Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.ppc.elf

Overview

General Information

Sample name:Space.ppc.elf
Analysis ID:1665368
MD5:8d9fe50bc0391271094d2cbec8e1efc3
SHA1:6cf68983f5cfe981232996937d269bddaec26d92
SHA256:6945ff139b82bd2dca947926cdca60bc3cb2e97f716f76becf2843f2bd2bf4b2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:68
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1665368
Start date and time:2025-04-15 14:12:12 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.ppc.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
Command:/tmp/Space.ppc.elf
PID:5415
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5415.1.00007f6020014000.00007f6020017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5419.1.00007f6020014000.00007f6020017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5429.1.00007f6020014000.00007f6020017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5417.1.00007f6020014000.00007f6020017000.rwx.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x350:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x364:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x378:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x38c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x404:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x418:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x42c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x440:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x454:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x468:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x47c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x490:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.ppc.elf PID: 5415Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xff7f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff93:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffcf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1001f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10033:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10047:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1005b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1006f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10083:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10097:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100ab:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100bf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100d3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100e7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100fb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1010f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.ppc.elfAvira: detected
Source: Space.ppc.elfVirustotal: Detection: 44%Perma Link
Source: Space.ppc.elfReversingLabs: Detection: 44%
Source: global trafficTCP traffic: 192.168.2.13:37342 -> 107.173.143.15:3778
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: Space.ppc.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5415.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5419.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5429.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5417.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 5415, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 5417, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 5419, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.ppc.elf PID: 5429, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 5415.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5419.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5429.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5417.1.00007f6020014000.00007f6020017000.rwx.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 5415, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 5417, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 5419, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.ppc.elf PID: 5429, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/238/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/239/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/3633/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/5398/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/5399/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/3095/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/241/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/1906/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/1482/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/1480/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/371/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/1238/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/134/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/3413/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/3773/statusJump to behavior
Source: /tmp/Space.ppc.elf (PID: 5415)File opened: /proc/936/statusJump to behavior
Source: Space.ppc.elfSubmission file: segment LOAD with 7.9632 entropy (max. 8.0)
Source: /tmp/Space.ppc.elf (PID: 5415)Queries kernel information via 'uname': Jump to behavior
Source: Space.ppc.elf, 5415.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmp, Space.ppc.elf, 5417.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmp, Space.ppc.elf, 5419.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmp, Space.ppc.elf, 5429.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/Space.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.ppc.elf
Source: Space.ppc.elf, 5417.1.0000555ddf133000.0000555ddf1e3000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: Space.ppc.elf, 5415.1.0000555ddf133000.0000555ddf204000.rw-.sdmp, Space.ppc.elf, 5419.1.0000555ddf133000.0000555ddf1e3000.rw-.sdmp, Space.ppc.elf, 5429.1.0000555ddf133000.0000555ddf204000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: Space.ppc.elf, 5415.1.0000555ddf133000.0000555ddf204000.rw-.sdmp, Space.ppc.elf, 5417.1.0000555ddf133000.0000555ddf1e3000.rw-.sdmp, Space.ppc.elf, 5419.1.0000555ddf133000.0000555ddf1e3000.rw-.sdmp, Space.ppc.elf, 5429.1.0000555ddf133000.0000555ddf204000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: Space.ppc.elf, 5415.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmp, Space.ppc.elf, 5417.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmp, Space.ppc.elf, 5419.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmp, Space.ppc.elf, 5429.1.00007ffc3f4d0000.00007ffc3f4f1000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1665368 Sample: Space.ppc.elf Startdate: 15/04/2025 Architecture: LINUX Score: 68 20 107.173.143.15, 37342, 37344, 37346 AS-COLOCROSSINGUS United States 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Antivirus / Scanner detection for submitted sample 2->24 26 Multi AV Scanner detection for submitted file 2->26 28 Sample is packed with UPX 2->28 8 Space.ppc.elf 2->8         started        signatures3 process4 process5 10 Space.ppc.elf 8->10         started        12 Space.ppc.elf 8->12         started        14 Space.ppc.elf 8->14         started        process6 16 Space.ppc.elf 10->16         started        18 Space.ppc.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.ppc.elf44%VirustotalBrowse
Space.ppc.elf44%ReversingLabsLinux.Trojan.Mirai
Space.ppc.elf100%AviraEXP/ELF.Agent.F.118
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.ppc.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    107.173.143.15
    unknownUnited States
    36352AS-COLOCROSSINGUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    107.173.143.15Space.arm7.elfGet hashmaliciousMiraiBrowse
      Space.arm6.elfGet hashmaliciousUnknownBrowse
        Space.sh4.elfGet hashmaliciousUnknownBrowse
          Space.x86.elfGet hashmaliciousUnknownBrowse
            Space.m68k.elfGet hashmaliciousMiraiBrowse
              Space.mips.elfGet hashmaliciousUnknownBrowse
                No context
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                AS-COLOCROSSINGUSSpace.arm7.elfGet hashmaliciousMiraiBrowse
                • 107.173.143.15
                Space.arm6.elfGet hashmaliciousUnknownBrowse
                • 107.173.143.15
                Space.sh4.elfGet hashmaliciousUnknownBrowse
                • 107.173.143.15
                Space.x86.elfGet hashmaliciousUnknownBrowse
                • 107.173.143.15
                Space.m68k.elfGet hashmaliciousMiraiBrowse
                • 107.173.143.15
                Space.mips.elfGet hashmaliciousUnknownBrowse
                • 107.173.143.15
                ORDER-25013-67789543AX.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                • 104.168.7.12
                ORDER-2504014-0054739AP.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                • 172.245.208.13
                15042025Payment .xlsGet hashmaliciousUnknownBrowse
                • 172.245.208.21
                15042025Payment .xlsGet hashmaliciousUnknownBrowse
                • 172.245.208.21
                No context
                No context
                No created / dropped files found
                File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, no section header
                Entropy (8bit):7.961145165413035
                TrID:
                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                File name:Space.ppc.elf
                File size:40'308 bytes
                MD5:8d9fe50bc0391271094d2cbec8e1efc3
                SHA1:6cf68983f5cfe981232996937d269bddaec26d92
                SHA256:6945ff139b82bd2dca947926cdca60bc3cb2e97f716f76becf2843f2bd2bf4b2
                SHA512:72bbc89ddb31841f831f23112ed1efa5e72152639ba0d90b42b2d90383ad8e6ac0ec03952d4603a5c22737ed15214cf767641786c56297e0cb73d47131349daf
                SSDEEP:768:mYIycbQHUBnVYoMcb/BLY+d34eE6H2PUQzSh18rbYoi4uVcqgw091:pI7bQ0BVeA5YYnH25zAoi4u+qgw091
                TLSH:0F03F1B1F1E60DB9EABECB760198E7C53FE1B7CF3AD58490E1A1C2217148C151996EC2
                File Content Preview:.ELF...........................4.........4. ...(.......................h...h..............k...k...k.................dt.Q................................UPX!..........b...b........V.......?.E.h4...@b........=.a....`..Y...j{.c.HL}.....H..z.q.H.....8ea......

