Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.mips.elf

Overview

General Information

Sample name:Space.mips.elf
Analysis ID:1665359
MD5:2499cd03d508e4a3a4bdb4ac5b50459c
SHA1:0690c9bed1bb4f6d747eb168ae3b0fda4fd050cd
SHA256:bc71fbfbd8415a8d978ac8d4057121bc1fa82d1ccd184371e59c0f9c79de34ba
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1665359
Start date and time:2025-04-15 14:02:14 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mips.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.mips.elf
PID:5491
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5505.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5493.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5491.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5495.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.mips.elf PID: 5491Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xf60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x103c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x108c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.mips.elfVirustotal: Detection: 46%Perma Link
Source: Space.mips.elfReversingLabs: Detection: 44%
Source: global trafficTCP traffic: 192.168.2.14:42020 -> 107.173.143.15:3778
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: Space.mips.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5505.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5493.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5491.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5495.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5491, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5493, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5495, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 5505, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 5505.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5493.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5491.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5495.1.00007ff3e8400000.00007ff3e842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5491, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5493, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5495, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 5505, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1583/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/2672/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1577/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3770/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1593/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3094/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3406/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1589/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3402/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/801/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3767/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/806/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3768/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/807/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/928/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3769/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/135/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1599/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/3412/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/35/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/1371/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/260/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/261/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 5491)File opened: /proc/262/statusJump to behavior
Source: Space.mips.elfSubmission file: segment LOAD with 7.9461 entropy (max. 8.0)
Source: /tmp/Space.mips.elf (PID: 5491)Queries kernel information via 'uname': Jump to behavior
