Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.i686.elf

Overview

General Information

Sample name:Space.i686.elf
Analysis ID:1665370
MD5:6a23277225aa517fb26257716cf4fe78
SHA1:d756114b96ea5f579e2698c24a91d71c900fb6cb
SHA256:1b74c08ecd711fe952e68644063fc1fbb806fb0633e24ca48207673d3e41102d
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1665370
Start date and time:2025-04-15 14:16:17 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 51s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.i686.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.i686.elf
PID:5565
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5565.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x115f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11608:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1161c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1166c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1170c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1175c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5565.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0x9ccb:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
5565.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_dab39a25unknownunknown
  • 0x84ae:$a: 0E 75 20 50 6A 00 6A 00 6A 00 53 6A 0E FF 74 24 48 68 DD 00
5567.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x115f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11608:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1161c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11658:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1166c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11680:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11694:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1170c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1175c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5567.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_3a56423bunknownunknown
  • 0x9ccb:$a: 24 1C 8B 44 24 20 0F B6 D0 C1 E8 08 89 54 24 24 89 44 24 20 BA 01 00
Click to see the 11 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.i686.elfVirustotal: Detection: 45%Perma Link
Source: Space.i686.elfReversingLabs: Detection: 47%
Source: global trafficTCP traffic: 192.168.2.13:37360 -> 107.173.143.15:3778
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: Space.i686.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5565.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5565.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 5565.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: 5567.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5567.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 5567.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: 5566.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5566.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 5566.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: 5571.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5571.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b Author: unknown
Source: 5571.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown
Source: Process Memory Space: Space.i686.elf PID: 5565, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.i686.elf PID: 5566, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.i686.elf PID: 5567, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.i686.elf PID: 5571, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0xc01000
Source: 5565.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5565.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 5565.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: 5567.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5567.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 5567.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: 5566.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5566.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 5566.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: 5571.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5571.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_3a56423b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 117d6eb47f000c9d475119ca0e6a1b49a91bbbece858758aaa3d7f30d0777d75, id = 3a56423b-c0cf-4483-87e3-552beb40563a, last_modified = 2021-09-16
Source: 5571.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 5a628d9af9d6dccf29e78f780bb74a2fa25167954c34d4a1529bdea5ea891ac0, id = dab39a25-852b-441f-86ab-23d945daa62c, last_modified = 2022-01-26
