IOC Report
MqFwPcgsJ6.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/MqFwPcgsJ6.elf
/tmp/MqFwPcgsJ6.elf

URLs

Name
IP
Malicious
http://103.174.73.190/tajma.mpsl;
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3cf042c000
page execute read
malicious
7f3d7734b000
page read and write
564deaf4e000
page read and write
7fff9d7b3000
page read and write
7f3d75e1c000
page read and write
7f3d76632000
page read and write
7f3d76624000
page read and write
7f3d76c83000
page read and write
7f3d70021000
page read and write
564decf4c000
page execute and read and write
7f3d70000000
page read and write
7f3d771d5000
page read and write
7f3d76cc3000
page read and write
564deaf44000
page read and write
7f3cf0471000
page read and write
564decf63000
page read and write
7f3d77306000
page read and write
7f3d76ff4000
page read and write
7f3d76ca6000
page read and write
7fff9d7c6000
page execute read
564dee38f000
page read and write
564deacbc000
page execute read
7f3d768e2000
page read and write
7f3d772fe000
page read and write
There are 14 hidden memdumps, click here to show them.