Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.sh4.elf

Overview

General Information

Sample name:Space.sh4.elf
Analysis ID:1665362
MD5:cb55e328ee6b26f6b113d205ce70fa7f
SHA1:d5f171512255c0b062c62077db5c75003955f555
SHA256:757632d4dde13e0756e50c8b0d7d9f9f1496761d8cdfaa95f1301246a6e65047
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1665362
Start date and time:2025-04-15 14:06:11 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 41s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.sh4.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
Command:/tmp/Space.sh4.elf
PID:5428
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5484, Parent: 3581)
  • rm (PID: 5484, Parent: 3581, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.iwsNA1ZzO0 /tmp/tmp.ovYZBiW3ah /tmp/tmp.3NmsdW7Bfp
  • dash New Fork (PID: 5485, Parent: 3581)
  • cat (PID: 5485, Parent: 3581, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.iwsNA1ZzO0
  • dash New Fork (PID: 5486, Parent: 3581)
  • head (PID: 5486, Parent: 3581, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5487, Parent: 3581)
  • tr (PID: 5487, Parent: 3581, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5488, Parent: 3581)
  • cut (PID: 5488, Parent: 3581, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5489, Parent: 3581)
  • cat (PID: 5489, Parent: 3581, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.iwsNA1ZzO0
  • dash New Fork (PID: 5490, Parent: 3581)
  • head (PID: 5490, Parent: 3581, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 5491, Parent: 3581)
  • tr (PID: 5491, Parent: 3581, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 5492, Parent: 3581)
  • cut (PID: 5492, Parent: 3581, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 5493, Parent: 3581)
  • rm (PID: 5493, Parent: 3581, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.iwsNA1ZzO0 /tmp/tmp.ovYZBiW3ah /tmp/tmp.3NmsdW7Bfp
  • cleanup
SourceRuleDescriptionAuthorStrings
Space.sh4.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1106c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1110c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1115c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5430.1.00007fef2c400000.00007fef2c414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1106c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1110c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1115c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5428.1.00007fef2c400000.00007fef2c414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1106c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1110c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1115c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5432.1.00007fef2c400000.00007fef2c414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1106c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1110c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1115c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5442.1.00007fef2c400000.00007fef2c414000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x11058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1106c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1110c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1115c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.sh4.elf PID: 5428Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x21ca:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21de:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21f2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2206:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x221a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x222e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2242:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2256:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x226a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x227e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2292:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x22a6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x22ba:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x22ce:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x22e2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x22f6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x230a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x231e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2332:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2346:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x235a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.sh4.elfAvira: detected
Source: Space.sh4.elfVirustotal: Detection: 61%Perma Link
Source: Space.sh4.elfReversingLabs: Detection: 63%
Source: global trafficTCP traffic: 192.168.2.13:37340 -> 107.173.143.15:3778
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 34.243.160.129
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: wget/1.20.3-1ubuntu1 Ubuntu/20.04.2/LTS GNU/Linux/5.4.0-72-generic/x86_64 Intel(R)/Xeon(R)/Silver/4210/CPU/@/2.20GHz cloud_id/noneAccept: */*Accept-Encoding: identityHost: motd.ubuntu.comConnection: Keep-Alive
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50562
Source: unknownNetwork traffic detected: HTTP traffic on port 37674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50562 -> 443

System Summary

barindex
Source: Space.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5430.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5428.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5432.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5442.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.sh4.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.sh4.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.sh4.elf PID: 5432, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.sh4.elf PID: 5442, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Initial sampleString containing 'busybox' found: /bin/busybox
Source: Initial sampleString containing 'busybox' found: /proc/net/tcp.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc/proc/proc/%d/exe/proc/%s/statusrName:%s/bin/busybox/bin/systemd/usr/bintest/tmp/condi/tmp/zxcr9999/tmp/condinetwork/var/condibot/var/zxcr9999/var/CondiBot/var/condinet/bin/watchdog107.173.143.15
