.14:51296 -> 209.97.147.158:3778
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: Space.arm6.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 37920 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37920

System Summary

barindex
Source: 5481.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5501.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5485.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5483.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5481, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5483, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5485, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5501, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x8000
Source: 5481.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5501.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5485.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5483.1.00007fe794017000.00007fe79402f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5481, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5483, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5485, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5501, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1583/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/2672/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1577/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3752/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3632/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1593/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3094/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3406/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1589/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3402/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/801/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/806/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/807/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/928/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3783/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/135/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1599/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/3412/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/35/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/1371/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/260/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/261/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/262/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5481)File opened: /proc/142/statusJump to behavior
Source: /usr/bin/dash (PID: 5562)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.GBuXLr4p9L /tmp/tmp.I4Svy2tUug /tmp/tmp.0PVSgapK0cJump to behavior
Source: /usr/bin/dash (PID: 5563)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.GBuXLr4p9L /tmp/tmp.I4Svy2tUug /tmp/tmp.0PVSgapK0cJump to behavior
Source: Space.arm6.elfSubmission file: segment LOAD with 7.9738 entropy (max. 8.0)
Source: /tmp/Space.arm6.elf (PID: 5481)Queries kernel information via 'uname': Jump to behavior
Source: Space.arm6.elf, 5481.1.000055cfdc11a000.000055cfdc308000.rw-.sdmp, Space.arm6.elf, 5483.1.000055cfdc11a000.000055cfdc308000.rw-.sdmp, Space.arm6.elf, 5485.1.000055cfdc11a000.000055cfdc308000.rw-.sdmp, Space.arm6.elf, 5501.1.000055cfdc11a000.000055cfdc308000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: Space.arm6.elf, 5481.1.000055cfdc11a000.000055cfdc308000.rw-.sdmp, Space.arm6.elf, 5483.1.000055cfdc11a000.000055cfdc308000.rw-.sdmp, Space.arm6.elf, 5485.1.000055cfdc11a000.000055cfdc308000.rw-.sdmp, Space.arm6.elf, 5501.1.000055cfdc11a000.000055cfdc308000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: Space.arm6.elf, 5481.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmp, Space.arm6.elf, 5483.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmp, Space.arm6.elf, 5485.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmp, Space.arm6.elf, 5501.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: Space.arm6.elf, 5481.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmp, Space.arm6.elf, 5483.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmp, Space.arm6.elf, 5485.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmp, Space.arm6.elf, 5501.1.00007ffc763cc000.00007ffc763ed000.rw-.sdmpBinary or memory string: l x86_64/usr/bin/qemu-arm/tmp/Space.arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.arm6.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1644272 Sample: Space.arm6.elf Startdate: 20/03/2025 Architecture: LINUX Score: 60 24 209.97.147.158, 3778 DIGITALOCEAN-ASNUS United States 2->24 26 54.171.230.55, 37920, 443 AMAZON-02US United States 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Sample is packed with UPX 2->32 8 Space.arm6.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 Space.arm6.elf 8->14         started        16 Space.arm6.elf 8->16         started        18 Space.arm6.elf 8->18         started        process6 20 Space.arm6.elf 14->20         started        22 Space.arm6.elf 14->22         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Space.arm6.elf38%VirustotalBrowse
Space.arm6.elf42%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.arm6.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.171.230.55
    unknownUnited States
    16509AMAZON-02USfalse
    209.97.147.158
    unknownUnited States
    14061DIGITALOCEAN-ASNUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.171.230.55smips.elfGet hashmaliciousUnknownBrowse
      psmips.elfGet hashmaliciousUnknownBrowse
        yakuza.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
