Edit tour

Linux Analysis Report
Space.mips.elf

Overview

General Information

Sample name:Space.mips.elf
Analysis ID:1644276
MD5:6c34a07570e23ff6fd450f13b69903b9
SHA1:acd0bd2149eb0cd69af27486fd98276fdfa29b52
SHA256:f812dedfc949a9c4695ea828855ca311448e61a005f9bf952b6b5d4d9ee5b56d
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1644276
Start date and time:2025-03-20 14:01:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mips.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.mips.elf
PID:5473
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5488.1.00007f4534400000.00007f453442c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5478.1.00007f4534400000.00007f453442c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5473.1.00007f4534400000.00007f453442c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5476.1.00007f4534400000.00007f453442c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.mips.elf PID: 5473Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x474b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x475f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4773:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4787:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x479b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4813:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4827:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x483b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x484f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4863:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4877:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x488b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x489f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x48b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x48c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x48db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.mips.elfVirustotal: Detection: 37%Perma Link
Source: Space.mips.elfReversingLabs: Detection: 38%
Source: global trafficTCP traffic: 192.168.2.13:45902 -> 209.97.147.158:3778
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: unknownTCP traffic detected without corresponding DNS query: 209.97.147.158
Source: Space.mips.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443

System Summary

barindex
Source: 5488.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5478.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5473.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5476.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5473, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5476, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5478, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5488, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 5488.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5478.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5473.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5476.1.00007f4534400000.00007f453442c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5473, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5476, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5478, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5488, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/238/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/239/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/3636/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/3095/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/241/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/1906/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/1482/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/1480/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/371/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/1238/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/134/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/3413/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/816/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5473)File opened: /proc/35/statusJump to behavior
Source: Space.mips.elfSubmission file: segment LOAD with 7.9481 entropy (max. 8.0)
Source: /tmp/Space.mips.elf (PID: 5473)Queries kernel information via 'uname': Jump to behavior
Source: Space.mips.elf, 5473.1.000056487bdb9000.000056487be61000.rw-.sdmp, Space.mips.elf, 5476.1.000056487bdb9000.000056487be61000.rw-.sdmp, Space.mips.elf, 5478.1.000056487bdb9000.000056487be61000.rw-.sdmp, Space.mips.elf, 5488.1.000056487bdb9000.000056487be61000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: Space.mips.elf, 5473.1.00007fffabaa3000.00007fffabac4000.rw-.sdmp, Space.mips.elf, 5476.1.00007fffabaa3000.00007fffabac4000.rw-.sdmp, Space.mips.elf, 5478.1.00007fffabaa3000.00007fffabac4000.rw-.sdmp, Space.mips.elf, 5488.1.00007fffabaa3000.00007fffabac4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: Space.mips.elf, 5473.1.000056487bdb9000.000056487be61000.rw-.sdmp, Space.mips.elf, 5476.1.000056487bdb9000.000056487be61000.rw-.sdmp, Space.mips.elf, 5478.1.000056487bdb9000.000056487be61000.rw-.sdmp, Space.mips.elf, 5488.1.000056487bdb9000.000056487be61000.rw-.sdmpBinary or memory string: {HV!/etc/qemu-binfmt/mips
Source: Space.mips.elf, 5473.1.00007fffabaa3000.00007fffabac4000.rw-.sdmp, Space.mips.elf, 5476.1.00007fffabaa3000.00007fffabac4000.rw-.sdmp, Space.mips.elf, 5478.1.00007fffabaa3000.00007fffabac4000.rw-.sdmp, Space.mips.elf, 5488.1.00007fffabaa3000.00007fffabac4000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/Space.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mips.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1644276 Sample: Space.mips.elf Startdate: 20/03/2025 Architecture: LINUX Score: 60 20 209.97.147.158, 3778 DIGITALOCEAN-ASNUS United States 2->20 22 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->22 24 Malicious sample detected (through community Yara rule) 2->24 26 Multi AV Scanner detection for submitted file 2->26 28 Sample is packed with UPX 2->28 8 Space.mips.elf 2->8         started        signatures3 process4 process5 10 Space.mips.elf 8->10         started        12 Space.mips.elf 8->12         started        14 Space.mips.elf 8->14         started        process6 16 Space.mips.elf 10->16         started        18 Space.mips.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.mips.elf38%VirustotalBrowse
