IOC Report
NvmCe2XrqN.elf

loading gif

Files

File Path
Type
Category
Malicious
NvmCe2XrqN.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.tn6Ngr (deleted)
data
dropped

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.iJLtKB5QY8 /tmp/tmp.dt7IYfcmuf /tmp/tmp.sKYu2lEDt7
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.iJLtKB5QY8
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.iJLtKB5QY8
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.iJLtKB5QY8 /tmp/tmp.dt7IYfcmuf /tmp/tmp.sKYu2lEDt7
/tmp/NvmCe2XrqN.elf
/tmp/NvmCe2XrqN.elf
/tmp/NvmCe2XrqN.elf
-
There are 12 hidden processes, click here to show them.

Domains

Name
IP
Malicious
kovey.mezo-api.xyz
45.131.111.219
malicious

IPs

IP
Domain
Country
Malicious
45.131.111.219
kovey.mezo-api.xyz
Germany
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f63fc412000
page execute read
malicious
7f6481e22000
page read and write
7f6480a69000
page read and write
559bb98ca000
page execute and read and write
7f648152f000
page read and write
7f64818d0000
page read and write
7f648127f000
page read and write
559bb78cc000
page read and write
7f6481271000
page read and write
7f63fc456000
page read and write
7f6481f53000
page read and write
559bb763a000
page execute read
559bb9e9a000
page read and write
7f63fc453000
page read and write
559bb98e1000
page read and write
7f6481910000
page read and write
7f6481c41000
page read and write
559bb78c2000
page read and write
7ffc1d729000
page read and write
7f6481f4b000
page read and write
7f647c000000
page read and write
7f64818f3000
page read and write
7f647c021000
page read and write
7ffc1d7a1000
page execute read
7f6481f98000
page read and write
There are 15 hidden memdumps, click here to show them.