Source: ELF static info symbol of initial sample.symtab present: no
Source: Space.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5430.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5428.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5432.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5442.1.00007fef2c400000.00007fef2c414000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.sh4.elf PID: 5428, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.sh4.elf PID: 5430, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.sh4.elf PID: 5432, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.sh4.elf PID: 5442, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/5266/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/238/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/239/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/3633/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/3095/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/241/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/1906/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/3782/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/1482/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/1480/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/371/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/1238/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/134/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/3413/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)File opened: /proc/30/statusJump to behavior
Source: /usr/bin/dash (PID: 5484)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.iwsNA1ZzO0 /tmp/tmp.ovYZBiW3ah /tmp/tmp.3NmsdW7BfpJump to behavior
Source: /usr/bin/dash (PID: 5493)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.iwsNA1ZzO0 /tmp/tmp.ovYZBiW3ah /tmp/tmp.3NmsdW7BfpJump to behavior
Source: /tmp/Space.sh4.elf (PID: 5428)Queries kernel information via 'uname': Jump to behavior
Source: Space.sh4.elf, 5428.1.0000556ce4e6e000.0000556ce4ef8000.rw-.sdmp, Space.sh4.elf, 5430.1.0000556ce4e6e000.0000556ce4ed1000.rw-.sdmp, Space.sh4.elf, 5432.1.0000556ce4e6e000.0000556ce4ed1000.rw-.sdmp, Space.sh4.elf, 5442.1.0000556ce4e6e000.0000556ce4ef8000.rw-.sdmpBinary or memory string: lU5!/etc/qemu-binfmt/sh4
Source: Space.sh4.elf, 5428.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmp, Space.sh4.elf, 5430.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmp, Space.sh4.elf, 5432.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmp, Space.sh4.elf, 5442.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: Space.sh4.elf, 5428.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmp, Space.sh4.elf, 5430.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmp, Space.sh4.elf, 5432.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmp, Space.sh4.elf, 5442.1.00007ffef97c2000.00007ffef97e3000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/Space.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.sh4.elf
Source: Space.sh4.elf, 5428.1.0000556ce4e6e000.0000556ce4ef8000.rw-.sdmp, Space.sh4.elf, 5430.1.0000556ce4e6e000.0000556ce4ed1000.rw-.sdmp, Space.sh4.elf, 5432.1.0000556ce4e6e000.0000556ce4ed1000.rw-.sdmp, Space.sh4.elf, 5442.1.0000556ce4e6e000.0000556ce4ef8000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsInternet Connection DiscoverySSHKeylogging1
Ingress Tool Transfer
Scheduled TransferData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1665362 Sample: Space.sh4.elf Startdate: 15/04/2025 Architecture: LINUX Score: 64 26 107.173.143.15, 37340, 37342, 37344 AS-COLOCROSSINGUS United States 2->26 28 34.243.160.129, 443, 50562 AMAZON-02US United States 2->28 30 54.217.10.153, 443 AMAZON-02US United States 2->30 32 Malicious sample detected (through community Yara rule) 2->32 34 Antivirus / Scanner detection for submitted sample 2->34 36 Multi AV Scanner detection for submitted file 2->36 8 Space.sh4.elf 2->8         started        10 dash rm 2->10         started        12 dash head 2->12         started        14 8 other processes 2->14 signatures3 process4 process5 16 Space.sh4.elf 8->16         started        18 Space.sh4.elf 8->18         started        20 Space.sh4.elf 8->20         started        process6 22 Space.sh4.elf 16->22         started        24 Space.sh4.elf 16->24         started       
SourceDetectionScannerLabelLink
Space.sh4.elf62%VirustotalBrowse
Space.sh4.elf64%ReversingLabsLinux.Backdoor.Mirai
Space.sh4.elf100%AviraLINUX/Mirai.bonb
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameMaliciousAntivirus DetectionReputation
https://motd.ubuntu.com/false
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.217.10.153
    unknownUnited States
    16509AMAZON-02USfalse
    34.243.160.129
    unknownUnited States
    16509AMAZON-02USfalse
    107.173.143.15
    unknownUnited States
    36352AS-COLOCROSSINGUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.217.10.153m68k.elfGet hashmaliciousMiraiBrowse
      .i.elfGet hashmaliciousUnknownBrowse
        boatnet.mips.elfGet hashmaliciousMiraiBrowse
          hidakibest.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
            hidakibest.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
              hidakibest.arm7.elfGet hashmaliciousGafgyt, MiraiBrowse
                arm.elfGet hashmaliciousMiraiBrowse
                  2xvhK6n0L5YrHJ4.x86_64.elfGet hashmaliciousMiraiBrowse
                    Pitbull.arm.elfGet hashmaliciousMiraiBrowse
                      t7h65hoHB2.elfGet hashmaliciousUnknownBrowse
                        34.243.160.129Space.m68k.elfGet hashmaliciousMiraiBrowse
                          sh4.elfGet hashmaliciousAquabotBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                resgod.arc.elfGet hashmaliciousMiraiBrowse
                                  i.elfGet hashmaliciousUnknownBrowse
                                    ntpd.elfGet hashmaliciousMuhstik, TsunamiBrowse
                                      GoldAge3ATOspc.elfGet hashmaliciousUnknownBrowse