          main_mpsl.elfGet hashmaliciousMiraiBrowse
            i.elfGet hashmaliciousMiraiBrowse
              arc.elfGet hashmaliciousMiraiBrowse
                aarch64.elfGet hashmaliciousMiraiBrowse
                  boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        209.97.147.158Space.mpsl.elfGet hashmaliciousUnknownBrowse
                          Space.i686.elfGet hashmaliciousUnknownBrowse
                            Space.x86_64.elfGet hashmaliciousUnknownBrowse
                              Space.sh4.elfGet hashmaliciousUnknownBrowse
                                Space.m68k.elfGet hashmaliciousMiraiBrowse
                                  Space.x86.elfGet hashmaliciousUnknownBrowse
                                    No context
                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                    AMAZON-02USSpace.m68k.elfGet hashmaliciousMiraiBrowse
                                    • 34.249.145.219
                                    https://mandrillapp.com/track/click/30319935/app.axure.cloud?p=eyJzIjoiVlZjanVlTVFEa1dCMEdNcWdqM3N2M1V2TXRzIiwidiI6MSwicCI6IntcInVcIjozMDMxOTkzNSxcInZcIjoxLFwidXJsXCI6XCJodHRwczpcXFwvXFxcL2FwcC5heHVyZS5jbG91ZFxcXC9ERFZPOUhcXFwvXCIsXCJpZFwiOlwiMWRmZjdjZjYyZmFhNGNiN2I5NWI1MjA4Y2FjM2I2MzJcIixcInVybF9pZHNcIjpbXCIzNjBjNGIwODczODAyZGVjZTE1NTNhYmM1MGQwZjViMGMyNTdjMzM2XCJdfSJ9Get hashmaliciousHTMLPhisherBrowse
                                    • 18.238.80.100
                                    Nyx4r.ppc.elfGet hashmaliciousOkiruBrowse
                                    • 18.190.189.22
                                    Nyx4r.arm.elfGet hashmaliciousOkiruBrowse
                                    • 65.1.108.4
                                    Space.arm5.elfGet hashmaliciousUnknownBrowse
                                    • 34.254.182.186
                                    Nyx4r.arm7.elfGet hashmaliciousMirai, OkiruBrowse
                                    • 13.235.242.244
                                    Nyx4r.m68k.elfGet hashmaliciousOkiruBrowse
                                    • 54.121.79.8
                                    Nyx4r.sh4.elfGet hashmaliciousOkiruBrowse
                                    • 18.248.212.201
                                    Nyx4r.spc.elfGet hashmaliciousOkiruBrowse
                                    • 18.217.152.126
                                    hoho.mips.elfGet hashmaliciousUnknownBrowse
                                    • 13.245.212.34
                                    DIGITALOCEAN-ASNUSSpace.mpsl.elfGet hashmaliciousUnknownBrowse
                                    • 209.97.147.158
                                    Space.i686.elfGet hashmaliciousUnknownBrowse
                                    • 209.97.147.158
                                    Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                    • 209.97.147.158
                                    Space.sh4.elfGet hashmaliciousUnknownBrowse
                                    • 209.97.147.158
                                    Space.m68k.elfGet hashmaliciousMiraiBrowse
                                    • 209.97.147.158
                                    Space.x86.elfGet hashmaliciousUnknownBrowse
                                    • 209.97.147.158
                                    https://bjpgckrr.ciaxalimited.com/T/?ur=lpOIUYFTDCVBKNLMJIHUGyfbnpohiguyftcgvhBNLKPOIHUGYFCGvhbjknkpojhiugyfvhjbKNLM;KPJOHIGUFYCGOYFTGUHIJDOKFLMEKNJBHYG478U9I3OKFJKNGHGRYUH3OKPEFI09U8Y7GVHBJFNKLG4KPI0U9Y87GYFGUHI4GJONK4YBJEVGUHIOJNK4BJEVUGHIJOY8T7F6DTXCGHVJBKNOJGet hashmaliciousUnknownBrowse
                                    • 165.22.210.101
                                    http://fliqlo.appGet hashmaliciousUnknownBrowse
                                    • 161.35.127.181
                                    task1.exeGet hashmaliciousEmotetBrowse
                                    • 134.209.36.254
                                    task1.exeGet hashmaliciousEmotetBrowse
                                    • 134.209.36.254
                                    No context
                                    No context
                                    No created / dropped files found
                                    File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, no section header
                                    Entropy (8bit):7.972167146709983
                                    TrID:
                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                    File name:Space.arm6.elf
                                    File size:44'600 bytes
                                    MD5:ddf4f9c9b60d35817ac87dc6fbbf7967
                                    SHA1:5b12170410fb389dddbd70b0a4afaff4db03425c
                                    SHA256:d6ec0ab27eca71ef8f9afa1589738fe98ec71bf5b29f5e1b2701e6c9a2ff8669
                                    SHA512:d380d170cf62d98bc7b7b3dbfb65967017f561eb7c355eaaa15d07d25bbe7e1becf8a6d1c94ee4e1384e5b43faea64abf363e06b4f6e2aeece6bdc0ec24134b0
                                    SSDEEP:768:oBZOKj8x/QSQ3y/4qFTOdeoJWBhdYnjWcBWDW4s5GyZDa6XXic6+9q3UELm:gXwQSYPqFHI8rOjBn4+9DXB6jLm
                                    TLSH:F013F181CA06BFD3D9926E37FFE499CB47188AE9C2362613762946BC4C93640D5D8583
                                    File Content Preview:.ELF..............(.........4...........4. ...(.........................................H...H...H...................Q.td...............................OUPX!...................._..........?.E.h;....#..$.......L..T.|..r.F..ZS..n.8.I+.e......rQN..D....I.:#/.

