IOC Report
JU8juw0kr0.elf

loading gif

Files

File Path
Type
Category
Malicious
JU8juw0kr0.elf
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.TsJKJG (deleted)
data
dropped

Processes

Path
Cmdline
Malicious
/tmp/JU8juw0kr0.elf
/tmp/JU8juw0kr0.elf
/tmp/JU8juw0kr0.elf
-
/tmp/JU8juw0kr0.elf
-
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
/usr/libexec/gsd-rfkill
/usr/libexec/gsd-rfkill
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-hostnamed
/lib/systemd/systemd-hostnamed

Domains

Name
IP
Malicious
cnc.voidnet.click
94.156.79.77
malicious
cnc.voidnet.click.'fNT66a/PV!E(&:?5)I'fTNNPV!a/E@.@@y5,br)I
unknown
malicious
cnc.voidnet.click.'fJJPV!a/E<V@@+Y5p('f66
unknown
malicious
cnc.voidnet.click.'f66a/PV!E(t:5r)I'fNNPV!a/E@
unknown
malicious
cnc.voidnet.click.'fx66a/PV!E(bBj>5)I'fNNPV!a/E@.@@y
unknown
malicious
cnc.voidnet.click.'f66a/PV!E(lj5)I'fNNPV!a/E@.@@y.5,a
unknown
malicious

IPs

IP
Domain
Country
Malicious
94.156.79.77
cnc.voidnet.click
Bulgaria
malicious
89.190.156.145
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
5561668da000
page execute read
7efefee52000
page read and write
7efeffcb9000
page read and write
7efeffe48000
page read and write
7eff0039d000
page read and write
7efef8021000
page read and write
556166b34000
page read and write
7efdf8029000
page execute read
7efdf8035000
page read and write
7ffdcd3ec000
page read and write
556168b49000
page read and write
7eff00334000
page read and write
7eff00358000
page read and write
7efeffcdc000
page read and write
7ffdcd3f0000
page execute read
556166b2b000
page read and write
55616a049000
page read and write
7efeffa4e000
page read and write
7efdf8032000
page read and write
7efeff6ec000
page read and write
7eff0020b000
page read and write
7eff0002a000
page read and write
556168b32000
page execute and read and write
7efef7fff000
page read and write
7efeff65a000
page read and write
There are 15 hidden memdumps, click here to show them.