Edit tour

Linux Analysis Report
Space.ppc.elf

Overview

General Information

Sample name:Space.ppc.elf
Analysis ID:1654325
MD5:7541675428a9227df2ccfd9fa7ab6adb
SHA1:d8b479427514125111c9234cbc27b39b8a10dfae
SHA256:cb0b24de774da3a65f2619a962c3a80f568610cf2ab2b75dd91dafd69715f0ee
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1654325
Start date and time:2025-04-02 09:42:34 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 2s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.ppc.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
Command:/tmp/Space.ppc.elf
PID:6275
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
6275.1.00007f78a0014000.00007f78a0017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6277.1.00007f78a0014000.00007f78a0017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6279.1.00007f78a0014000.00007f78a0017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6290.1.00007f78a0014000.00007f78a0017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.ppc.elf PID: 6275Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x1a95:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1aa9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1abd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1ad1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1ae5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1af9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b0d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b21:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b35:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b49:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b5d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b71:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b85:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b99:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1bad:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1bc1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1bd5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1be9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1bfd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1c11:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1c25:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.ppc.elfAvira: detected
Source: Space.ppc.elfVirustotal: Detection: 41%Perma Link
Source: Space.ppc.elfReversingLabs: Detection: 52%
Source: global trafficTCP traffic: 192.168.2.23:45212 -> 176.65.144.220:3778
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: Space.ppc.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6275.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6277.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6279.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6290.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 6275, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 6277, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 6279, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 6290, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6275.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6277.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6279.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6290.1.00007f78a0014000.00007f78a0017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 6275, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 6277, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 6279, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 6290, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/6230/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/6111/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/6110/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/6236/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1582/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/3088/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1579/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1699/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1335/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1698/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1334/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1576/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/2302/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/910/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/912/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/2307/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/918/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1594/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1349/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1344/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1465/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1586/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1463/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/801/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1900/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/491/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1599/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1477/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/379/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1476/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/4502/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/2208/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/4506/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 6275)File opened: /proc/6262/statusJump to behavior
Source: Space.ppc.elfSubmission file: segment LOAD with 7.9632 entropy (max. 8.0)
Source: /tmp/Space.ppc.elf (PID: 6275)Queries kernel information via 'uname': Jump to behavior
Source: Space.ppc.elf, 6275.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmp, Space.ppc.elf, 6277.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmp, Space.ppc.elf, 6279.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmp, Space.ppc.elf, 6290.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/Space.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.ppc.elf
Source: Space.ppc.elf, 6277.1.0000562527a37000.0000562527ae7000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: Space.ppc.elf, 6275.1.0000562527a37000.0000562527b08000.rw-.sdmp, Space.ppc.elf, 6279.1.0000562527a37000.0000562527ae7000.rw-.sdmp, Space.ppc.elf, 6290.1.0000562527a37000.0000562527b08000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: Space.ppc.elf, 6275.1.0000562527a37000.0000562527b08000.rw-.sdmp, Space.ppc.elf, 6277.1.0000562527a37000.0000562527ae7000.rw-.sdmp, Space.ppc.elf, 6279.1.0000562527a37000.0000562527ae7000.rw-.sdmp, Space.ppc.elf, 6290.1.0000562527a37000.0000562527b08000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: Space.ppc.elf, 6275.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmp, Space.ppc.elf, 6277.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmp, Space.ppc.elf, 6279.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmp, Space.ppc.elf, 6290.1.00007ffd33e61000.00007ffd33e82000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1654325 Sample: Space.ppc.elf Startdate: 02/04/2025 Architecture: LINUX Score: 68 20 176.65.144.220, 3778, 45212, 45214 PALTEL-ASPALTELAutonomousSystemPS Germany 2->20 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 2 other IPs or domains 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Sample is packed with UPX 2->32 8 Space.ppc.elf 2->8         started        signatures3 process4 process5 10 Space.ppc.elf 8->10         started        12 Space.ppc.elf 8->12         started        14 Space.ppc.elf 8->14         started        process6 16 Space.ppc.elf 10->16         started        18 Space.ppc.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.ppc.elf41%VirustotalBrowse