Source: Space.mips.elf, 5491.1.000056279441e000.00005627944c6000.rw-.sdmp, Space.mips.elf, 5493.1.000056279441e000.00005627944c6000.rw-.sdmp, Space.mips.elf, 5495.1.000056279441e000.00005627944c6000.rw-.sdmp, Space.mips.elf, 5505.1.000056279441e000.00005627944c6000.rw-.sdmpBinary or memory string: 'V!/etc/qemu-binfmt/mips
Source: Space.mips.elf, 5491.1.000056279441e000.00005627944c6000.rw-.sdmp, Space.mips.elf, 5493.1.000056279441e000.00005627944c6000.rw-.sdmp, Space.mips.elf, 5495.1.000056279441e000.00005627944c6000.rw-.sdmp, Space.mips.elf, 5505.1.000056279441e000.00005627944c6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: Space.mips.elf, 5491.1.00007ffd48437000.00007ffd48458000.rw-.sdmp, Space.mips.elf, 5493.1.00007ffd48437000.00007ffd48458000.rw-.sdmp, Space.mips.elf, 5495.1.00007ffd48437000.00007ffd48458000.rw-.sdmp, Space.mips.elf, 5505.1.00007ffd48437000.00007ffd48458000.rw-.sdmpBinary or memory string: 0x86_64/usr/bin/qemu-mips/tmp/Space.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mips.elf
Source: Space.mips.elf, 5491.1.00007ffd48437000.00007ffd48458000.rw-.sdmp, Space.mips.elf, 5493.1.00007ffd48437000.00007ffd48458000.rw-.sdmp, Space.mips.elf, 5495.1.00007ffd48437000.00007ffd48458000.rw-.sdmp, Space.mips.elf, 5505.1.00007ffd48437000.00007ffd48458000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1665359 Sample: Space.mips.elf Startdate: 15/04/2025 Architecture: LINUX Score: 60 20 107.173.143.15, 3778, 42020, 42022 AS-COLOCROSSINGUS United States 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 Space.mips.elf 2->8         started        signatures3 process4 process5 10 Space.mips.elf 8->10         started        12 Space.mips.elf 8->12         started        14 Space.mips.elf 8->14         started        process6 16 Space.mips.elf 10->16         started        18 Space.mips.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.mips.elf46%VirustotalBrowse
Space.mips.elf44%ReversingLabsLinux.Trojan.Multiverze
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.mips.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    107.173.143.15
    unknownUnited States
    36352AS-COLOCROSSINGUSfalse
    No context
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    AS-COLOCROSSINGUSORDER-25013-67789543AX.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
    • 104.168.7.12
    ORDER-2504014-0054739AP.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
    • 172.245.208.13
    15042025Payment .xlsGet hashmaliciousUnknownBrowse
    • 172.245.208.21
    15042025Payment .xlsGet hashmaliciousUnknownBrowse
    • 172.245.208.21
    ORDER#250944.XLS.vbsGet hashmaliciousCaesium Obfuscator, STRRATBrowse
    • 172.245.208.13
    15042025Payment .xlsGet hashmaliciousUnknownBrowse
    • 172.245.208.21
    003.exeGet hashmaliciousUnknownBrowse
    • 104.168.28.10
    003.exeGet hashmaliciousUnknownBrowse
    • 104.168.28.10
    sdf.htaGet hashmaliciousCobalt StrikeBrowse
    • 172.245.191.88
    GFL-001-2034-PO-BK - REV.docx.docGet hashmaliciousUnknownBrowse
    • 192.3.140.103
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
    Entropy (8bit):7.943938077705882
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:Space.mips.elf
    File size:44'140 bytes
    MD5:2499cd03d508e4a3a4bdb4ac5b50459c
    SHA1:0690c9bed1bb4f6d747eb168ae3b0fda4fd050cd
    SHA256:bc71fbfbd8415a8d978ac8d4057121bc1fa82d1ccd184371e59c0f9c79de34ba
    SHA512:620b764aab382734bffe97d7de38d89b6c1b8641818237bbcb3cecb690747911a986e4bd221d5c844fafbf18e9a852e18aee2feb532b1ee5282efe2a96da1bb8
    SSDEEP:768:G7ph1LjFGpx652lJXasyEk6JGbr6MWiNIx8FJ8/0JgGlzDpbuR1JXA:GzA65yk6JGbrbNwQJ0sVJuu
    TLSH:9213E15E850088EEE8818D7147E45B616F710BB0F463E943E50DF887EA696FD3E235A8
    File Content Preview:.ELF...........................4.........4. ...(.......................<...<.................C...C......................UPX!.d.....................V.......?.E.h4...@b..) ..]....E..`..........@4#.Y..~.9....b...Q".|.H.%Q.z....6u.."....cLw.........`.........

