Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.x86_64.elf

Overview

General Information

Sample name:Space.x86_64.elf
Analysis ID:1665377
MD5:5315695a29fb344b607af4d3694c54a2
SHA1:b2e806e9f41b4f842d1e6bcec394909996b59afd
SHA256:07a919ec4502eb9a58bfc9d2ec7c9e59514c5add56d602542a6abd6f3da81757
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1665377
Start date and time:2025-04-15 14:23:26 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.x86_64.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
Command:/tmp/Space.x86_64.elf
PID:5535
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
5535.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5535.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x49b2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
5537.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5537.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x49b2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
5536.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 7 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.x86_64.elfVirustotal: Detection: 39%Perma Link
Source: Space.x86_64.elfReversingLabs: Detection: 41%
Source: global trafficTCP traffic: 192.168.2.15:58298 -> 107.173.143.15:3778
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: unknownTCP traffic detected without corresponding DNS query: 107.173.143.15
Source: Space.x86_64.elfString found in binary or memory: http://upx.sf.net

System Summary

barindex
Source: 5535.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5535.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5537.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5537.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5536.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5536.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 5541.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5541.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 5535, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 5536, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 5537, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 5541, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x400000
Source: 5535.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5535.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5537.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5537.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5536.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5536.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 5541.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5541.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 5535, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 5536, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 5537, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 5541, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1333/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1695/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/911/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/914/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/917/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/3879/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/19/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1591/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/246/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/5/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1585/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/7/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/129/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/8/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/802/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/803/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/804/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/3407/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1484/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/490/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/131/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/133/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1479/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/378/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/931/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1595/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/812/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/933/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/3419/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/35/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/3310/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/260/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/261/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/262/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/142/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/263/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/264/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/265/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/145/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/266/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/267/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/268/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/3303/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/269/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1486/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/1806/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/3440/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 5535)File opened: /proc/270/statusJump to behavior
Source: Space.x86_64.elfSubmission file: segment LOAD with 7.9629 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1665377 Sample: Space.x86_64.elf Startdate: 15/04/2025 Architecture: LINUX Score: 60 20 107.173.143.15, 3778, 58298, 58300 AS-COLOCROSSINGUS United States 2->20 22 Malicious sample detected (through community Yara rule) 2->22 24 Multi AV Scanner detection for submitted file 2->24 26 Sample is packed with UPX 2->26 8 Space.x86_64.elf 2->8         started        signatures3 process4 process5 10 Space.x86_64.elf 8->10         started        12 Space.x86_64.elf 8->12         started        14 Space.x86_64.elf 8->14         started        process6 16 Space.x86_64.elf 10->16         started        18 Space.x86_64.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.x86_64.elf39%VirustotalBrowse
Space.x86_64.elf42%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.x86_64.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    107.173.143.15
    unknownUnited States
    36352AS-COLOCROSSINGUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    107.173.143.15Space.i686.elfGet hashmaliciousUnknownBrowse
      Space.ppc.elfGet hashmaliciousUnknownBrowse
        Space.arm7.elfGet hashmaliciousMiraiBrowse
          Space.arm6.elfGet hashmaliciousUnknownBrowse
            Space.sh4.elfGet hashmaliciousUnknownBrowse
              Space.x86.elfGet hashmaliciousUnknownBrowse
                Space.m68k.elfGet hashmaliciousMiraiBrowse
                  Space.mips.elfGet hashmaliciousUnknownBrowse
                    No context
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    AS-COLOCROSSINGUSSpace.i686.elfGet hashmaliciousUnknownBrowse
                    • 107.173.143.15
                    Space.ppc.elfGet hashmaliciousUnknownBrowse
                    • 107.173.143.15
                    Space.arm7.elfGet hashmaliciousMiraiBrowse
                    • 107.173.143.15
                    Space.arm6.elfGet hashmaliciousUnknownBrowse
                    • 107.173.143.15
                    Space.sh4.elfGet hashmaliciousUnknownBrowse
                    • 107.173.143.15
                    Space.x86.elfGet hashmaliciousUnknownBrowse
                    • 107.173.143.15
                    Space.m68k.elfGet hashmaliciousMiraiBrowse
                    • 107.173.143.15
                    Space.mips.elfGet hashmaliciousUnknownBrowse
                    • 107.173.143.15
                    ORDER-25013-67789543AX.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                    • 104.168.7.12
                    ORDER-2504014-0054739AP.vbsGet hashmaliciousWSHRat, DarkTortillaBrowse
                    • 172.245.208.13
                    No context
                    No context
                    No created / dropped files found
                    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                    Entropy (8bit):7.960932097139582
                    TrID:
                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                    File name:Space.x86_64.elf
                    File size:37'524 bytes
                    MD5:5315695a29fb344b607af4d3694c54a2
                    SHA1:b2e806e9f41b4f842d1e6bcec394909996b59afd
                    SHA256:07a919ec4502eb9a58bfc9d2ec7c9e59514c5add56d602542a6abd6f3da81757
                    SHA512:e30a245d8edf5a31234cea833ca78a81bbabb6c14fdf401a377a8c442b6a79bd560a49299430814bff6fee6ab6908b1cf33a41821560149e858dcf5b2abcec8d
                    SSDEEP:768:RLR/W7ThZdFW7v2ZJdNWK/fPquiYKqdlqGNX0wiXuDAisdEkQp3LWx0K:RV2zdITqJnqu3dTVLOdZ63a/
                    TLSH:9EF2F1E64B83EA90C50486F0C4559EC4E693B12284234E2A0BDDF8E57CEFD173B12663
                    File Content Preview:.ELF..............>.....P.@.....@...................@.8...@.......................@.......@....................... ......................Ka......Ka.............................Q.td.....................................................I..UPX!D.......8:..8:.

