Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/x86.elf
|
/tmp/x86.elf
|
||
/tmp/x86.elf
|
-
|
||
/tmp/x86.elf
|
-
|
||
/tmp/x86.elf
|
-
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.aWHfGzRgEL /tmp/tmp.UB90sp39KJ /tmp/tmp.vh18H185mB
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cat
|
cat /tmp/tmp.aWHfGzRgEL
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cat
|
cat /tmp/tmp.aWHfGzRgEL
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.aWHfGzRgEL /tmp/tmp.UB90sp39KJ /tmp/tmp.vh18H185mB
|
There are 14 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://motd.ubuntu.com/
|
34.254.182.186
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
123.149.244.136
|
unknown
|
China
|
||
46.199.187.144
|
unknown
|
Cyprus
|
||
49.174.215.175
|
unknown
|
Korea Republic of
|
||
104.100.148.254
|
unknown
|
United States
|
||
111.228.205.64
|
unknown
|
China
|
||
79.204.53.188
|
unknown
|
Germany
|
||
180.190.209.167
|
unknown
|
Philippines
|
||
189.178.55.4
|
unknown
|
Mexico
|
||
93.135.72.70
|
unknown
|
Germany
|
||
160.239.121.27
|
unknown
|
Japan
|
||
80.139.201.82
|
unknown
|
Germany
|
||
12.220.80.163
|
unknown
|
United States
|
||
154.119.198.99
|
unknown
|
Gabon
|
||
179.191.9.242
|
unknown
|
Brazil
|
||
87.109.111.78
|
unknown
|
Saudi Arabia
|
||
14.26.54.18
|
unknown
|
China
|
||
102.124.182.174
|
unknown
|
Sudan
|
||
153.109.234.55
|
unknown
|
Switzerland
|
||
109.186.178.164
|
unknown
|
Israel
|
||
209.241.68.19
|
unknown
|
United States
|
||
50.148.49.253
|
unknown
|
United States
|
||
204.41.243.149
|
unknown
|
Canada
|
||
59.158.158.58
|
unknown
|
Japan
|
||
106.204.163.72
|
unknown
|
India
|
||
162.82.139.83
|
unknown
|
United States
|
||
218.221.1.108
|
unknown
|
Japan
|
||
2.129.249.235
|
unknown
|
Denmark
|
||
148.4.234.85
|
unknown
|
United States
|
||
195.78.7.160
|
unknown
|
Monaco
|
||
54.208.91.35
|
unknown
|
United States
|
||
128.59.166.196
|
unknown
|
United States
|
||
222.177.247.136
|
unknown
|
China
|
||
47.104.53.185
|
unknown
|
China
|
||
101.32.24.81
|
unknown
|
China
|
||
40.183.19.47
|
unknown
|
United States
|
||
31.21.104.92
|
unknown
|
Netherlands
|
||
131.89.227.136
|
unknown
|
United States
|
||
176.47.106.111
|
unknown
|
Saudi Arabia
|
||
74.126.33.176
|
unknown
|
United States
|
||
92.234.198.138
|
unknown
|
United Kingdom
|
||
69.191.19.45
|
unknown
|
United States
|
||
116.119.157.106
|
unknown
|
India
|
||
101.151.184.217
|
unknown
|
China
|
||
189.121.96.192
|
unknown
|
Brazil
|
||
112.105.112.99
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
58.248.43.94
|
unknown
|
China
|
||
197.184.187.151
|
unknown
|
South Africa
|
||
218.69.151.142
|
unknown
|
China
|
||
69.248.48.24
|
unknown
|
United States
|
||
103.31.207.182
|
unknown
|
Indonesia
|
||
222.30.159.53
|
unknown
|
China
|
||
202.4.16.19
|
unknown
|
New Zealand
|
||
119.205.46.173
|
unknown
|
Korea Republic of
|
||
178.133.239.122
|
unknown
|
Ukraine
|
||
91.53.108.115
|
unknown
|
Germany
|
||
81.120.149.76
|
unknown
|
Italy
|
||
112.252.147.89
|
unknown
|
China
|
||
24.17.95.215
|
unknown
|
United States
|
||
37.50.225.146
|
unknown
|
Germany
|
||
153.152.9.154
|
unknown
|
Japan
|
||
43.250.137.177
|
unknown
|
Afghanistan
|
||
212.244.109.228
|
unknown
|
Poland
|
||
169.18.204.214
|
unknown
|
United States
|
||
148.27.206.100
|
unknown
|
United States
|
||
48.69.16.90
|
unknown
|
United States
|
||
154.3.74.177
|
unknown
|
United States
|
||
195.179.84.20
|
unknown
|
Germany
|
||
12.10.152.125
|
unknown
|
United States
|
||
165.215.1.28
|
unknown
|
United States
|
||
2.101.19.93
|
unknown
|
United Kingdom
|
||
79.106.163.144
|
unknown
|
Albania
|
||
65.114.67.37
|
unknown
|
United States
|
||
109.222.109.205
|
unknown
|
France
|
||
190.53.135.33
|
unknown
|
El Salvador
|
||
19.117.204.35
|
unknown
|
United States
|
||
129.54.78.98
|
unknown
|
United States
|
||
161.224.76.137
|
unknown
|
United States
|
||
112.16.170.238
|
unknown
|
China
|
||
79.199.76.147
|
unknown
|
Germany
|
||
119.86.74.221
|
unknown
|
China
|
||
170.163.243.119
|
unknown
|
United States
|
||
194.184.107.125
|
unknown
|
Italy
|
||
78.65.128.101
|
unknown
|
Sweden
|
||
113.142.231.140
|
unknown
|
China
|
||
216.123.198.60
|
unknown
|
Canada
|
||
116.223.140.160
|
unknown
|
Japan
|
||
136.104.21.38
|
unknown
|
United States
|
||
92.68.0.26
|
unknown
|
Netherlands
|
||
53.125.253.49
|
unknown
|
Germany
|
||
190.132.225.119
|
unknown
|
Uruguay
|
||
47.141.228.45
|
unknown
|
United States
|
||
128.80.145.161
|
unknown
|
United States
|
||
138.119.110.119
|
unknown
|
Canada
|
||
102.229.128.41
|
unknown
|
unknown
|
||
142.91.37.62
|
unknown
|
United States
|
||
73.224.88.205
|
unknown
|
United States
|
||
113.59.50.247
|
unknown
|
China
|
||
154.90.165.236
|
unknown
|
Seychelles
|
||
219.247.24.196
|
unknown
|
China
|
||
164.65.131.148
|
unknown
|
United States
|
There are 90 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
8054000
|
page execute read
|
|||
8054000
|
page execute read
|
|||
8058000
|
page read and write
|
|||
9e62000
|
page read and write
|
|||
f7f49000
|
page execute read
|
|||
fff9b000
|
page read and write
|
|||
fff9b000
|
page read and write
|
|||
8055000
|
page read and write
|
|||
8055000
|
page read and write
|
|||
f7f49000
|
page execute read
|
|||
9e62000
|
page read and write
|
|||
8058000
|
page read and write
|
There are 2 hidden memdumps, click here to show them.