IOC Report
8awpc7GpMh.elf

loading gif

Files

File Path
Type
Category
Malicious
8awpc7GpMh.elf
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.4zRZeD (deleted)
data
dropped

Processes

Path
Cmdline
Malicious
/tmp/8awpc7GpMh.elf
/tmp/8awpc7GpMh.elf
/tmp/8awpc7GpMh.elf
-
/tmp/8awpc7GpMh.elf
-
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
/usr/libexec/gsd-rfkill
/usr/libexec/gsd-rfkill
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-hostnamed
/lib/systemd/systemd-hostnamed

Domains

Name
IP
Malicious
cnc.voidnet.click
94.156.79.77
malicious
cnc.voidnet.click.''f66PV,PV!E(9(w5#Fw%''fNNPV!PV,E@
unknown
malicious
cnc.voidnet.click.''f<66PV,PV!E(nj5?H[%''fNNPV!PV,E@
unknown
malicious
cnc.voidnet.click.''fhi66PV,PV!E(Pj,52$h%''fiNNPV!PV,E@
unknown
malicious
cnc.voidnet.click.''fT66PV,PV!E(*jR5W%''fmJJPV!PV,E<
unknown
malicious
cnc.voidnet.click.''f466PV,PV!E(:Y5W+C%''fh5NNPV!PV,E@
unknown
malicious

IPs

IP
Domain
Country
Malicious
94.156.79.77
cnc.voidnet.click
Bulgaria
malicious
109.202.202.202
unknown
Switzerland
89.190.156.145
unknown
United Kingdom
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffe4d67d000
page read and write
563374f07000
page execute and read and write
7fc51ffff000
page read and write
563372f00000
page read and write
7fc520021000
page read and write
7fc52946e000
page read and write
7fc5294d7000
page read and write
7fc528e16000
page read and write
7fc528b88000
page read and write
563374f1e000
page read and write
7fc528826000
page read and write
7fc42002a000
page execute read
7fc528f82000
page read and write
7fc529492000
page read and write
7fc529345000
page read and write
563376180000
page read and write
7ffe4d6a7000
page execute read
7fc529164000
page read and write
7fc528794000
page read and write
563372caf000
page execute read
7fc420032000
page read and write
7fc527f8c000
page read and write
563372f09000
page read and write
7fc528df3000
page read and write
7fc420035000
page read and write
There are 15 hidden memdumps, click here to show them.