                    ELF header

                    Class:ELF64
                    Data:2's complement, little endian
                    Version:1 (current)
                    Machine:Advanced Micro Devices X86-64
                    Version Number:0x1
                    Type:EXEC (Executable file)
                    OS/ABI:UNIX - System V
                    ABI Version:0
                    Entry Point Address:0x408050
                    Flags:0x0
                    ELF Header Size:64
                    Program Header Offset:64
                    Program Header Size:56
                    Number of Program Headers:3
                    Section Header Offset:0
                    Section Header Size:64
                    Number of Section Headers:0
                    Header String Table Index:0
                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                    LOAD0x00x4000000x4000000x918c0x918c7.96290x5R E0x200000
                    LOAD0xb000x614b000x614b000x00x00.00000x6RW 0x1000
                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                    TimestampSource PortDest PortSource IPDest IP
                    Apr 15, 2025 14:24:21.902765036 CEST582983778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:22.037061930 CEST377858298107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:27.481765032 CEST583003778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:27.615647078 CEST377858300107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:31.038677931 CEST583023778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:31.172951937 CEST377858302107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:33.174873114 CEST583043778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:33.309382915 CEST377858304107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:34.311563015 CEST583063778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:34.446047068 CEST377858306107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:36.617685080 CEST583083778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:36.752506971 CEST377858308107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:38.756100893 CEST583103778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:38.890047073 CEST377858310107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:39.894702911 CEST583123778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:40.029634953 CEST377858312107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:43.449081898 CEST583143778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:43.582843065 CEST377858314107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:49.031984091 CEST583163778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:49.165962934 CEST377858316107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:50.587166071 CEST583183778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:50.721277952 CEST377858318107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:52.723522902 CEST583203778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:52.862605095 CEST377858320107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:53.865437031 CEST583223778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:53.999866962 CEST377858322107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:56.003124952 CEST583243778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:56.137667894 CEST377858324107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:56.168443918 CEST583263778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:56.302200079 CEST377858326107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:58.140093088 CEST583283778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:58.274450064 CEST377858328107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:58.304836988 CEST583303778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:58.438515902 CEST377858330107.173.143.15192.168.2.15
                    Apr 15, 2025 14:24:59.441442966 CEST583323778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:24:59.575402021 CEST377858332107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:01.579118967 CEST583343778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:01.713342905 CEST377858334107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:03.717144012 CEST583363778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:03.850826979 CEST377858336107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:08.277744055 CEST583383778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:08.411815882 CEST377858338107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:13.854523897 CEST583403778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:13.989175081 CEST377858340107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:14.415354967 CEST583423778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:14.549242973 CEST377858342107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:19.992222071 CEST583443778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:20.125921011 CEST377858344107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:20.552690029 CEST583463778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:20.686984062 CEST377858346107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:26.128653049 CEST583483778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:26.263382912 CEST377858348107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:26.689912081 CEST583503778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:26.824039936 CEST377858350107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:28.827615976 CEST583523778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:28.962156057 CEST377858352107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:29.964900970 CEST583543778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:30.099359989 CEST377858354107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:32.103503942 CEST583563778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:32.237339020 CEST377858356107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:32.266618967 CEST583583778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:32.461066008 CEST377858358107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:34.240305901 CEST583603778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:34.373989105 CEST377858360107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:34.463917971 CEST583623778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:34.598939896 CEST377858362107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:35.602150917 CEST583643778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:35.736294985 CEST377858364107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:37.739201069 CEST583663778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:37.873073101 CEST377858366107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:39.876259089 CEST583683778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:40.010999918 CEST377858368107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:44.376638889 CEST583703778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:44.510684013 CEST377858370107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:49.512912989 CEST583723778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:49.646969080 CEST377858372107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:50.012871981 CEST583743778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:50.147356033 CEST377858374107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:55.150501013 CEST583763778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:55.284590960 CEST377858376107.173.143.15192.168.2.15
                    Apr 15, 2025 14:25:59.649595976 CEST583783778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:25:59.784760952 CEST377858378107.173.143.15192.168.2.15
                    Apr 15, 2025 14:26:05.287153959 CEST583803778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:26:05.423402071 CEST377858380107.173.143.15192.168.2.15
                    Apr 15, 2025 14:26:09.787632942 CEST583823778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:26:09.921835899 CEST377858382107.173.143.15192.168.2.15
                    Apr 15, 2025 14:26:15.426578045 CEST583843778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:26:15.561213970 CEST377858384107.173.143.15192.168.2.15
                    Apr 15, 2025 14:26:19.925206900 CEST583863778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:26:20.059138060 CEST377858386107.173.143.15192.168.2.15
                    Apr 15, 2025 14:26:25.563648939 CEST583883778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:26:25.697356939 CEST377858388107.173.143.15192.168.2.15
                    Apr 15, 2025 14:26:26.062169075 CEST583903778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:26:26.196451902 CEST377858390107.173.143.15192.168.2.15
                    Apr 15, 2025 14:26:31.699855089 CEST583923778192.168.2.15107.173.143.15
                    Apr 15, 2025 14:26:31.834381104 CEST377858392107.173.143.15192.168.2.15

