IOC Report
JX1KTFsitM.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/JX1KTFsitM.elf
/tmp/JX1KTFsitM.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.uVPj8ZZnc7 /tmp/tmp.nYFAjzZUHo /tmp/tmp.TpafgwzZyt
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.uVPj8ZZnc7 /tmp/tmp.nYFAjzZUHo /tmp/tmp.TpafgwzZyt

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f062801c000
page execute read
malicious
562b6b2b0000
page read and write
7f072f8fc000
page read and write
7f062802c000
page execute and read and write
562b6ec6c000
page read and write
7f0728021000
page read and write
562b6b2a7000
page read and write
562b6b079000
page execute read
7f072ff4d000
page read and write
7f07303e6000
page read and write
7f072f0eb000
page read and write
7f0730433000
page read and write
7fff215fe000
page execute read
7f072ff72000
page read and write
7f072fb8b000
page read and write
7fff215f3000
page read and write
7f07302bd000
page read and write
7f0728000000
page read and write
7f072f8ee000
page read and write
562b6d2c5000
page read and write
562b6d2af000
page execute and read and write
7f07303ee000
page read and write
There are 12 hidden memdumps, click here to show them.