                                        zerarm.elfGet hashmaliciousUnknownBrowse
                                          main_ppc.elfGet hashmaliciousMiraiBrowse
                                            107.173.143.15Space.m68k.elfGet hashmaliciousMiraiBrowse
                                              Space.mips.elfGet hashmaliciousUnknownBrowse
                                                No context
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                AMAZON-02USSpace.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 54.247.62.1
                                                done1.ps1Get hashmaliciousFormBookBrowse
                                                • 143.204.29.58
                                                https://files.stample.com/browserUpload/59722db0-d3c0-43c0-b975-c51a1290a89dGet hashmaliciousHTMLPhisherBrowse
                                                • 3.163.115.83
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                https://we.tl/t-IBThwlthXD?trk=dw_recover_expired_transfer&utm_campaign=dw_recover_expired_transfer&utm_medium=email&utm_source=wt_sendgrid&utm_template=pre_deletion_72hrs_emailGet hashmaliciousUnknownBrowse
                                                • 3.248.132.116
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                m68k.elfGet hashmaliciousMiraiBrowse
                                                • 54.217.10.153
                                                .i.elfGet hashmaliciousUnknownBrowse
                                                • 54.217.10.153
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                AS-COLOCROSSINGUSSpace.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 107.173.143.15
                                                Space.mips.elfGet hashmaliciousUnknownBrowse
                                                • 107.173.143.15
                                                ORDER-25013-67789543AX.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                                                • 104.168.7.12
                                                ORDER-2504014-0054739AP.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                                                • 172.245.208.13
                                                15042025Payment .xlsGet hashmaliciousUnknownBrowse
                                                • 172.245.208.21
                                                15042025Payment .xlsGet hashmaliciousUnknownBrowse
                                                • 172.245.208.21
                                                ORDER#250944.XLS.vbsGet hashmaliciousCaesium Obfuscator, STRRATBrowse
                                                • 172.245.208.13
                                                15042025Payment .xlsGet hashmaliciousUnknownBrowse
                                                • 172.245.208.21
                                                003.exeGet hashmaliciousUnknownBrowse
                                                • 104.168.28.10
                                                003.exeGet hashmaliciousUnknownBrowse
                                                • 104.168.28.10
                                                AMAZON-02USSpace.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 54.247.62.1
                                                done1.ps1Get hashmaliciousFormBookBrowse
                                                • 143.204.29.58
                                                https://files.stample.com/browserUpload/59722db0-d3c0-43c0-b975-c51a1290a89dGet hashmaliciousHTMLPhisherBrowse
                                                • 3.163.115.83
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                https://we.tl/t-IBThwlthXD?trk=dw_recover_expired_transfer&utm_campaign=dw_recover_expired_transfer&utm_medium=email&utm_source=wt_sendgrid&utm_template=pre_deletion_72hrs_emailGet hashmaliciousUnknownBrowse
                                                • 3.248.132.116
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                m68k.elfGet hashmaliciousMiraiBrowse
                                                • 54.217.10.153
                                                .i.elfGet hashmaliciousUnknownBrowse
                                                • 54.217.10.153
                                                na.elfGet hashmaliciousPrometeiBrowse
                                                • 52.11.240.239
                                                No context
                                                No context
                                                No created / dropped files found
                                                File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                                Entropy (8bit):6.60374281651136
                                                TrID:
                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                File name:Space.sh4.elf
                                                File size:82'652 bytes
                                                MD5:cb55e328ee6b26f6b113d205ce70fa7f
                                                SHA1:d5f171512255c0b062c62077db5c75003955f555
                                                SHA256:757632d4dde13e0756e50c8b0d7d9f9f1496761d8cdfaa95f1301246a6e65047
                                                SHA512:6da46bb16df3f4c2a92f753644a6454faa325d83721e6155e01ca5280d91b07abd8e6d86450cd04a249d87041fc7cf1a213ec1fb6f1253f8243035854d474e8e
                                                SSDEEP:1536:/RU/uDZhX+yTzUIDrnYVohwH5wX6SNmTdEyRHr:q/+PX+yTzUEnY66L5dRL
                                                TLSH:C2839E61F0142CA5C8660674F0F8ED35471369F123A52CB26EEEE9A184F368DF44AFD4
                                                File Content Preview:.ELF..............*.......@.4...LA......4. ...(...............@...@.L4..L4...............@...@B..@B.0...............Q.td..............................././"O.n......#.*@........#.*@L...&O.n.l..................................././.../.a"O.!...n...a.b("...q.