Source: Process Memory Space: Space.i686.elf PID: 5565, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.i686.elf PID: 5566, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.i686.elf PID: 5567, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.i686.elf PID: 5571, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/3761/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/238/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/239/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/240/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/3095/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/241/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/242/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/244/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/245/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/247/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/1906/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/3420/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/1482/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/1480/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/371/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/1238/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/134/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/3413/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/816/statusJump to behavior
Source: /tmp/Space.i686.elf (PID: 5565)File opened: /proc/35/statusJump to behavior
Source: Space.i686.elfSubmission file: segment LOAD with 7.9634 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1665370 Sample: Space.i686.elf Startdate: 15/04/2025 Architecture: LINUX Score: 60 20 107.173.143.15, 37360, 37362, 37364 AS-COLOCROSSINGUS United States 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 Space.i686.elf 2->8         started        signatures3 process4 process5 10 Space.i686.elf 8->10         started        12 Space.i686.elf 8->12         started        14 Space.i686.elf 8->14         started        process6 16 Space.i686.elf 10->16         started        18 Space.i686.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.i686.elf45%VirustotalBrowse
Space.i686.elf47%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.i686.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    107.173.143.15
    unknownUnited States
    36352AS-COLOCROSSINGUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    107.173.143.15Space.ppc.elfGet hashmaliciousUnknownBrowse
      Space.arm7.elfGet hashmaliciousMiraiBrowse
        Space.arm6.elfGet hashmaliciousUnknownBrowse
          Space.sh4.elfGet hashmaliciousUnknownBrowse
            Space.x86.elfGet hashmaliciousUnknownBrowse
              Space.m68k.elfGet hashmaliciousMiraiBrowse
                Space.mips.elfGet hashmaliciousUnknownBrowse
                  No context
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  AS-COLOCROSSINGUSSpace.ppc.elfGet hashmaliciousUnknownBrowse
                  • 107.173.143.15
                  Space.arm7.elfGet hashmaliciousMiraiBrowse
                  • 107.173.143.15
                  Space.arm6.elfGet hashmaliciousUnknownBrowse
                  • 107.173.143.15
                  Space.sh4.elfGet hashmaliciousUnknownBrowse
                  • 107.173.143.15
                  Space.x86.elfGet hashmaliciousUnknownBrowse
                  • 107.173.143.15
                  Space.m68k.elfGet hashmaliciousMiraiBrowse
                  • 107.173.143.15
                  Space.mips.elfGet hashmaliciousUnknownBrowse
                  • 107.173.143.15
                  ORDER-25013-67789543AX.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                  • 104.168.7.12
                  ORDER-2504014-0054739AP.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                  • 172.245.208.13
                  15042025Payment .xlsGet hashmaliciousUnknownBrowse
                  • 172.245.208.21
                  No context
                  No context
                  No created / dropped files found
                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
                  Entropy (8bit):7.961510020312946
                  TrID:
                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                  File name:Space.i686.elf
                  File size:38'304 bytes
                  MD5:6a23277225aa517fb26257716cf4fe78
                  SHA1:d756114b96ea5f579e2698c24a91d71c900fb6cb
                  SHA256:1b74c08ecd711fe952e68644063fc1fbb806fb0633e24ca48207673d3e41102d
                  SHA512:ecab9560e5479727c0285b4f66ef9f2399e71bf739aafb1b50ad99a344f166735f90ed23e127e5ee5534cc460bd96174a4b255636fa574cf5679d4ead94c790f
                  SSDEEP:768:KgpHcj1yjMkH2vvMFZP1cJjYBprV9V6/AQjTUnbcuyD7UHQRjL:Kg+1yjMO2va1SjGprx6XnUnouy8HyH
                  TLSH:EA03E05310900398E1CEA27A8CFF3C9B6076D5F5A900A8FE0BDCB56F5616D602724FE6
                  File Content Preview:.ELF........................4...........4. ...(.....................................................................Q.td.............................-[.UPX!.........B...B......W..........?..k.I/.j....\.W'"....)....4go.|.>#.....{~w.y.l...H..@.UO.dA....X...

