IOC Report
ROxR8Lw6ug.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/ROxR8Lw6ug.elf
/tmp/ROxR8Lw6ug.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.v2iLAP30Pe /tmp/tmp.nW8IAxZyVx /tmp/tmp.uLXmnQv5K3
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.v2iLAP30Pe /tmp/tmp.nW8IAxZyVx /tmp/tmp.uLXmnQv5K3

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fde10036000
page execute read
malicious
7ffd2a7ec000
page read and write
7fdf0ffff000
page read and write
55a6f919e000
page read and write
7fde10047000
page read and write
7fdf17532000
page read and write
7fdf17a84000
page read and write
7fdf17bd1000
page read and write
55a6f91a7000
page read and write
7ffd2a7fd000
page execute read
7fde10042000
page read and write
7fdf176c1000
page read and write
7fdf166cb000
page read and write
55a6f8f4d000
page execute read
7fdf10021000
page read and write
55a6fb1bc000
page read and write
7fdf17c16000
page read and write
55a6fb1a5000
page execute and read and write
7fdf17bad000
page read and write
7fdf17555000
page read and write
55a6fd188000
page read and write
7fdf172c7000
page read and write
7fdf16ed3000
page read and write
7fdf16f65000
page read and write
7fdf178a3000
page read and write
There are 15 hidden memdumps, click here to show them.