                ELF header

                Class:ELF32
                Data:2's complement, big endian
                Version:1 (current)
                Machine:PowerPC
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:UNIX - Linux
                ABI Version:0
                Entry Point Address:0x108a80
                Flags:0x0
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:3
                Section Header Offset:0
                Section Header Size:40
                Number of Section Headers:0
                Header String Table Index:0
                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                LOAD0x00x1000000x1000000x9c680x9c687.96320x5R E0x10000
                LOAD0x6b900x10026b900x10026b900x00x00.00000x6RW 0x10000
                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                TimestampSource PortDest PortSource IPDest IP
                Apr 15, 2025 14:12:59.614303112 CEST373423778192.168.2.13107.173.143.15
                Apr 15, 2025 14:12:59.747994900 CEST377837342107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:02.790537119 CEST373443778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:02.924632072 CEST377837344107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:05.458019972 CEST373463778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:05.591736078 CEST377837346107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:08.625808001 CEST373483778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:08.760138988 CEST377837348107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:10.926647902 CEST373503778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:11.060744047 CEST377837350107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:12.062463999 CEST373523778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:12.196746111 CEST377837352107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:13.199227095 CEST373543778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:13.333358049 CEST377837354107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:16.762209892 CEST373563778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:16.896421909 CEST377837356107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:17.898822069 CEST373583778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:18.033169985 CEST377837358107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:19.035593987 CEST373603778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:19.169197083 CEST377837360107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:22.335995913 CEST373623778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:22.469458103 CEST377837362107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:25.471590042 CEST373643778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:25.605144024 CEST377837364107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:28.171173096 CEST373663778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:28.305535078 CEST377837366107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:31.307323933 CEST373683778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:31.441643953 CEST377837368107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:35.606985092 CEST373703778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:35.741065979 CEST377837370107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:36.743340969 CEST373723778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:36.877865076 CEST377837372107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:40.879904032 CEST373743778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:41.013293028 CEST377837374107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:41.444010973 CEST373763778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:41.578171015 CEST377837376107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:42.580230951 CEST373783778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:42.714257002 CEST377837378107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:46.716552973 CEST373803778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:46.851700068 CEST377837380107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:50.015198946 CEST373823778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:50.149425983 CEST377837382107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:51.151566029 CEST373843778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:51.285567045 CEST377837384107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:55.287833929 CEST373863778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:55.421648026 CEST377837386107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:55.854365110 CEST373883778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:55.988075018 CEST377837388107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:56.990946054 CEST373903778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:57.125660896 CEST377837390107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:57.424200058 CEST373923778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:57.557643890 CEST377837392107.173.143.15192.168.2.13
                Apr 15, 2025 14:13:58.560168028 CEST373943778192.168.2.13107.173.143.15