                                    ELF header

                                    Class:ELF32
                                    Data:2's complement, little endian
                                    Version:1 (current)
                                    Machine:ARM
                                    Version Number:0x1
                                    Type:EXEC (Executable file)
                                    OS/ABI:UNIX - Linux
                                    ABI Version:0
                                    Entry Point Address:0x11b00
                                    Flags:0x4000002
                                    ELF Header Size:52
                                    Program Header Offset:52
                                    Program Header Size:32
                                    Number of Program Headers:3
                                    Section Header Offset:0
                                    Section Header Size:40
                                    Number of Section Headers:0
                                    Header String Table Index:0
                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                    LOAD0x00x80000x80000xaced0xaced7.97380x5R E0x8000
                                    LOAD0xb480x20b480x20b480x00x00.00000x6RW 0x8000
                                    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                    Download Network PCAP: filteredfull

                                    • Total Packets: 101
                                    • 3778 undefined
                                    • 443 (HTTPS)
                                    TimestampSource PortDest PortSource IPDest IP
                                    Mar 20, 2025 13:59:40.957899094 CET512963778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:41.981507063 CET512963778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:43.997575045 CET512963778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:47.388989925 CET512983778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:48.125427961 CET512963778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:48.413341999 CET512983778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:50.429318905 CET512983778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:51.985534906 CET513003778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:52.989490032 CET513003778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:54.525183916 CET512983778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:55.005368948 CET513003778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:58.406035900 CET513023778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:59.133147001 CET513003778192.168.2.14209.97.147.158
                                    Mar 20, 2025 13:59:59.422198057 CET513023778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:01.437319994 CET513023778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:02.990535975 CET513043778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:03.839629889 CET37920443192.168.2.1454.171.230.55
                                    Mar 20, 2025 14:00:03.839679956 CET4433792054.171.230.55192.168.2.14
                                    Mar 20, 2025 14:00:03.839886904 CET37920443192.168.2.1454.171.230.55
                                    Mar 20, 2025 14:00:03.841777086 CET37920443192.168.2.1454.171.230.55
                                    Mar 20, 2025 14:00:03.841804028 CET4433792054.171.230.55192.168.2.14
                                    Mar 20, 2025 14:00:03.996970892 CET513043778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:05.533118963 CET513023778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:06.012993097 CET513043778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:09.419835091 CET513083778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:10.140976906 CET513043778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:10.428894043 CET513083778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:12.444885969 CET513083778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:14.003941059 CET513103778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:15.004802942 CET513103778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:16.540762901 CET513083778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:17.020697117 CET513103778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:20.433871031 CET513123778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:21.148691893 CET513103778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:21.436681986 CET513123778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:23.452646971 CET513123778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:25.017306089 CET513143778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:26.044492006 CET513143778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:27.548466921 CET513123778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:28.060436964 CET513143778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:31.447752953 CET513163778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:32.156382084 CET513143778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:32.476351976 CET513163778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:34.492289066 CET513163778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:36.032169104 CET513183778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:37.052340984 CET513183778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:38.556266069 CET513163778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:39.068253040 CET513183778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:42.460699081 CET513203778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:43.164093018 CET513183778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:43.484150887 CET513203778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:45.500030994 CET513203778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:47.045612097 CET513223778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:48.059964895 CET513223778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:49.563961029 CET513203778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:50.075921059 CET513223778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:53.474061966 CET513243778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:54.171806097 CET513223778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:54.491857052 CET513243778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:56.507869959 CET513243778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:58.066126108 CET513263778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:00:59.067768097 CET513263778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:00.571672916 CET513243778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:01.083684921 CET513263778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:03.838844061 CET37920443192.168.2.1454.171.230.55