                  ELF header

                  Class:ELF32
                  Data:2's complement, little endian
                  Version:1 (current)
                  Machine:Intel 80386
                  Version Number:0x1
                  Type:EXEC (Executable file)
                  OS/ABI:UNIX - Linux
                  ABI Version:0
                  Entry Point Address:0xc092b0
                  Flags:0x0
                  ELF Header Size:52
                  Program Header Offset:52
                  Program Header Size:32
                  Number of Program Headers:3
                  Section Header Offset:0
                  Section Header Size:40
                  Number of Section Headers:0
                  Header String Table Index:0
                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                  LOAD0x00xc010000xc010000x94a40x94a47.96340x5R E0x1000
                  LOAD0xc080x805cc080x805cc080x00x00.00000x6RW 0x1000
                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                  TimestampSource PortDest PortSource IPDest IP
                  Apr 15, 2025 14:17:25.884186029 CEST373603778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:26.017812967 CEST377837360107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:31.419697046 CEST373623778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:31.553050995 CEST377837362107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:35.019483089 CEST373643778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:35.153400898 CEST377837364107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:37.156033993 CEST373663778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:37.290333033 CEST377837366107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:40.555099010 CEST373683778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:40.689007044 CEST377837368107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:42.691473007 CEST373703778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:42.825799942 CEST377837370107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:44.293211937 CEST373723778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:44.428561926 CEST377837372107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:45.430682898 CEST373743778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:45.564390898 CEST377837374107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:49.828639984 CEST373763778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:49.962999105 CEST377837376107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:50.964935064 CEST373783778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:51.099205017 CEST377837378107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:54.567228079 CEST373803778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:54.701438904 CEST377837380107.173.143.15192.168.2.13
                  Apr 15, 2025 14:17:59.703138113 CEST373823778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:17:59.837312937 CEST377837382107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:00.100807905 CEST373843778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:00.235116005 CEST377837384107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:05.237334967 CEST373863778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:05.371259928 CEST377837386107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:06.839859009 CEST373883778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:06.973922968 CEST377837388107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:12.374021053 CEST373903778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:12.508887053 CEST377837390107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:15.976421118 CEST373923778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:16.109987020 CEST377837392107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:21.511223078 CEST373943778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:21.645397902 CEST377837394107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:22.113195896 CEST373963778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:22.247494936 CEST377837396107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:27.647643089 CEST373983778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:27.781311035 CEST377837398107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:31.250323057 CEST374003778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:31.384700060 CEST377837400107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:33.387469053 CEST374023778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:33.522130966 CEST377837402107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:36.783773899 CEST374043778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:36.918081045 CEST377837404107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:38.921154022 CEST374063778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:39.055421114 CEST377837406107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:40.524853945 CEST374083778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:40.658739090 CEST377837408107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:46.057760954 CEST374103778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:46.191507101 CEST377837410107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:49.661130905 CEST374123778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:49.795028925 CEST377837412107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:55.193939924 CEST374143778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:55.327946901 CEST377837414107.173.143.15192.168.2.13
                  Apr 15, 2025 14:18:59.797460079 CEST374163778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:18:59.930891037 CEST377837416107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:05.330048084 CEST374183778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:05.463785887 CEST377837418107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:07.932765961 CEST374203778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:08.066570044 CEST377837420107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:13.466409922 CEST374223778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:13.599987984 CEST377837422107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:17.069108963 CEST374243778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:17.202778101 CEST377837424107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:20.205140114 CEST374263778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:20.339776993 CEST377837426107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:21.342890978 CEST374283778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:21.477401018 CEST377837428107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:22.602135897 CEST374303778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:22.735985041 CEST377837430107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:23.480750084 CEST374323778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:23.614372015 CEST377837432107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:25.738693953 CEST374343778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:25.872982025 CEST377837434107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:26.875866890 CEST374363778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:27.011884928 CEST377837436107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:28.617662907 CEST374383778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:28.751477957 CEST377837438107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:29.014035940 CEST374403778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:29.147918940 CEST377837440107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:34.150595903 CEST374423778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:34.284523010 CEST377837442107.173.143.15192.168.2.13
                  Apr 15, 2025 14:19:34.754410982 CEST374443778192.168.2.13107.173.143.15
                  Apr 15, 2025 14:19:34.888371944 CEST377837444107.173.143.15192.168.2.13

                  System Behavior

                  Start time (UTC):12:17:25
                  Start date (UTC):15/04/2025
                  Path:/tmp/Space.i686.elf
                  Arguments:/tmp/Space.i686.elf
                  File size:38304 bytes
                  MD5 hash:6a23277225aa517fb26257716cf4fe78

                  Start time (UTC):12:17:25
                  Start date (UTC):15/04/2025
                  Path:/tmp/Space.i686.elf
                  Arguments:-
                  File size:38304 bytes
                  MD5 hash:6a23277225aa517fb26257716cf4fe78

                  Start time (UTC):12:17:25
                  Start date (UTC):15/04/2025
                  Path:/tmp/Space.i686.elf
                  Arguments:-
                  File size:38304 bytes
                  MD5 hash:6a23277225aa517fb26257716cf4fe78

                  Start time (UTC):12:17:25
                  Start date (UTC):15/04/2025
                  Path:/tmp/Space.i686.elf
                  Arguments:-
                  File size:38304 bytes
                  MD5 hash:6a23277225aa517fb26257716cf4fe78

                  Start time (UTC):12:17:31
                  Start date (UTC):15/04/2025
                  Path:/tmp/Space.i686.elf
                  Arguments:-
                  File size:38304 bytes
                  MD5 hash:6a23277225aa517fb26257716cf4fe78

                  Start time (UTC):12:17:31
                  Start date (UTC):15/04/2025
                  Path:/tmp/Space.i686.elf
                  Arguments:-
                  File size:38304 bytes
                  MD5 hash:6a23277225aa517fb26257716cf4fe78