Edit tour

Linux Analysis Report
Space.mips.elf

Overview

General Information

Sample name:Space.mips.elf
Analysis ID:1654342
MD5:711758d4b9683429525db5e81a3943e7
SHA1:20458ede2a85f6f128cc3a5fe8635c1280047d33
SHA256:3e13e95c12498af56d4ece9ecf4086195d421ba60ddd854966bbef7829d6b56b
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1654342
Start date and time:2025-04-02 09:57:40 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 58s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mips.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.mips.elf
PID:6253
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6318, Parent: 4333)
  • rm (PID: 6318, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.RuqRjxGi8S /tmp/tmp.1gEJubyySz /tmp/tmp.2W4YOJCFxz
  • dash New Fork (PID: 6319, Parent: 4333)
  • rm (PID: 6319, Parent: 4333, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.RuqRjxGi8S /tmp/tmp.1gEJubyySz /tmp/tmp.2W4YOJCFxz
  • cleanup
SourceRuleDescriptionAuthorStrings
6253.1.00007f4528400000.00007f452842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6257.1.00007f4528400000.00007f452842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6255.1.00007f4528400000.00007f452842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6267.1.00007f4528400000.00007f452842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.mips.elf PID: 6253Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xa17:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa2b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa3f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa53:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa67:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa7b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa8f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xacb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xadf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb07:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb1b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb2f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb43:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb57:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb7f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xba7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.mips.elfVirustotal: Detection: 51%Perma Link
Source: Space.mips.elfReversingLabs: Detection: 52%
Source: global trafficTCP traffic: 192.168.2.23:45210 -> 176.65.144.220:3778
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: Space.mips.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39250
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 39250 -> 443

