IOC Report
Kt28gy4sgm.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/Kt28gy4sgm.elf
/tmp/Kt28gy4sgm.elf
/tmp/Kt28gy4sgm.elf
-
/tmp/Kt28gy4sgm.elf
-
/tmp/Kt28gy4sgm.elf
-
/tmp/Kt28gy4sgm.elf
-
/tmp/Kt28gy4sgm.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.0Yye5q8mNq /tmp/tmp.dgNBUU65IJ /tmp/tmp.swPyngJifa
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.0Yye5q8mNq /tmp/tmp.dgNBUU65IJ /tmp/tmp.swPyngJifa

Domains

Name
IP
Malicious
tcpdown.su
104.168.45.11
tcpdown.su(
unknown

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
172.245.119.63
unknown
United States
109.202.202.202
unknown
Switzerland
104.168.45.11
tcpdown.su
United States
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f24d69e5000
page read and write
7f24d5d34000
page read and write
7f24d69e5000
page read and write
7ffdef120000
page execute read
7f24d69a0000
page read and write
7f24d6301000
page read and write
7f23d0041000
page read and write
7f24d6324000
page read and write
7f24d0021000
page read and write
7ffdef120000
page execute read
559b5ea61000
page read and write
7f24d6672000
page read and write
7ffdef037000
page read and write
559b60a5f000
page execute and read and write
7f24d6672000
page read and write
7f24cffff000
page read and write
7f24d6324000
page read and write
559b60a76000
page read and write
7f23d002f000
page execute read
559b5e807000
page execute read
7f24d6490000
page read and write
7ffdef037000
page read and write
559b5ea58000
page read and write
559b60a76000
page read and write
7f24d6096000
page read and write
559b5ea61000
page read and write
7f24d5d34000
page read and write
7f24d0021000
page read and write
559b5e807000
page execute read
7f24d697c000
page read and write
7f24cffff000
page read and write
7f23d0030000
page read and write
559b5ea58000
page read and write
559b620d4000
page read and write
7f24d697c000
page read and write
7f24d6301000
page read and write
559b620d5000
page read and write
7f23d0030000
page read and write
7f24d5ca2000
page read and write
7f24d6853000
page read and write
7f23d0041000
page read and write
7f24d5ca2000
page read and write
7f24d549a000
page read and write
7f24d6853000
page read and write
559b60a5f000
page execute and read and write
7f23d002f000
page execute read
7f24d69a0000
page read and write
7f24d549a000
page read and write
559b620b3000
page read and write
7f24d6096000
page read and write
7f24d6490000
page read and write
There are 41 hidden memdumps, click here to show them.