Space.mips.elf39%ReversingLabsLinux.Trojan.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.mips.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    185.125.190.26
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    209.97.147.158
    unknownUnited States
    14061DIGITALOCEAN-ASNUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    185.125.190.26Space.x86_64.elfGet hashmaliciousUnknownBrowse
      sshd.elfGet hashmaliciousUnknownBrowse
        .5r3fqt67ew531has4231.sh4.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
          yakuza.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
            .5r3fqt67ew531has4231.arm5.elfGet hashmaliciousUnknownBrowse
              main_arm6.elfGet hashmaliciousMiraiBrowse
                main_mips.elfGet hashmaliciousMiraiBrowse
                  bot.arm6.elfGet hashmaliciousUnknownBrowse
                    hiss.arm7.elfGet hashmaliciousUnknownBrowse
                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                        209.97.147.158Space.ppc.elfGet hashmaliciousUnknownBrowse
                          Space.arm7.elfGet hashmaliciousMiraiBrowse
                            Space.arm6.elfGet hashmaliciousUnknownBrowse
                              Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                Space.i686.elfGet hashmaliciousUnknownBrowse
                                  Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                    Space.sh4.elfGet hashmaliciousUnknownBrowse
                                      Space.m68k.elfGet hashmaliciousMiraiBrowse
                                        Space.x86.elfGet hashmaliciousUnknownBrowse
                                          No context
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          CANONICAL-ASGBSpace.ppc.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          686i.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                          • 185.125.190.26
                                          sshd.elfGet hashmaliciousUnknownBrowse
                                          • 185.125.190.26
                                          Space.sh4.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          Space.m68k.elfGet hashmaliciousMiraiBrowse
                                          • 91.189.91.42
                                          mips.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          smips.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          psmpsl.elfGet hashmaliciousUnknownBrowse
                                          • 91.189.91.42
                                          .5r3fqt67ew531has4231.sh4.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
                                          • 185.125.190.26
                                          DIGITALOCEAN-ASNUSSpace.ppc.elfGet hashmaliciousUnknownBrowse
                                          • 209.97.147.158
                                          Space.arm7.elfGet hashmaliciousMiraiBrowse
                                          • 209.97.147.158
                                          Space.arm6.elfGet hashmaliciousUnknownBrowse
                                          • 209.97.147.158
                                          Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                          • 209.97.147.158
                                          Space.i686.elfGet hashmaliciousUnknownBrowse
                                          • 209.97.147.158
                                          Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                          • 209.97.147.158
                                          Space.sh4.elfGet hashmaliciousUnknownBrowse
                                          • 209.97.147.158
                                          Space.m68k.elfGet hashmaliciousMiraiBrowse
                                          • 209.97.147.158
                                          Space.x86.elfGet hashmaliciousUnknownBrowse
                                          • 209.97.147.158
                                          https://bjpgckrr.ciaxalimited.com/T/?ur=lpOIUYFTDCVBKNLMJIHUGyfbnpohiguyftcgvhBNLKPOIHUGYFCGvhbjknkpojhiugyfvhjbKNLM;KPJOHIGUFYCGOYFTGUHIJDOKFLMEKNJBHYG478U9I3OKFJKNGHGRYUH3OKPEFI09U8Y7GVHBJFNKLG4KPI0U9Y87GYFGUHI4GJONK4YBJEVGUHIOJNK4BJEVUGHIJOY8T7F6DTXCGHVJBKNOJGet hashmaliciousUnknownBrowse
                                          • 165.22.210.101
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
                                          Entropy (8bit):7.945906317188764
                                          TrID:
                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                          File name:Space.mips.elf
                                          File size:44'196 bytes
                                          MD5:6c34a07570e23ff6fd450f13b69903b9
                                          SHA1:acd0bd2149eb0cd69af27486fd98276fdfa29b52
                                          SHA256:f812dedfc949a9c4695ea828855ca311448e61a005f9bf952b6b5d4d9ee5b56d
                                          SHA512:a37f9a984351738eebfac5148e28f60f2f22fd3033111da3e13f3c52fc01e9fd092b0629e1b19b5d3f1e68bb82ee5b88ac794992b49ad2628f6d962b4be7d855
                                          SSDEEP:768:NDfzzMwdu3W4CbuznqQd8eYkGyJfH6QhjS0jlDGnHMhgNSRxUkCkHhVeg527yKs/:NDEwdu3ubuznqreGyJfH6QhjDGnHMhg4
                                          TLSH:2B13F198370201EACB5AD4F19BF403637B752FF961868C196CA9DBA1A9E104DFCD0AC4
                                          File Content Preview:.ELF.......................0...4.........4. ...(.......................t...t.................C...C......................UPX!.h.....................V.......?.E.h4...@b..) ..]....E..`..........@4#.Y..~.9....b...Q".|.H.%Q.z....6u.."....cLw...................

