IOC Report
NlF293hgXW.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/NlF293hgXW.elf
/tmp/NlF293hgXW.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.HsfnTCZvWL /tmp/tmp.gbmyRafLoO /tmp/tmp.V9H3yqubRw
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.HsfnTCZvWL /tmp/tmp.gbmyRafLoO /tmp/tmp.V9H3yqubRw

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
185.125.190.26
unknown
United Kingdom
54.247.62.1
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
7f601c01f000
page execute read
malicious
55cd6dee2000
page read and write
7f611320b000
page read and write
7f611388f000
page read and write
7f610c021000
page read and write
55cd7018e000
page read and write
7f6112a08000
page read and write
55cd6fee0000
page execute and read and write
7f6113bda000
page read and write
7ffcbf197000
page read and write
7ffcbf1d5000
page execute read
7f6113219000
page read and write
55cd6deda000
page read and write
55cd6fef6000
page read and write
7f611386a000
page read and write
7f610c000000
page read and write
7f6113d03000
page read and write
7f61134a8000
page read and write
7f6113d0b000
page read and write
7f601c034000
page read and write
7f601c048000
page read and write
55cd6dc57000
page execute read
7f6113d50000
page read and write
There are 13 hidden memdumps, click here to show them.