IOC Report
YLjhvMJyOO.elf

loading gif

Files

File Path
Type
Category
Malicious
YLjhvMJyOO.elf
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.nrn8tC (deleted)
data
dropped

Processes

Path
Cmdline
Malicious
/tmp/YLjhvMJyOO.elf
/tmp/YLjhvMJyOO.elf
/tmp/YLjhvMJyOO.elf
-

Domains

Name
IP
Malicious
kovey.mezo-api.xyz
45.131.111.219
malicious
kovey.mezo-api.xyz.= fvK66a1PV!E(%:5;= fMOOPV!a1EAP@@x
unknown
malicious
kovey.mezo-api.xyz.= f66a1PV!E(j5`V= fOOPV!a1EAc@@x
unknown
malicious
kovey.mezo-api.xyz.= ftc66a1PV!E(:5P= feOOPV!a1EA@@t
unknown
malicious
kovey.mezo-api.xyz.= fk66a1PV!E(:,5 = fJJJPV!a1E<=@@h
unknown
malicious
kovey.mezo-api.xyz.= f66a1PV!E(:#5I= fOOPV!a1EAe@@x
unknown
malicious
kovey.mezo-api.xyz.= fR66a1PV!E(|:1I5OL= fJJPV!a1E<Z@@5L
unknown
malicious
kovey.mezo-api.xyz.= fG/66a1PV!E(`mj5$= f1OOPV!a1EA@@t
unknown
malicious
kovey.mezo-api.xyz.= f66a1PV!E(je5!{= fNOOPV!a1EA*@@t
unknown
malicious
kovey.mezo-api.xyz.= f66a1PV!E(j~5uG= fOOPV!a1EA;@@x
unknown
malicious
kovey.mezo-api.xyz.= f66a1PV!E(x:5;= fOOPV!a1EA@@t
unknown
malicious
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
45.131.111.219
kovey.mezo-api.xyz
Germany
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7fad58026000
page execute read
malicious
55bd22a3c000
page execute read
7ffe359a4000
page read and write
7fad58031000
page read and write
7fae5e77e000
page read and write
7fad5802e000
page read and write
7fae5f29d000
page read and write
7fae5eeda000
page read and write
7fae5e6ec000
page read and write
7fae5ed4b000
page read and write
7fae57fff000
page read and write
7fae5f42f000
page read and write
55bd22c8d000
page read and write
55bd22c96000
page read and write
7ffe359be000
page execute read
7fae5dee4000
page read and write
55bd24cab000
page read and write
7fae58021000
page read and write
7fae5f0bc000
page read and write
7fae5eae0000
page read and write
55bd250a0000
page read and write
7fae5f3c6000
page read and write
7fae5ed6e000
page read and write
7fae5f3ea000
page read and write
55bd24c94000
page execute and read and write
There are 15 hidden memdumps, click here to show them.