Edit tour

Linux Analysis Report
Space.arm6.elf

Overview

General Information

Sample name:Space.arm6.elf
Analysis ID:1654344
MD5:324f171653c05b039696aa79ba3b5070
SHA1:4c3d338760172fd94e1c517f57d594d535803d28
SHA256:8e53e592b27ecb0b0cb22ebcb04c0181e32ae8ca58caa0838e4120e32a9835b5
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1654344
Start date and time:2025-04-02 09:57:44 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.arm6.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.arm6.elf
PID:5426
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5428.1.00007fa76c017000.00007fa76c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5436.1.00007fa76c017000.00007fa76c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5430.1.00007fa76c017000.00007fa76c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5426.1.00007fa76c017000.00007fa76c02f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x15320:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15334:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15348:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1535c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15370:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15384:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15398:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x153fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15410:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15424:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15438:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1544c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15460:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15474:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15488:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1549c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x154b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.arm6.elf PID: 5426Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x1710e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17122:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17136:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1714a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1715e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17172:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17186:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1719a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x171ae:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x171c2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x171d6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x171ea:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x171fe:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17212:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17226:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1723a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1724e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17262:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17276:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1728a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1729e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.arm6.elfVirustotal: Detection: 40%Perma Link
Source: Space.arm6.elfReversingLabs: Detection: 52%
Source: global trafficTCP traffic: 192.168.2.13:43922 -> 176.65.144.220:3778
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: unknownTCP traffic detected without corresponding DNS query: 176.65.144.220
Source: Space.arm6.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5428.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5436.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5430.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5426.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5426, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.arm6.elf PID: 5436, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x8000
Source: 5428.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5436.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5430.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5426.1.00007fa76c017000.00007fa76c02f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5426, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.arm6.elf PID: 5436, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/3760/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/5267/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/238/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/239/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/3095/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/241/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/1906/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/3644/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/1482/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/1480/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/371/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/1238/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/134/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/3413/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.arm6.elf (PID: 5426)File opened: /proc/30/statusJump to behavior
Source: Space.arm6.elfSubmission file: segment LOAD with 7.9742 entropy (max. 8.0)
Source: /tmp/Space.arm6.elf (PID: 5426)Queries kernel information via 'uname': Jump to behavior
Source: Space.arm6.elf, 5426.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmp, Space.arm6.elf, 5428.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmp, Space.arm6.elf, 5430.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmp, Space.arm6.elf, 5436.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/Space.arm6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.arm6.elf
Source: Space.arm6.elf, 5426.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmp, Space.arm6.elf, 5428.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmp, Space.arm6.elf, 5430.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmp, Space.arm6.elf, 5436.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: Space.arm6.elf, 5426.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmp, Space.arm6.elf, 5428.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmp, Space.arm6.elf, 5430.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmp, Space.arm6.elf, 5436.1.00007fff1ece5000.00007fff1ed06000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: Space.arm6.elf, 5426.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmp, Space.arm6.elf, 5428.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmp, Space.arm6.elf, 5430.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmp, Space.arm6.elf, 5436.1.0000560e5ed87000.0000560e5ef75000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1654344 Sample: Space.arm6.elf Startdate: 02/04/2025 Architecture: LINUX Score: 60 20 176.65.144.220, 3778, 43922, 43924 PALTEL-ASPALTELAutonomousSystemPS Germany 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 Space.arm6.elf 2->8         started        signatures3 process4 process5 10 Space.arm6.elf 8->10         started        12 Space.arm6.elf 8->12         started        14 Space.arm6.elf 8->14         started        process6 16 Space.arm6.elf 10->16         started        18 Space.arm6.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.arm6.elf41%VirustotalBrowse
Space.arm6.elf53%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.arm6.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    176.65.144.220
    unknownGermany
    12975PALTEL-ASPALTELAutonomousSystemPSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    176.65.144.220Space.arm.elfGet hashmaliciousMiraiBrowse
      Space.m68k.elfGet hashmaliciousMiraiBrowse
        Space.arm7.elfGet hashmaliciousMiraiBrowse
          Space.x86_64.elfGet hashmaliciousUnknownBrowse
            Space.ppc.elfGet hashmaliciousUnknownBrowse
              Space.i686.elfGet hashmaliciousUnknownBrowse
                Space.mpsl.elfGet hashmaliciousUnknownBrowse
                  Space.sh4.elfGet hashmaliciousUnknownBrowse
                    Space.x86.elfGet hashmaliciousUnknownBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      PALTEL-ASPALTELAutonomousSystemPSSpace.arm.elfGet hashmaliciousMiraiBrowse
                      • 176.65.144.220
                      Space.m68k.elfGet hashmaliciousMiraiBrowse
                      • 176.65.144.220
                      Space.arm7.elfGet hashmaliciousMiraiBrowse
                      • 176.65.144.220
                      Space.x86_64.elfGet hashmaliciousUnknownBrowse
                      • 176.65.144.220
                      Space.ppc.elfGet hashmaliciousUnknownBrowse
                      • 176.65.144.220
                      Space.i686.elfGet hashmaliciousUnknownBrowse
                      • 176.65.144.220
                      Space.mpsl.elfGet hashmaliciousUnknownBrowse
                      • 176.65.144.220
                      Space.sh4.elfGet hashmaliciousUnknownBrowse
                      • 176.65.144.220
                      Space.x86.elfGet hashmaliciousUnknownBrowse
                      • 176.65.144.220
                      FBI.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                      • 176.65.144.18
                      No context
                      No context
                      No created / dropped files found
                      File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, no section header
                      Entropy (8bit):7.9725537929464
                      TrID:
                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                      File name:Space.arm6.elf
                      File size:44'600 bytes
                      MD5:324f171653c05b039696aa79ba3b5070
                      SHA1:4c3d338760172fd94e1c517f57d594d535803d28
                      SHA256:8e53e592b27ecb0b0cb22ebcb04c0181e32ae8ca58caa0838e4120e32a9835b5
                      SHA512:baf0a289992bb4caa339ae4b49ed2af9c5c40eabe5a79454a836c5b0f9989c27b97489d841f11e41ece92f748cf8f3bb571a3721491aa7342ed75acb1fa36ef3
                      SSDEEP:768:EnZOKj8x/QSQ3y/4qFTOdeoJWBhdYnjWcBWDW4s5GyZDa6XXcWWL9q3UELk:yXwQSYPqFHI8rOjBn4+9DXceLk
                      TLSH:4F13F191CE06BED2C9517D33FEE888DF431C8AE5C27A22137A3846B8989364099D4593
                      File Content Preview:.ELF..............(.........4...........4. ...(.........................................H...H...H...................Q.td...............................OUPX!...................._..........?.E.h;....#..$.......L..T.|..r.F..ZS..n.8.I+.e......rQN..D....I.:#/.