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, big endian
                                          Version:1 (current)
                                          Machine:MIPS R3000
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x109830
                                          Flags:0x1007
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:2
                                          Section Header Offset:0
                                          Section Header Size:40
                                          Number of Section Headers:0
                                          Header String Table Index:0
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x1000000x1000000xab740xab747.94810x5R E0x10000
                                          LOAD0xcffc0x43cffc0x43cffc0x00x00.00000x6RW 0x10000

                                          Download Network PCAP: filteredfull

                                          • Total Packets: 97
                                          • 3778 undefined
                                          • 443 (HTTPS)
                                          TimestampSource PortDest PortSource IPDest IP
                                          Mar 20, 2025 14:02:05.854866028 CET459023778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:06.868125916 CET459023778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:08.884152889 CET459023778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:11.551440954 CET459043778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:12.564155102 CET459043778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:12.980249882 CET459023778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:14.516206026 CET48202443192.168.2.13185.125.190.26
                                          Mar 20, 2025 14:02:14.580147028 CET459043778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:16.915772915 CET459063778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:17.940295935 CET459063778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:18.612143040 CET459043778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:19.956162930 CET459063778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:22.587630987 CET459083778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:23.604171038 CET459083778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:23.988282919 CET459063778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:25.620328903 CET459083778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:27.929133892 CET459103778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:28.948333025 CET459103778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:29.876173019 CET459083778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:30.964174032 CET459103778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:33.601821899 CET459123778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:34.612284899 CET459123778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:34.996248960 CET459103778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:36.628226995 CET459123778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:38.941515923 CET459143778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:39.956366062 CET459143778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:40.884267092 CET459123778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:41.972304106 CET459143778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:44.615971088 CET459163778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:44.980211020 CET48202443192.168.2.13185.125.190.26
                                          Mar 20, 2025 14:02:45.620268106 CET459163778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:46.004215002 CET459143778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:47.636359930 CET459163778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:49.954747915 CET459183778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:50.964195013 CET459183778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:51.892363071 CET459163778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:52.980165005 CET459183778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:55.631294966 CET459203778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:56.660186052 CET459203778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:57.012319088 CET459183778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:02:58.676269054 CET459203778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:00.967992067 CET459223778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:01.972207069 CET459223778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:02.900279999 CET459203778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:03.988296032 CET459223778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:06.637125015 CET459243778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:07.668261051 CET459243778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:08.020299911 CET459223778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:09.684286118 CET459243778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:11.978370905 CET459263778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:12.980207920 CET459263778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:13.908231974 CET459243778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:14.996202946 CET459263778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:17.650345087 CET459283778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:18.676198006 CET459283778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:19.028239012 CET459263778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:20.692194939 CET459283778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:22.990992069 CET459303778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:24.020167112 CET459303778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:24.916311026 CET459283778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:26.036204100 CET459303778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:28.663222075 CET459323778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:29.684226036 CET459323778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:30.292251110 CET459303778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:31.700345039 CET459323778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:34.003870010 CET459343778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:35.028278112 CET459343778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:35.924434900 CET459323778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:37.044267893 CET459343778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:39.675256014 CET459363778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:40.692394018 CET459363778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:41.300234079 CET459343778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:42.708410025 CET459363778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:45.017070055 CET459383778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:46.036261082 CET459383778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:46.932296991 CET459363778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:48.052329063 CET459383778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:50.690706968 CET459403778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:51.700314999 CET459403778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:52.308312893 CET459383778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:53.716332912 CET459403778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:56.030431986 CET459423778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:57.044320107 CET459423778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:57.940296888 CET459403778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:03:59.060290098 CET459423778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:01.698422909 CET459443778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:02.708257914 CET459443778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:03.316246033 CET459423778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:04.724287033 CET459443778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:07.044338942 CET459463778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:08.052341938 CET459463778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:08.948507071 CET459443778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:10.068185091 CET459463778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:12.711841106 CET459483778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:13.716334105 CET459483778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:14.324316025 CET459463778192.168.2.13209.97.147.158
                                          Mar 20, 2025 14:04:15.732335091 CET459483778192.168.2.13209.97.147.158

                                          System Behavior

                                          Start time (UTC):13:02:04
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/Space.mips.elf
                                          Arguments:/tmp/Space.mips.elf
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):13:02:04
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/Space.mips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):13:02:04
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/Space.mips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):13:02:04
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/Space.mips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):13:02:10
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/Space.mips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                          Start time (UTC):13:02:10
                                          Start date (UTC):20/03/2025
                                          Path:/tmp/Space.mips.elf
                                          Arguments:-
                                          File size:5777432 bytes
                                          MD5 hash:0083f1f0e77be34ad27f849842bbb00c