Space.ppc.elf53%ReversingLabsLinux.Trojan.Mirai
Space.ppc.elf100%AviraEXP/ELF.Agent.F.118
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.ppc.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    176.65.144.220
    unknownGermany
    12975PALTEL-ASPALTELAutonomousSystemPSfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    176.65.144.220Space.i686.elfGet hashmaliciousUnknownBrowse
      Space.mpsl.elfGet hashmaliciousUnknownBrowse
        Space.sh4.elfGet hashmaliciousUnknownBrowse
          Space.x86.elfGet hashmaliciousUnknownBrowse
            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
            91.189.91.43Space.arc.elfGet hashmaliciousMiraiBrowse
              mips.elfGet hashmaliciousUnknownBrowse
                FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                  FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                    FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            arm5.elfGet hashmaliciousUnknownBrowse
                              rjfe686.elfGet hashmaliciousUnknownBrowse
                                91.189.91.42Space.arc.elfGet hashmaliciousMiraiBrowse
                                  mips.elfGet hashmaliciousUnknownBrowse
                                    FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                      FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                        FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            na.elfGet hashmaliciousPrometeiBrowse
                                              na.elfGet hashmaliciousPrometeiBrowse
                                                arm5.elfGet hashmaliciousUnknownBrowse
                                                  rjfe686.elfGet hashmaliciousUnknownBrowse
                                                    No context
                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                    CANONICAL-ASGBSpace.mpsl.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    Space.arc.elfGet hashmaliciousMiraiBrowse
                                                    • 91.189.91.42
                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 91.189.91.42
                                                    FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 91.189.91.42
                                                    FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 91.189.91.42
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 91.189.91.42
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 91.189.91.42
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 91.189.91.42
                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    CANONICAL-ASGBSpace.mpsl.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    Space.arc.elfGet hashmaliciousMiraiBrowse
                                                    • 91.189.91.42
                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 91.189.91.42
                                                    FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 91.189.91.42
                                                    FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 91.189.91.42
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 91.189.91.42
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 91.189.91.42
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 91.189.91.42
                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    PALTEL-ASPALTELAutonomousSystemPSSpace.i686.elfGet hashmaliciousUnknownBrowse
                                                    • 176.65.144.220
                                                    Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                                    • 176.65.144.220
                                                    Space.sh4.elfGet hashmaliciousUnknownBrowse
                                                    • 176.65.144.220
                                                    Space.x86.elfGet hashmaliciousUnknownBrowse
                                                    • 176.65.144.220
                                                    FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 176.65.144.18
                                                    FBI.arm.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 176.65.144.18
                                                    FBI.sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 176.65.144.18
                                                    FBI.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 176.65.144.18
                                                    FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 176.65.144.18
                                                    FBI.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 176.65.144.18
                                                    INIT7CHSpace.arc.elfGet hashmaliciousMiraiBrowse
                                                    • 109.202.202.202
                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 109.202.202.202
                                                    FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 109.202.202.202
                                                    FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                    • 109.202.202.202
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 109.202.202.202
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 109.202.202.202
                                                    na.elfGet hashmaliciousPrometeiBrowse
                                                    • 109.202.202.202
                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    rjfe686.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    No context
                                                    No context
                                                    No created / dropped files found
                                                    File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, no section header
                                                    Entropy (8bit):7.961159127816327
                                                    TrID:
                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                    File name:Space.ppc.elf
                                                    File size:40'324 bytes
                                                    MD5:7541675428a9227df2ccfd9fa7ab6adb
                                                    SHA1:d8b479427514125111c9234cbc27b39b8a10dfae
                                                    SHA256:cb0b24de774da3a65f2619a962c3a80f568610cf2ab2b75dd91dafd69715f0ee
                                                    SHA512:15b7b9405cfdba22ffe12b93d682d3bde717f076e8afefc78bc43f65d5da27b753490f4ed06a5cd6669a7f26ac0ee23e45162453e323731a4068bc8b31cb3c4c
                                                    SSDEEP:768:y1qQ4JXTPxcCj3do/vTKRVDkO1HmQcvbG+TqarjEP8o8j4uVcqgw09O:4qQbCj3do/+fDrJ1cyUqOgkZ4u+qgw0U
                                                    TLSH:5203E15BCC496ED6E9FFD9115708CAE2F7E01B9D6BA24CAE1856CB07331F868630C950
                                                    File Content Preview:.ELF...........................4.........4. ...(.......................x...x..............k...k...k.................dt.Q................................UPX!..........b...b........V.......?.E.h4...@b........=.a....`..Y...j{.c.HL}.....H..z.q.H.....8ea......