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, little endian
                                                Version:1 (current)
                                                Machine:<unknown>
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x4001a0
                                                Flags:0xc
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:3
                                                Section Header Offset:82252
                                                Section Header Size:40
                                                Number of Section Headers:10
                                                Header String Table Index:9
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .initPROGBITS0x4000940x940x2e0x00x6AX004
                                                .textPROGBITS0x4000e00xe00x10e600x00x6AX0032
                                                .finiPROGBITS0x410f400x10f400x220x00x6AX004
                                                .rodataPROGBITS0x410f640x10f640x24e80x00x2A004
                                                .ctorsPROGBITS0x4240dc0x140dc0x80x00x3WA004
                                                .dtorsPROGBITS0x4240e40x140e40x80x00x3WA004
                                                .dataPROGBITS0x4240f00x140f00x1c0x00x3WA004
                                                .bssNOBITS0x42410c0x1410c0xaec0x00x3WA004
                                                .shstrtabSTRTAB0x00x1410c0x3e0x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x4000000x4000000x1344c0x1344c6.77600x5R E0x10000.init .text .fini .rodata
                                                LOAD0x140dc0x4240dc0x4240dc0x300xb1c2.47110x6RW 0x10000.ctors .dtors .data .bss
                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                TimestampSource PortDest PortSource IPDest IP
                                                Apr 15, 2025 14:06:52.659885883 CEST37674443192.168.2.1354.217.10.153
                                                Apr 15, 2025 14:06:53.581954956 CEST373403778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:06:53.715840101 CEST377837340107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:06:59.723987103 CEST373423778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:06:59.776179075 CEST373443778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:06:59.857894897 CEST377837342107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:06:59.910885096 CEST377837344107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:05.913671970 CEST373463778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:06.047265053 CEST377837346107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:07.875935078 CEST373483778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:08.010900974 CEST377837348107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:11.014194012 CEST373503778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:11.148417950 CEST377837350107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:12.151890039 CEST373523778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:12.286130905 CEST377837352107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:13.289226055 CEST373543778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:13.423366070 CEST377837354107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:14.049954891 CEST373563778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:14.184081078 CEST377837356107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:17.187412024 CEST373583778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:17.321613073 CEST377837358107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:18.325368881 CEST373603778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:18.458976030 CEST377837360107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:19.462913990 CEST373623778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:19.596478939 CEST377837362107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:21.239304066 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:21.239383936 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:21.239465952 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:21.240521908 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:21.240557909 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:23.427767992 CEST373663778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:23.562086105 CEST377837366107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:25.565144062 CEST373683778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:25.698985100 CEST377837368107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:29.599877119 CEST373703778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:29.735945940 CEST377837370107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:31.739696980 CEST373723778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:31.873894930 CEST377837372107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:33.183000088 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:33.183207035 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:33.183362007 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:33.183373928 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:33.184710026 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:33.184762955 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:33.185534954 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:33.185601950 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:33.185647011 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:33.185655117 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:33.185693026 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:34.686029911 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:34.686162949 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:34.686167002 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:34.687055111 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:34.687107086 CEST4435056234.243.160.129192.168.2.13
