Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
XmztmwSit3.elf
|
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
|
initial sample
|
||
/tmp/qemu-open.wy6Lxl (deleted)
|
ASCII text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/XmztmwSit3.elf
|
/tmp/XmztmwSit3.elf
|
||
/tmp/XmztmwSit3.elf
|
-
|
||
/tmp/XmztmwSit3.elf
|
-
|
||
/tmp/XmztmwSit3.elf
|
-
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.rLIS1Axjqg /tmp/tmp.kl74NVvZwE /tmp/tmp.GmcWMqmMNl
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.rLIS1Axjqg /tmp/tmp.kl74NVvZwE /tmp/tmp.GmcWMqmMNl
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
jhbaghjbasdg.shop
|
185.196.8.213
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
185.196.8.213
|
jhbaghjbasdg.shop
|
Switzerland
|
||
34.249.145.219
|
unknown
|
United States
|
||
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.43
|
unknown
|
United Kingdom
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
55ac6da69000
|
page read and write
|
|||
55ac6b0c7000
|
page read and write
|
|||
7f887a309000
|
page read and write
|
|||
7f88797d2000
|
page read and write
|
|||
55ac6d0c5000
|
page execute and read and write
|
|||
7f88797c4000
|
page read and write
|
|||
55ac6d0dc000
|
page read and write
|
|||
7f8774034000
|
page read and write
|
|||
7f887a193000
|
page read and write
|
|||
7f887a309000
|
page read and write
|
|||
7f8879e48000
|
page read and write
|
|||
7f8874021000
|
page read and write
|
|||
55ac6ae90000
|
page execute read
|
|||
7f887a2c4000
|
page read and write
|
|||
7f8874000000
|
page read and write
|
|||
7f8774034000
|
page read and write
|
|||
7f8874000000
|
page read and write
|
|||
7f8879a61000
|
page read and write
|
|||
55ac6b0be000
|
page read and write
|
|||
7ffc0c97c000
|
page execute read
|
|||
7f8774024000
|
page execute read
|
|||
7f887a2bc000
|
page read and write
|
|||
55ac6b0be000
|
page read and write
|
|||
7f8774037000
|
page read and write
|
|||
55ac6d0dc000
|
page read and write
|
|||
7f88797c4000
|
page read and write
|
|||
55ac6da49000
|
page read and write
|
|||
55ac6da69000
|
page read and write
|
|||
55ac6b0c7000
|
page read and write
|
|||
7f8874021000
|
page read and write
|
|||
7f887a2c4000
|
page read and write
|
|||
7f887a193000
|
page read and write
|
|||
7f8878fc1000
|
page read and write
|
|||
7f8879e48000
|
page read and write
|
|||
7f887a2bc000
|
page read and write
|
|||
7f8774024000
|
page execute read
|
|||
55ac6d0c5000
|
page execute and read and write
|
|||
7f8878fc1000
|
page read and write
|
|||
7f8774037000
|
page read and write
|
|||
7f8879a61000
|
page read and write
|
|||
7ffc0c97c000
|
page execute read
|
|||
7f88797d2000
|
page read and write
|
|||
7f8879e23000
|
page read and write
|
|||
7f8879e23000
|
page read and write
|
|||
7ffc0c8eb000
|
page read and write
|
|||
7ffc0c8eb000
|
page read and write
|
|||
55ac6ae90000
|
page execute read
|
There are 37 hidden memdumps, click here to show them.