System Summary

barindex
Source: 6253.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6257.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6255.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6267.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6253, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6255, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6257, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6253.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6257.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6255.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6267.1.00007f4528400000.00007f452842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6253, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6255, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6257, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6267, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/6234/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1582/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/3088/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1579/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1699/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1335/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1698/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1334/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1576/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/2302/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/910/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/912/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/2307/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/918/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1594/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1349/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1344/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1465/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1586/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1463/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/801/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/6237/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1900/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/6253/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/6258/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/491/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/4508/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1599/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1477/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/379/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1476/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/4503/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/2208/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6253)File opened: /proc/35/statusJump to behavior
Source: /usr/bin/dash (PID: 6318)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.RuqRjxGi8S /tmp/tmp.1gEJubyySz /tmp/tmp.2W4YOJCFxzJump to behavior
Source: /usr/bin/dash (PID: 6319)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.RuqRjxGi8S /tmp/tmp.1gEJubyySz /tmp/tmp.2W4YOJCFxzJump to behavior
Source: Space.mips.elfSubmission file: segment LOAD with 7.9482 entropy (max. 8.0)
Source: /tmp/Space.mips.elf (PID: 6253)Queries kernel information via 'uname': Jump to behavior
Source: Space.mips.elf, 6253.1.000055a8c20ca000.000055a8c2172000.rw-.sdmp, Space.mips.elf, 6255.1.000055a8c20ca000.000055a8c2172000.rw-.sdmp, Space.mips.elf, 6257.1.000055a8c20ca000.000055a8c2172000.rw-.sdmp, Space.mips.elf, 6267.1.000055a8c20ca000.000055a8c2172000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: Space.mips.elf, 6253.1.000055a8c20ca000.000055a8c2172000.rw-.sdmp, Space.mips.elf, 6255.1.000055a8c20ca000.000055a8c2172000.rw-.sdmp, Space.mips.elf, 6257.1.000055a8c20ca000.000055a8c2172000.rw-.sdmp, Space.mips.elf, 6267.1.000055a8c20ca000.000055a8c2172000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: Space.mips.elf, 6253.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmp, Space.mips.elf, 6255.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmp, Space.mips.elf, 6257.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmp, Space.mips.elf, 6267.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: Space.mips.elf, 6253.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmp, Space.mips.elf, 6255.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmp, Space.mips.elf, 6257.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmp, Space.mips.elf, 6267.1.00007fffdc5b3000.00007fffdc5d4000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/Space.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mips.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1654342 Sample: Space.mips.elf Startdate: 02/04/2025 Architecture: LINUX Score: 60 24 176.65.144.220, 3778, 45210, 45212 PALTEL-ASPALTELAutonomousSystemPS Germany 2->24 26 109.202.202.202, 80 INIT7CH Switzerland 2->26 28 3 other IPs or domains 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Sample is packed with UPX 2->34 8 Space.mips.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 Space.mips.elf 8->14         started        16 Space.mips.elf 8->16         started        18 Space.mips.elf 8->18         started        process6 20 Space.mips.elf 14->20         started        22 Space.mips.elf 14->22         started       
SourceDetectionScannerLabelLink
Space.mips.elf52%VirustotalBrowse
Space.mips.elf53%ReversingLabsLinux.Trojan.Multiverze
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.mips.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    34.249.145.219
    unknownUnited States
    16509AMAZON-02USfalse
    176.65.144.220
    unknownGermany
    12975PALTEL-ASPALTELAutonomousSystemPSfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    34.249.145.219Space.spc.elfGet hashmaliciousMiraiBrowse
      Space.arc.elfGet hashmaliciousMiraiBrowse
        mips.elfGet hashmaliciousUnknownBrowse
          FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
            FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  efefa7.elfGet hashmaliciousMiraiBrowse
                    sh4.elfGet hashmaliciousUnknownBrowse
                      arm5.elfGet hashmaliciousUnknownBrowse
                        176.65.144.220Space.arm.elfGet hashmaliciousMiraiBrowse
                          Space.m68k.elfGet hashmaliciousMiraiBrowse
                            Space.arm7.elfGet hashmaliciousMiraiBrowse
                              Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                Space.ppc.elfGet hashmaliciousUnknownBrowse
                                  Space.i686.elfGet hashmaliciousUnknownBrowse
                                    Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                      Space.sh4.elfGet hashmaliciousUnknownBrowse
                                        Space.x86.elfGet hashmaliciousUnknownBrowse
                                          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                          91.189.91.43rrrdsl.elfGet hashmaliciousUnknownBrowse
                                            Space.spc.elfGet hashmaliciousMiraiBrowse
                                              Space.ppc.elfGet hashmaliciousUnknownBrowse
                                                Space.arc.elfGet hashmaliciousMiraiBrowse
                                                  mips.elfGet hashmaliciousUnknownBrowse
                                                    FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                      FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGBrrrdsl.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Space.spc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              Space.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              Space.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 91.189.91.42
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 91.189.91.42
                                                              PALTEL-ASPALTELAutonomousSystemPSSpace.arm.elfGet hashmaliciousMiraiBrowse
                                                              • 176.65.144.220
                                                              Space.m68k.elfGet hashmaliciousMiraiBrowse
                                                              • 176.65.144.220
                                                              Space.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 176.65.144.220
                                                              Space.x86_64.elfGet hashmaliciousUnknownBrowse
                                                              • 176.65.144.220
                                                              Space.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 176.65.144.220
                                                              Space.i686.elfGet hashmaliciousUnknownBrowse
                                                              • 176.65.144.220
                                                              Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 176.65.144.220
                                                              Space.sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 176.65.144.220
                                                              Space.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 176.65.144.220
                                                              FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 176.65.144.18
                                                              INIT7CHrrrdsl.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Space.spc.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              Space.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Space.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                              • 109.202.202.202
                                                              AMAZON-02USrrrdsl.elfGet hashmaliciousUnknownBrowse
                                                              • 54.171.230.55
                                                              Space.spc.elfGet hashmaliciousMiraiBrowse
                                                              • 34.249.145.219
                                                              Space.arc.elfGet hashmaliciousMiraiBrowse
                                                              • 34.249.145.219
                                                              5AzgNwCtN5.exeGet hashmaliciousCryptOne, LummaC StealerBrowse
                                                              • 108.139.47.92
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                              • 34.249.145.219
                                                              7H9CCIVPzr.exeGet hashmaliciousUnknownBrowse
                                                              • 108.139.47.92
                                                              http://cdn.systweak.com/downloads/setups/dpfw/dpfsetup_afterupdate_1004.exeGet hashmaliciousPureLog Stealer, zgRATBrowse
                                                              • 108.138.113.91
                                                              Order 501 & 502.exeGet hashmaliciousFormBookBrowse
                                                              • 13.248.169.48
                                                              FBI.x86.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 34.249.145.219
                                                              FBI.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              • 34.249.145.219
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
                                                              Entropy (8bit):7.945977472305082
                                                              TrID:
                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                              File name:Space.mips.elf
                                                              File size:44'196 bytes
                                                              MD5:711758d4b9683429525db5e81a3943e7
                                                              SHA1:20458ede2a85f6f128cc3a5fe8635c1280047d33
                                                              SHA256:3e13e95c12498af56d4ece9ecf4086195d421ba60ddd854966bbef7829d6b56b
                                                              SHA512:666efc5ac326d48e9e5b9675b09636939bb90138ecfca127cf5c20e4582376883b2bda15adc05a29bda910f6c65e9fe90b9e08ecb7f5ca328d526e2a1a7bb3b8
                                                              SSDEEP:768:vDfzzMwdu3W4CbuznqQd8eYkGyJfH6QhjS0jlDGnHMhgNSRxUkCkHhVeg527Oiw/:vDEwdu3ubuznqreGyJfH6QhjDGnHMhg+
                                                              TLSH:B013E198370345B9C79AC4F09BF443623F752FF95186CC09A8A5EBA1BDD0088BCE56C4
                                                              File Content Preview:.ELF.......................0...4.........4. ...(.......................t...t.................C...C......................UPX!.h.....................V.......?.E.h4...@b..) ..]....E..`..........@4#.Y..~.9....b...Q".|.H.%Q.z....6u.."....cLw...................