                                                Apr 15, 2025 14:07:34.687159061 CEST50562443192.168.2.1334.243.160.129
                                                Apr 15, 2025 14:07:35.701276064 CEST373743778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:35.834804058 CEST377837374107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:41.876523972 CEST373763778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:42.010725021 CEST377837376107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:45.837852001 CEST373783778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:45.973417044 CEST377837378107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:52.013816118 CEST373803778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:52.148515940 CEST377837380107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:55.976687908 CEST373823778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:56.111169100 CEST377837382107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:07:57.115252018 CEST373843778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:07:57.249571085 CEST377837384107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:02.151660919 CEST373863778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:02.252286911 CEST373883778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:02.285530090 CEST377837386107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:02.385917902 CEST377837388107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:03.291224957 CEST373903778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:03.426106930 CEST377837390107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:08.428634882 CEST373923778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:08.562196970 CEST377837392107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:12.389797926 CEST373943778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:12.523257017 CEST377837394107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:18.565089941 CEST373963778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:18.699450970 CEST377837396107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:22.526303053 CEST373983778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:22.660806894 CEST377837398107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:28.702368021 CEST374003778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:28.836800098 CEST377837400107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:31.663917065 CEST374023778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:31.798088074 CEST377837402107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:35.801029921 CEST374043778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:35.942482948 CEST377837404107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:37.839756966 CEST374063778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:37.945521116 CEST374083778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:37.979842901 CEST377837406107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:38.084383965 CEST377837408107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:41.982976913 CEST374103778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:42.120044947 CEST377837410107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:44.123558998 CEST374123778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:44.262630939 CEST377837412107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:48.088309050 CEST374143778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:48.222146034 CEST377837414107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:51.225325108 CEST374163778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:51.358756065 CEST377837416107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:53.362468004 CEST374183778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:53.496121883 CEST377837418107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:54.265779018 CEST374203778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:54.399533033 CEST377837420107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:57.402832031 CEST374223778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:57.536415100 CEST377837422107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:08:59.539170980 CEST374243778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:08:59.672661066 CEST377837424107.173.143.15192.168.2.13
                                                Apr 15, 2025 14:09:02.498955011 CEST374263778192.168.2.13107.173.143.15
                                                Apr 15, 2025 14:09:02.634932995 CEST377837426107.173.143.15192.168.2.13
                                                • motd.ubuntu.com
                                                Session IDSource IPSource PortDestination IPDestination Port
                                                0192.168.2.135056234.243.160.129443
                                                TimestampBytes transferredDirectionData
                                                2025-04-15 12:07:33 UTC249OUTGET / HTTP/1.1
                                                User-Agent: wget/1.20.3-1ubuntu1 Ubuntu/20.04.2/LTS GNU/Linux/5.4.0-72-generic/x86_64 Intel(R)/Xeon(R)/Silver/4210/CPU/@/2.20GHz cloud_id/none
                                                Accept: */*
                                                Accept-Encoding: identity
                                                Host: motd.ubuntu.com
                                                Connection: Keep-Alive
                                                2025-04-15 12:07:34 UTC271INHTTP/1.1 200 OK
                                                Date: Tue, 15 Apr 2025 12:07:34 GMT
                                                Server: Apache/2.4.18 (Ubuntu)
                                                Last-Modified: Tue, 01 Apr 2025 23:15:26 GMT
                                                ETag: "d8-631bfb6444b92"
                                                Accept-Ranges: bytes
                                                Content-Length: 216
