IOC Report
1lkozpLZNX.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/1lkozpLZNX.elf
/tmp/1lkozpLZNX.elf
/tmp/1lkozpLZNX.elf
-
/tmp/1lkozpLZNX.elf
-
/tmp/1lkozpLZNX.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.uvmvl1JYZ6 /tmp/tmp.eijiQvLH2y /tmp/tmp.t8nL1FlxFk
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.uvmvl1JYZ6
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.uvmvl1JYZ6
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.uvmvl1JYZ6 /tmp/tmp.eijiQvLH2y /tmp/tmp.t8nL1FlxFk
There are 14 hidden processes, click here to show them.

Domains

Name
IP
Malicious
jhbaghjbasdg.shop
185.196.8.213
malicious

IPs

IP
Domain
Country
Malicious
185.196.8.213
jhbaghjbasdg.shop
Switzerland
malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f88acc6b000
page read and write
563c922f6000
page execute read
7f88ad1c0000
page read and write
7ffc652f2000
page read and write
7f87a402d000
page execute read
7f88ac871000
page read and write
7f88abc75000
page read and write
7f88abc75000
page read and write
7f87a4038000
page read and write
563c92547000
page read and write
7f88ac50f000
page read and write
7f88acaff000
page read and write
7f88acaff000
page read and write
7f88ace4d000
page read and write
7ffc653c5000
page execute read
7f87a402d000
page execute read
7ffc652f2000
page read and write
7f88ace4d000
page read and write
563c92550000
page read and write
563c9454e000
page execute and read and write
7f88ac47d000
page read and write
7f88ac50f000
page read and write
7f88a3fff000
page read and write
563c94565000
page read and write
7f88acadc000
page read and write
7f88ad02e000
page read and write
7f88ac47d000
page read and write
7f88ad17b000
page read and write
7f88a3fff000
page read and write
7ffc653c5000
page execute read
7f88a4021000
page read and write
563c92547000
page read and write
563c94565000
page read and write
7f88ad157000
page read and write
563c9583a000
page read and write
7f88acadc000
page read and write
563c9454e000
page execute and read and write
563c9583a000
page read and write
7f88ad17b000
page read and write
7f88ac871000
page read and write
563c92550000
page read and write
7f88ad1c0000
page read and write
7f88a4021000
page read and write
7f88acc6b000
page read and write
563c922f6000
page execute read
7f87a4038000
page read and write
7f88ad02e000
page read and write
7f88ad157000
page read and write
7f87a4035000
page read and write
7f87a4035000
page read and write
There are 40 hidden memdumps, click here to show them.