                      ELF header

                      Class:ELF32
                      Data:2's complement, little endian
                      Version:1 (current)
                      Machine:ARM
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:UNIX - Linux
                      ABI Version:0
                      Entry Point Address:0x11b00
                      Flags:0x4000002
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:3
                      Section Header Offset:0
                      Section Header Size:40
                      Number of Section Headers:0
                      Header String Table Index:0
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00x80000x80000xaced0xaced7.97420x5R E0x8000
                      LOAD0xb480x20b480x20b480x00x00.00000x6RW 0x8000
                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                      Download Network PCAP: filteredfull

                      TimestampSource PortDest PortSource IPDest IP
                      Apr 2, 2025 09:58:29.307848930 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:29.513147116 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:29.513231993 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:29.514810085 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:29.716119051 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:29.716187000 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:29.917081118 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:34.975903034 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:35.178023100 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:35.178097010 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:35.180160046 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:35.384429932 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:35.384555101 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:35.586808920 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:39.525109053 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:39.727582932 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:39.782080889 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:39.782179117 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:45.190458059 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:45.393276930 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:45.438246012 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:45.438442945 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:58:55.182832956 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:58:55.183020115 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:00.816246986 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:00.816396952 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:10.385217905 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:10.385364056 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:16.022840977 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:16.023071051 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:25.593137026 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:25.593343973 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:31.280241966 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:31.280431032 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:39.834876060 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:40.036521912 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:40.055527925 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:40.055649996 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:45.499345064 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:45.703583002 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:45.739464998 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:45.739609957 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 09:59:55.346504927 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 09:59:55.347305059 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 10:00:00.973731995 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 10:00:00.973927021 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 10:00:10.548957109 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 10:00:10.549110889 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 10:00:16.195478916 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 10:00:16.195697069 CEST439243778192.168.2.13176.65.144.220
                      Apr 2, 2025 10:00:25.807041883 CEST377843922176.65.144.220192.168.2.13
                      Apr 2, 2025 10:00:25.807358980 CEST439223778192.168.2.13176.65.144.220
                      Apr 2, 2025 10:00:31.397248983 CEST377843924176.65.144.220192.168.2.13
                      Apr 2, 2025 10:00:31.397511005 CEST439243778192.168.2.13176.65.144.220

                      System Behavior

                      Start time (UTC):07:58:27
                      Start date (UTC):02/04/2025
                      Path:/tmp/Space.arm6.elf
                      Arguments:/tmp/Space.arm6.elf
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):07:58:28
                      Start date (UTC):02/04/2025
                      Path:/tmp/Space.arm6.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):07:58:28
                      Start date (UTC):02/04/2025
                      Path:/tmp/Space.arm6.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):07:58:28
                      Start date (UTC):02/04/2025
                      Path:/tmp/Space.arm6.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):07:58:33
                      Start date (UTC):02/04/2025
                      Path:/tmp/Space.arm6.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                      Start time (UTC):07:58:33
                      Start date (UTC):02/04/2025
                      Path:/tmp/Space.arm6.elf
                      Arguments:-
                      File size:4956856 bytes
                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1