IOC Report
XmztmwSit3.elf

loading gif

Files

File Path
Type
Category
Malicious
XmztmwSit3.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.wy6Lxl (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/XmztmwSit3.elf
/tmp/XmztmwSit3.elf
/tmp/XmztmwSit3.elf
-
/tmp/XmztmwSit3.elf
-
/tmp/XmztmwSit3.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.rLIS1Axjqg /tmp/tmp.kl74NVvZwE /tmp/tmp.GmcWMqmMNl
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.rLIS1Axjqg /tmp/tmp.kl74NVvZwE /tmp/tmp.GmcWMqmMNl

Domains

Name
IP
Malicious
jhbaghjbasdg.shop
185.196.8.213
malicious

IPs

IP
Domain
Country
Malicious
185.196.8.213
jhbaghjbasdg.shop
Switzerland
malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
55ac6da69000
page read and write
55ac6b0c7000
page read and write
7f887a309000
page read and write
7f88797d2000
page read and write
55ac6d0c5000
page execute and read and write
7f88797c4000
page read and write
55ac6d0dc000
page read and write
7f8774034000
page read and write
7f887a193000
page read and write
7f887a309000
page read and write
7f8879e48000
page read and write
7f8874021000
page read and write
55ac6ae90000
page execute read
7f887a2c4000
page read and write
7f8874000000
page read and write
7f8774034000
page read and write
7f8874000000
page read and write
7f8879a61000
page read and write
55ac6b0be000
page read and write
7ffc0c97c000
page execute read
7f8774024000
page execute read
7f887a2bc000
page read and write
55ac6b0be000
page read and write
7f8774037000
page read and write
55ac6d0dc000
page read and write
7f88797c4000
page read and write
55ac6da49000
page read and write
55ac6da69000
page read and write
55ac6b0c7000
page read and write
7f8874021000
page read and write
7f887a2c4000
page read and write
7f887a193000
page read and write
7f8878fc1000
page read and write
7f8879e48000
page read and write
7f887a2bc000
page read and write
7f8774024000
page execute read
55ac6d0c5000
page execute and read and write
7f8878fc1000
page read and write
7f8774037000
page read and write
7f8879a61000
page read and write
7ffc0c97c000
page execute read
7f88797d2000
page read and write
7f8879e23000
page read and write
7f8879e23000
page read and write
7ffc0c8eb000
page read and write
7ffc0c8eb000
page read and write
55ac6ae90000
page execute read
There are 37 hidden memdumps, click here to show them.