                                                Vary: Accept-Encoding
                                                Connection: close
                                                Content-Type: text/plain
                                                2025-04-15 12:07:34 UTC216INData Raw: 20 2a 20 53 74 72 69 63 74 6c 79 20 63 6f 6e 66 69 6e 65 64 20 4b 75 62 65 72 6e 65 74 65 73 20 6d 61 6b 65 73 20 65 64 67 65 20 61 6e 64 20 49 6f 54 20 73 65 63 75 72 65 2e 20 4c 65 61 72 6e 20 68 6f 77 20 4d 69 63 72 6f 4b 38 73 0a 20 20 20 6a 75 73 74 20 72 61 69 73 65 64 20 74 68 65 20 62 61 72 20 66 6f 72 20 65 61 73 79 2c 20 72 65 73 69 6c 69 65 6e 74 20 61 6e 64 20 73 65 63 75 72 65 20 4b 38 73 20 63 6c 75 73 74 65 72 20 64 65 70 6c 6f 79 6d 65 6e 74 2e 0a 0a 20 20 20 68 74 74 70 73 3a 2f 2f 75 62 75 6e 74 75 2e 63 6f 6d 2f 65 6e 67 61 67 65 2f 73 65 63 75 72 65 2d 6b 75 62 65 72 6e 65 74 65 73 2d 61 74 2d 74 68 65 2d 65 64 67 65 0a
                                                Data Ascii: * Strictly confined Kubernetes makes edge and IoT secure. Learn how MicroK8s just raised the bar for easy, resilient and secure K8s cluster deployment. https://ubuntu.com/engage/secure-kubernetes-at-the-edge


                                                System Behavior

                                                Start time (UTC):12:06:52
                                                Start date (UTC):15/04/2025
                                                Path:/tmp/Space.sh4.elf
                                                Arguments:/tmp/Space.sh4.elf
                                                File size:4139976 bytes
                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                Start time (UTC):12:06:52
                                                Start date (UTC):15/04/2025
                                                Path:/tmp/Space.sh4.elf
                                                Arguments:-
                                                File size:4139976 bytes
                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                Start time (UTC):12:06:52
                                                Start date (UTC):15/04/2025
                                                Path:/tmp/Space.sh4.elf
                                                Arguments:-
                                                File size:4139976 bytes
                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                Start time (UTC):12:06:52
                                                Start date (UTC):15/04/2025
                                                Path:/tmp/Space.sh4.elf
                                                Arguments:-
                                                File size:4139976 bytes
                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                Start time (UTC):12:06:58
                                                Start date (UTC):15/04/2025
                                                Path:/tmp/Space.sh4.elf
                                                Arguments:-
                                                File size:4139976 bytes
                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                Start time (UTC):12:06:58
                                                Start date (UTC):15/04/2025
                                                Path:/tmp/Space.sh4.elf
                                                Arguments:-
                                                File size:4139976 bytes
                                                MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.iwsNA1ZzO0 /tmp/tmp.ovYZBiW3ah /tmp/tmp.3NmsdW7Bfp
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/cat
                                                Arguments:cat /tmp/tmp.iwsNA1ZzO0
                                                File size:43416 bytes
                                                MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/head
                                                Arguments:head -n 10
                                                File size:47480 bytes
                                                MD5 hash:fd96a67145172477dd57131396fc9608

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/tr
                                                Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                File size:51544 bytes
                                                MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/cut
                                                Arguments:cut -c -80
                                                File size:47480 bytes
                                                MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/cat
                                                Arguments:cat /tmp/tmp.iwsNA1ZzO0
                                                File size:43416 bytes
                                                MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/head
                                                Arguments:head -n 10
                                                File size:47480 bytes
                                                MD5 hash:fd96a67145172477dd57131396fc9608

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/tr
                                                Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                File size:51544 bytes
                                                MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/cut
                                                Arguments:cut -c -80
                                                File size:47480 bytes
                                                MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):12:07:33
                                                Start date (UTC):15/04/2025
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.iwsNA1ZzO0 /tmp/tmp.ovYZBiW3ah /tmp/tmp.3NmsdW7Bfp
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b