    ELF header

    Class:ELF32
    Data:2's complement, big endian
    Version:1 (current)
    Machine:MIPS R3000
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x1097f8
    Flags:0x1007
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:2
    Section Header Offset:0
    Section Header Size:40
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x1000000x1000000xab3c0xab3c7.94610x5R E0x10000
    LOAD0xcffc0x43cffc0x43cffc0x00x00.00000x6RW 0x10000
    TimestampSource PortDest PortSource IPDest IP
    Apr 15, 2025 14:02:54.046727896 CEST420203778192.168.2.14107.173.143.15
    Apr 15, 2025 14:02:54.180536985 CEST377842020107.173.143.15192.168.2.14
    Apr 15, 2025 14:02:55.196428061 CEST420223778192.168.2.14107.173.143.15
    Apr 15, 2025 14:02:55.330122948 CEST377842022107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:00.332828999 CEST420243778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:00.353935957 CEST420263778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:00.467902899 CEST377842024107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:00.487389088 CEST377842026107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:01.502811909 CEST420283778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:01.636612892 CEST377842028107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:05.484146118 CEST420303778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:05.618191957 CEST377842030107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:06.639322996 CEST420323778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:06.773735046 CEST377842032107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:09.620698929 CEST420343778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:09.756036043 CEST377842034107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:11.758923054 CEST420363778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:11.775778055 CEST420383778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:11.893126965 CEST377842036107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:11.909324884 CEST377842038107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:15.912311077 CEST420403778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:16.046473026 CEST377842040107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:18.049061060 CEST420423778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:18.182702065 CEST377842042107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:19.895143032 CEST420443778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:20.028927088 CEST377842044107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:23.031580925 CEST420463778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:23.165885925 CEST377842046107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:26.185062885 CEST420483778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:26.319571972 CEST377842048107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:29.322103977 CEST420503778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:29.457051039 CEST377842050107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:32.168575048 CEST420523778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:32.303462029 CEST377842052107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:37.305696011 CEST420543778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:37.439392090 CEST377842054107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:38.459305048 CEST420563778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:38.593909979 CEST377842056107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:43.441678047 CEST420583778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:43.576142073 CEST377842058107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:43.596473932 CEST420603778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:43.730163097 CEST377842060107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:45.578532934 CEST420623778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:45.713408947 CEST377842062107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:49.733208895 CEST420643778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:49.866940975 CEST377842064107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:51.870320082 CEST420663778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:52.004658937 CEST377842066107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:55.715883017 CEST420683778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:55.849898100 CEST377842068107.173.143.15192.168.2.14
    Apr 15, 2025 14:03:57.852698088 CEST420703778192.168.2.14107.173.143.15
    Apr 15, 2025 14:03:57.986658096 CEST377842070107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:00.989583015 CEST420723778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:01.123972893 CEST377842072107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:02.008162975 CEST420743778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:02.141731024 CEST377842074107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:04.144553900 CEST420763778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:04.278605938 CEST377842076107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:07.281522989 CEST420783778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:07.415832996 CEST377842078107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:10.126806974 CEST420803778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:10.260730028 CEST377842080107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:13.263138056 CEST420823778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:13.396840096 CEST377842082107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:14.399266958 CEST420843778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:14.533915997 CEST377842084107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:16.418726921 CEST420863778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:16.552604914 CEST377842086107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:19.555053949 CEST420883778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:19.689357042 CEST377842088107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:20.691541910 CEST420903778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:20.825171947 CEST377842090107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:24.536211967 CEST420923778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:24.670137882 CEST377842092107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:29.672338963 CEST420943778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:29.806755066 CEST377842094107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:30.828262091 CEST420963778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:30.961944103 CEST377842096107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:33.808541059 CEST420983778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:33.942095995 CEST377842098107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:35.964490891 CEST421003778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:36.102832079 CEST377842100107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:39.944667101 CEST421023778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:40.078341007 CEST377842102107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:40.104870081 CEST421043778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:40.239197969 CEST377842104107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:46.241527081 CEST421063778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:46.375519037 CEST377842106107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:49.080734015 CEST421083778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:49.214821100 CEST377842108107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:53.216685057 CEST421103778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:53.350476027 CEST377842110107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:55.379198074 CEST421123778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:55.512931108 CEST377842112107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:57.352657080 CEST421143778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:57.486162901 CEST377842114107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:58.488401890 CEST421163778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:58.622001886 CEST377842116107.173.143.15192.168.2.14
    Apr 15, 2025 14:04:59.515598059 CEST421183778192.168.2.14107.173.143.15
    Apr 15, 2025 14:04:59.649439096 CEST377842118107.173.143.15192.168.2.14
    Apr 15, 2025 14:05:03.651910067 CEST421203778192.168.2.14107.173.143.15
    Apr 15, 2025 14:05:03.785693884 CEST377842120107.173.143.15192.168.2.14
    Apr 15, 2025 14:05:04.789129019 CEST421223778192.168.2.14107.173.143.15
    Apr 15, 2025 14:05:04.922924995 CEST377842122107.173.143.15192.168.2.14

    System Behavior

    Start time (UTC):12:02:52
    Start date (UTC):15/04/2025
    Path:/tmp/Space.mips.elf
    Arguments:/tmp/Space.mips.elf
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:02:52
    Start date (UTC):15/04/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:02:52
    Start date (UTC):15/04/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:02:52
    Start date (UTC):15/04/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:02:59
    Start date (UTC):15/04/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):12:02:59
    Start date (UTC):15/04/2025
    Path:/tmp/Space.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c