IOC Report
ehDbsf5C6M.elf

loading gif

Files

File Path
Type
Category
Malicious
ehDbsf5C6M.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.UGOJDz (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/ehDbsf5C6M.elf
/tmp/ehDbsf5C6M.elf
/tmp/ehDbsf5C6M.elf
-
/tmp/ehDbsf5C6M.elf
-

URLs

Name
IP
Malicious
193.35.18.56:65490
malicious

IPs

IP
Domain
Country
Malicious
193.35.18.56
unknown
Germany
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fe278018000
page execute read
malicious
7fe278018000
page execute read
malicious
7fe370deb000
page read and write
7fe37042a000
page read and write
55aa785bd000
page read and write
7fe27802f000
page execute and read and write
7fe370f61000
page read and write
7fe37041c000
page read and write
7fe370f61000
page read and write
55aa7c263000
page read and write
7fe370a7b000
page read and write
7fe3706b9000
page read and write
55aa7a5d1000
page read and write
7fe36fc19000
page read and write
7ffd9b2cc000
page read and write
55aa785b5000
page read and write
7fe278028000
page execute and read and write
55aa78332000
page execute read
55aa785b5000
page read and write
55aa7c263000
page read and write
7ffd9b2e7000
page execute read
7ffd9b2e7000
page execute read
55aa7a5bb000
page execute and read and write
7fe278030000
page read and write
7fe370f14000
page read and write
7fe370f1c000
page read and write
7fe37042a000
page read and write
7fe370a7b000
page read and write
7fe278030000
page read and write
7fe36fc19000
page read and write
7fe370deb000
page read and write
7fe278028000
page execute and read and write
7fe370aa0000
page read and write
7fe368000000
page read and write
7fe370f1c000
page read and write
7ffd9b2cc000
page read and write
55aa78332000
page execute read
55aa7a5bb000
page execute and read and write
7fe368021000
page read and write
7fe3706b9000
page read and write
7fe27802f000
page execute and read and write
7fe370f14000
page read and write
7fe37041c000
page read and write
55aa785bd000
page read and write
55aa7a5d1000
page read and write
7fe368021000
page read and write
7fe368000000
page read and write
7fe370aa0000
page read and write
There are 38 hidden memdumps, click here to show them.