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, big endian
                                                              Version:1 (current)
                                                              Machine:MIPS R3000
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x109830
                                                              Flags:0x1007
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:2
                                                              Section Header Offset:0
                                                              Section Header Size:40
                                                              Number of Section Headers:0
                                                              Header String Table Index:0
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x1000000x1000000xab740xab747.94820x5R E0x10000
                                                              LOAD0xcffc0x43cffc0x43cffc0x00x00.00000x6RW 0x10000

                                                              Download Network PCAP: filteredfull

                                                              • Total Packets: 41
                                                              • 3778 undefined
                                                              • 443 (HTTPS)
                                                              • 80 (HTTP)
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Apr 2, 2025 09:58:31.330573082 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 2, 2025 09:58:32.222908974 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:32.423743010 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:32.423815966 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:32.440212965 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:32.644431114 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:32.644516945 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:32.845971107 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:36.961865902 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 2, 2025 09:58:37.928092957 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:37.985577106 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 2, 2025 09:58:38.130408049 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:38.130501986 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:38.131926060 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:38.334724903 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:38.334846973 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:38.536906004 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:42.449148893 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:42.654103994 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:42.702115059 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:42.702239037 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:47.829994917 CEST39250443192.168.2.2334.249.145.219
                                                              Apr 2, 2025 09:58:47.830053091 CEST4433925034.249.145.219192.168.2.23
                                                              Apr 2, 2025 09:58:47.830144882 CEST39250443192.168.2.2334.249.145.219
                                                              Apr 2, 2025 09:58:47.830729008 CEST39250443192.168.2.2334.249.145.219
                                                              Apr 2, 2025 09:58:47.830744028 CEST4433925034.249.145.219192.168.2.23
                                                              Apr 2, 2025 09:58:48.134288073 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:48.342679977 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:48.363476038 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:48.363667011 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:58:52.832132101 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 2, 2025 09:58:57.998135090 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:58:57.998296022 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:03.070465088 CEST42836443192.168.2.2391.189.91.43
                                                              Apr 2, 2025 09:59:03.630075932 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:03.630314112 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:09.213356018 CEST4251680192.168.2.23109.202.202.202
                                                              Apr 2, 2025 09:59:13.203634024 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:13.203841925 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:18.839689970 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:18.839845896 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:28.408718109 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:28.408875942 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:33.787456989 CEST43928443192.168.2.2391.189.91.42
                                                              Apr 2, 2025 09:59:34.097091913 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:34.097460985 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:42.750695944 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:42.951261997 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:42.998249054 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:42.998528004 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:47.822213888 CEST39250443192.168.2.2334.249.145.219
                                                              Apr 2, 2025 09:59:47.868267059 CEST4433925034.249.145.219192.168.2.23
                                                              Apr 2, 2025 09:59:48.396006107 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:48.618590117 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:48.618707895 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 09:59:58.415280104 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 09:59:58.415463924 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 10:00:04.047683954 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 10:00:04.047894955 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 10:00:13.620843887 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 10:00:13.620951891 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 10:00:19.253964901 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 10:00:19.254234076 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 10:00:28.828223944 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 10:00:28.828418016 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 10:00:34.509880066 CEST377845212176.65.144.220192.168.2.23
                                                              Apr 2, 2025 10:00:34.510072947 CEST452123778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 10:00:42.313905954 CEST4433925034.249.145.219192.168.2.23
                                                              Apr 2, 2025 10:00:43.041132927 CEST452103778192.168.2.23176.65.144.220
                                                              Apr 2, 2025 10:00:43.242171049 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 10:00:43.282882929 CEST377845210176.65.144.220192.168.2.23
                                                              Apr 2, 2025 10:00:43.283015013 CEST452103778192.168.2.23176.65.144.220

                                                              System Behavior

                                                              Start time (UTC):07:58:30
                                                              Start date (UTC):02/04/2025
                                                              Path:/tmp/Space.mips.elf
                                                              Arguments:/tmp/Space.mips.elf
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):07:58:30
                                                              Start date (UTC):02/04/2025
                                                              Path:/tmp/Space.mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):07:58:30
                                                              Start date (UTC):02/04/2025
                                                              Path:/tmp/Space.mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):07:58:30
                                                              Start date (UTC):02/04/2025
                                                              Path:/tmp/Space.mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):07:58:36
                                                              Start date (UTC):02/04/2025
                                                              Path:/tmp/Space.mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):07:58:36
                                                              Start date (UTC):02/04/2025
                                                              Path:/tmp/Space.mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):07:59:46
                                                              Start date (UTC):02/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):07:59:46
                                                              Start date (UTC):02/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.RuqRjxGi8S /tmp/tmp.1gEJubyySz /tmp/tmp.2W4YOJCFxz
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                              Start time (UTC):07:59:46
                                                              Start date (UTC):02/04/2025
                                                              Path:/usr/bin/dash
                                                              Arguments:-
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):07:59:46
                                                              Start date (UTC):02/04/2025
                                                              Path:/usr/bin/rm
                                                              Arguments:rm -f /tmp/tmp.RuqRjxGi8S /tmp/tmp.1gEJubyySz /tmp/tmp.2W4YOJCFxz
                                                              File size:72056 bytes
                                                              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b