                                                    ELF header

                                                    Class:ELF32
                                                    Data:2's complement, big endian
                                                    Version:1 (current)
                                                    Machine:PowerPC
                                                    Version Number:0x1
                                                    Type:EXEC (Executable file)
                                                    OS/ABI:UNIX - Linux
                                                    ABI Version:0
                                                    Entry Point Address:0x108a90
                                                    Flags:0x0
                                                    ELF Header Size:52
                                                    Program Header Offset:52
                                                    Program Header Size:32
                                                    Number of Program Headers:3
                                                    Section Header Offset:0
                                                    Section Header Size:40
                                                    Number of Section Headers:0
                                                    Header String Table Index:0
                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                    LOAD0x00x1000000x1000000x9c780x9c787.96320x5R E0x10000
                                                    LOAD0x6b900x10026b900x10026b900x00x00.00000x6RW 0x10000
                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                    Download Network PCAP: filteredfull

                                                    • Total Packets: 37
                                                    • 3778 undefined
                                                    • 443 (HTTPS)
                                                    • 80 (HTTP)
                                                    TimestampSource PortDest PortSource IPDest IP
                                                    Apr 2, 2025 09:43:31.832436085 CEST43928443192.168.2.2391.189.91.42
                                                    Apr 2, 2025 09:43:33.168286085 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:33.371875048 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:33.372203112 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:33.378586054 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:33.582840919 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:33.582973003 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:33.784181118 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:37.463747025 CEST42836443192.168.2.2391.189.91.43
                                                    Apr 2, 2025 09:43:38.231475115 CEST4251680192.168.2.23109.202.202.202
                                                    Apr 2, 2025 09:43:39.379911900 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:39.581125975 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:39.581212997 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:39.584990978 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:39.787565947 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:39.787677050 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:39.988461971 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:43.387577057 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:43.594017982 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:43.612663984 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:43.613007069 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:49.594275951 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:49.796171904 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:49.805068016 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:49.805274963 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:43:51.797708035 CEST43928443192.168.2.2391.189.91.42
                                                    Apr 2, 2025 09:43:58.924634933 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:43:58.924751997 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:04.084155083 CEST42836443192.168.2.2391.189.91.43
                                                    Apr 2, 2025 09:44:05.066262960 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:05.066404104 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:08.179537058 CEST4251680192.168.2.23109.202.202.202
                                                    Apr 2, 2025 09:44:14.131481886 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:14.131593943 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:20.270679951 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:20.271187067 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:29.388139009 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:29.388293028 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:32.752361059 CEST43928443192.168.2.2391.189.91.42
                                                    Apr 2, 2025 09:44:35.477798939 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:35.478065014 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:43.656873941 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:43.861571074 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:43.861771107 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:49.854434013 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:50.060245991 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:50.060446978 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:44:59.098506927 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:44:59.098946095 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:45:05.483352900 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:45:05.483625889 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:45:14.302829027 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:45:14.302959919 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:45:20.689532042 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:45:20.689723015 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:45:29.551652908 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:45:29.552031040 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:45:35.894624949 CEST377845214176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:45:35.894802094 CEST452143778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:45:43.904958010 CEST452123778192.168.2.23176.65.144.220
                                                    Apr 2, 2025 09:45:44.146564007 CEST377845212176.65.144.220192.168.2.23
                                                    Apr 2, 2025 09:45:44.146718979 CEST452123778192.168.2.23176.65.144.220

                                                    System Behavior

                                                    Start time (UTC):07:43:32
                                                    Start date (UTC):02/04/2025
                                                    Path:/tmp/Space.ppc.elf
                                                    Arguments:/tmp/Space.ppc.elf
                                                    File size:5388968 bytes
                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                    Start time (UTC):07:43:32
                                                    Start date (UTC):02/04/2025
                                                    Path:/tmp/Space.ppc.elf
                                                    Arguments:-
                                                    File size:5388968 bytes
                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                    Start time (UTC):07:43:32
                                                    Start date (UTC):02/04/2025
                                                    Path:/tmp/Space.ppc.elf
                                                    Arguments:-
                                                    File size:5388968 bytes
                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                    Start time (UTC):07:43:32
                                                    Start date (UTC):02/04/2025
                                                    Path:/tmp/Space.ppc.elf
                                                    Arguments:-
                                                    File size:5388968 bytes
                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                    Start time (UTC):07:43:38
                                                    Start date (UTC):02/04/2025
                                                    Path:/tmp/Space.ppc.elf
                                                    Arguments:-
                                                    File size:5388968 bytes
                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                    Start time (UTC):07:43:38
                                                    Start date (UTC):02/04/2025
                                                    Path:/tmp/Space.ppc.elf
                                                    Arguments:-
                                                    File size:5388968 bytes
                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6