IOC Report
CITauQKjMd.elf

loading gif

Files

File Path
Type
Category
Malicious
CITauQKjMd.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.IZmX2b (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/CITauQKjMd.elf
/tmp/CITauQKjMd.elf
/tmp/CITauQKjMd.elf
-
/tmp/CITauQKjMd.elf
-

URLs

Name
IP
Malicious
193.35.18.127:19286
malicious
http://www.majestic12.co.uk/bot.php?
unknown
http://majestic12.co.uk/bot.php?
unknown
http://wortschatz.uni-leipzig.de/findlinks/)
unknown
http://code.google.com/appengine;
unknown
http://www.brandwatch.net)
unknown
http://www.mojeek.com/bot.html)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
193.35.18.127
unknown
Germany
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4548037000
page execute read
malicious
7f4548037000
page execute read
malicious
557327a36000
page execute and read and write
7ffcd757b000
page execute read
7f45cffd6000
page read and write
7f45d09a5000
page read and write
557325a30000
page read and write
557325a38000
page read and write
7f45cffe4000
page read and write
7f45d0635000
page read and write
7f45d0ace000
page read and write
7f45cf7d3000
page read and write
7f45d0b1b000
page read and write
7f45d0b1b000
page read and write
7f45cf7d3000
page read and write
7f45d065a000
page read and write
7f45c8000000
page read and write
5573257fe000
page execute read
557329190000
page read and write
7f45d0ace000
page read and write
7f45c8021000
page read and write
7f45d0635000
page read and write
5573257fe000
page execute read
557325a30000
page read and write
7f45d0ad6000
page read and write
557325a38000
page read and write
7f45d0ad6000
page read and write
7f45cffe4000
page read and write
7f4548040000
page read and write
7f45d065a000
page read and write
7ffcd7567000
page read and write
557327a36000
page execute and read and write
7f45cffd6000
page read and write
7f4548040000
page read and write
7ffcd7567000
page read and write
7f45d0273000
page read and write
7f45c8000000
page read and write
557327acd000
page read and write
557327acd000
page read and write
7f45d09a5000
page read and write
7f45c8021000
page read and write
7ffcd757b000
page execute read
557329190000
page read and write
7f45d0273000
page read and write
7f454803a000
page read and write
7f454803a000
page read and write
There are 36 hidden memdumps, click here to show them.