                    System Behavior

                    Start time (UTC):12:24:21
                    Start date (UTC):15/04/2025
                    Path:/tmp/Space.x86_64.elf
                    Arguments:/tmp/Space.x86_64.elf
                    File size:37524 bytes
                    MD5 hash:5315695a29fb344b607af4d3694c54a2

                    Start time (UTC):12:24:21
                    Start date (UTC):15/04/2025
                    Path:/tmp/Space.x86_64.elf
                    Arguments:-
                    File size:37524 bytes
                    MD5 hash:5315695a29fb344b607af4d3694c54a2

                    Start time (UTC):12:24:21
                    Start date (UTC):15/04/2025
                    Path:/tmp/Space.x86_64.elf
                    Arguments:-
                    File size:37524 bytes
                    MD5 hash:5315695a29fb344b607af4d3694c54a2

                    Start time (UTC):12:24:21
                    Start date (UTC):15/04/2025
                    Path:/tmp/Space.x86_64.elf
                    Arguments:-
                    File size:37524 bytes
                    MD5 hash:5315695a29fb344b607af4d3694c54a2

                    Start time (UTC):12:24:27
                    Start date (UTC):15/04/2025
                    Path:/tmp/Space.x86_64.elf
                    Arguments:-
                    File size:37524 bytes
                    MD5 hash:5315695a29fb344b607af4d3694c54a2

                    Start time (UTC):12:24:27
                    Start date (UTC):15/04/2025
                    Path:/tmp/Space.x86_64.elf
                    Arguments:-
                    File size:37524 bytes
                    MD5 hash:5315695a29fb344b607af4d3694c54a2