                Apr 15, 2025 14:13:58.693886042 CEST377837394107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:01.128001928 CEST373963778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:01.262160063 CEST377837396107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:02.696412086 CEST373983778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:02.830116987 CEST377837398107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:03.264928102 CEST374003778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:03.399158955 CEST377837400107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:04.402040958 CEST374023778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:04.535847902 CEST377837402107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:08.545310020 CEST374043778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:08.678957939 CEST377837404107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:09.832384109 CEST374063778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:09.966530085 CEST377837406107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:14.968213081 CEST374083778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:15.102036953 CEST377837408107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:15.681360006 CEST374103778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:15.815241098 CEST377837410107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:19.104439974 CEST374123778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:19.238107920 CEST377837412107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:20.817193985 CEST374143778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:20.950902939 CEST377837414107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:24.953485966 CEST374163778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:25.086970091 CEST377837416107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:28.240351915 CEST374183778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:28.373964071 CEST377837418107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:30.376061916 CEST374203778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:30.509807110 CEST377837420107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:34.090140104 CEST374223778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:34.223623037 CEST377837422107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:36.226779938 CEST374243778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:36.361017942 CEST377837424107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:39.511814117 CEST374263778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:39.646173000 CEST377837426107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:41.648236990 CEST374283778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:41.782366037 CEST377837428107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:45.363590956 CEST374303778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:45.498811007 CEST377837430107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:47.501347065 CEST374323778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:47.634936094 CEST377837432107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:48.784713030 CEST374343778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:48.918400049 CEST377837434107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:49.921423912 CEST374363778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:50.056180954 CEST377837436107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:54.637693882 CEST374383778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:54.771763086 CEST377837438107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:55.774842024 CEST374403778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:55.908730030 CEST377837440107.173.143.15192.168.2.13
                Apr 15, 2025 14:14:58.058537006 CEST374423778192.168.2.13107.173.143.15
                Apr 15, 2025 14:14:58.192508936 CEST377837442107.173.143.15192.168.2.13
                Apr 15, 2025 14:15:02.194937944 CEST374443778192.168.2.13107.173.143.15
                Apr 15, 2025 14:15:02.330184937 CEST377837444107.173.143.15192.168.2.13
                Apr 15, 2025 14:15:03.911418915 CEST374463778192.168.2.13107.173.143.15
                Apr 15, 2025 14:15:04.045821905 CEST377837446107.173.143.15192.168.2.13
                Apr 15, 2025 14:15:05.332670927 CEST374483778192.168.2.13107.173.143.15
                Apr 15, 2025 14:15:05.466813087 CEST377837448107.173.143.15192.168.2.13
                Apr 15, 2025 14:15:07.469465971 CEST374503778192.168.2.13107.173.143.15
                Apr 15, 2025 14:15:07.603028059 CEST377837450107.173.143.15192.168.2.13
                Apr 15, 2025 14:15:08.048572063 CEST374523778192.168.2.13107.173.143.15
                Apr 15, 2025 14:15:08.182265043 CEST377837452107.173.143.15192.168.2.13
                Apr 15, 2025 14:15:09.604677916 CEST374543778192.168.2.13107.173.143.15
                Apr 15, 2025 14:15:09.738359928 CEST377837454107.173.143.15192.168.2.13

                System Behavior

                Start time (UTC):12:12:58
                Start date (UTC):15/04/2025
                Path:/tmp/Space.ppc.elf
                Arguments:/tmp/Space.ppc.elf
                File size:5388968 bytes
                MD5 hash:ae65271c943d3451b7f026d1fadccea6

                Start time (UTC):12:12:59
                Start date (UTC):15/04/2025
                Path:/tmp/Space.ppc.elf
                Arguments:-
                File size:5388968 bytes
                MD5 hash:ae65271c943d3451b7f026d1fadccea6

                Start time (UTC):12:12:59
                Start date (UTC):15/04/2025
                Path:/tmp/Space.ppc.elf
                Arguments:-
                File size:5388968 bytes
                MD5 hash:ae65271c943d3451b7f026d1fadccea6

                Start time (UTC):12:12:59
                Start date (UTC):15/04/2025
                Path:/tmp/Space.ppc.elf
                Arguments:-
                File size:5388968 bytes
                MD5 hash:ae65271c943d3451b7f026d1fadccea6

                Start time (UTC):12:13:04
                Start date (UTC):15/04/2025
                Path:/tmp/Space.ppc.elf
                Arguments:-
                File size:5388968 bytes
                MD5 hash:ae65271c943d3451b7f026d1fadccea6

                Start time (UTC):12:13:04
                Start date (UTC):15/04/2025
                Path:/tmp/Space.ppc.elf
                Arguments:-
                File size:5388968 bytes
                MD5 hash:ae65271c943d3451b7f026d1fadccea6