                                    Mar 20, 2025 14:01:03.880331993 CET4433792054.171.230.55192.168.2.14
                                    Mar 20, 2025 14:01:04.487803936 CET513283778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:05.179569006 CET513263778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:05.499680996 CET513283778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:07.515580893 CET513283778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:09.080043077 CET513303778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:09.703294992 CET4433792054.171.230.55192.168.2.14
                                    Mar 20, 2025 14:01:09.703476906 CET4433792054.171.230.55192.168.2.14
                                    Mar 20, 2025 14:01:09.703653097 CET37920443192.168.2.1454.171.230.55
                                    Mar 20, 2025 14:01:09.703653097 CET37920443192.168.2.1454.171.230.55
                                    Mar 20, 2025 14:01:10.107503891 CET513303778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:11.579520941 CET513283778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:12.123425961 CET513303778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:15.501425982 CET513323778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:16.187371016 CET513303778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:16.507425070 CET513323778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:18.523438931 CET513323778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:20.090066910 CET513343778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:21.115307093 CET513343778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:22.587337971 CET513323778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:23.131303072 CET513343778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:26.514556885 CET513363778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:27.195131063 CET513343778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:27.515166998 CET513363778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:29.531282902 CET513363778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:31.103688002 CET513383778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:32.122953892 CET513383778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:33.594902992 CET513363778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:34.139010906 CET513383778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:37.527362108 CET513403778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:38.202882051 CET513383778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:38.554788113 CET513403778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:40.570775032 CET513403778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:42.110048056 CET513423778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:43.130703926 CET513423778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:44.602719069 CET513403778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:45.146696091 CET513423778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:48.543258905 CET513443778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:49.210728884 CET513423778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:49.562654972 CET513443778192.168.2.14209.97.147.158
                                    Mar 20, 2025 14:01:51.582456112 CET513443778192.168.2.14209.97.147.158

                                    System Behavior

                                    Start time (UTC):12:59:40
                                    Start date (UTC):20/03/2025
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:/tmp/Space.arm6.elf
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):12:59:40
                                    Start date (UTC):20/03/2025
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):12:59:40
                                    Start date (UTC):20/03/2025
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):12:59:40
                                    Start date (UTC):20/03/2025
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):12:59:46
                                    Start date (UTC):20/03/2025
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):12:59:46
                                    Start date (UTC):20/03/2025
                                    Path:/tmp/Space.arm6.elf
                                    Arguments:-
                                    File size:4956856 bytes
                                    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                    Start time (UTC):13:01:03
                                    Start date (UTC):20/03/2025
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):13:01:03
                                    Start date (UTC):20/03/2025
                                    Path:/usr/bin/rm
                                    Arguments:rm -f /tmp/tmp.GBuXLr4p9L /tmp/tmp.I4Svy2tUug /tmp/tmp.0PVSgapK0c
                                    File size:72056 bytes
                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                    Start time (UTC):13:01:03
                                    Start date (UTC):20/03/2025
                                    Path:/usr/bin/dash
                                    Arguments:-
                                    File size:129816 bytes
                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                    Start time (UTC):13:01:03
                                    Start date (UTC):20/03/2025
                                    Path:/usr/bin/rm
                                    Arguments:rm -f /tmp/tmp.GBuXLr4p9L /tmp/tmp.I4Svy2tUug /tmp/tmp.0PVSgapK0c
                                    File size:72056 bytes
                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b