IOC Report
PN9QHDmpS1.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/PN9QHDmpS1.elf
/tmp/PN9QHDmpS1.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.5fMH37Grl2 /tmp/tmp.K4107qt98Q /tmp/tmp.nGAh4yXt5S
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.5fMH37Grl2 /tmp/tmp.K4107qt98Q /tmp/tmp.nGAh4yXt5S

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
185.125.190.26
unknown
United Kingdom
54.247.62.1
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
7fec0442a000
page execute read
malicious
55f7b52a7000
page read and write
7fec8bae9000
page read and write
7fec0446f000
page read and write
7fec8c141000
page read and write
55f7b4e2a000
page execute and read and write
7fec8b725000
page read and write
7fec8c149000
page read and write
7fec8b475000
page read and write
55f7b2e22000
page read and write
55f7b4e41000
page read and write
7fec8ac5f000
page read and write
7fec8bb06000
page read and write
7fec8c18e000
page read and write
7fec84000000
page read and write
7fec8b467000
page read and write
7ffd815c8000
page read and write
7fec84021000
page read and write
55f7b2e2c000
page read and write
7fec8be37000
page read and write
7fec8bac6000
page read and write
7fec8c018000
page read and write
7ffd815cd000
page execute read
55f7b2b9a000
page execute read
There are 14 hidden memdumps, click here to show them.