IOC Report
ij5Z8oy5e3.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/ij5Z8oy5e3.elf
/tmp/ij5Z8oy5e3.elf
/tmp/ij5Z8oy5e3.elf
-
/tmp/ij5Z8oy5e3.elf
-
/tmp/ij5Z8oy5e3.elf
-
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 260d40b3c-9c6a-4cb1-bbe4-3557725aa528
There are 4 hidden processes, click here to show them.

Domains

Name
IP
Malicious
aomacamada.ddns.net
203.145.46.240
malicious
net-killer.ddns.net
203.145.46.240
malicious
net-killer.ooguy.com
203.145.46.240
malicious
aomacamada.ddns.net. [malformed]
unknown
malicious
net-killer.ooguy.com. [malformed]
unknown
malicious
net-killer.ddns.net. [malformed]
unknown
malicious
Vet-killer.io.v. [malformed]
unknown
malicious
domain-botnet.servehttp.com
51.79.217.59

IPs

IP
Domain
Country
Malicious
203.145.46.240
aomacamada.ddns.net
unknown
malicious
51.79.217.59
domain-botnet.servehttp.com
Canada

Memdumps

Base Address
Regiontype
Protect
Malicious
ff946000
page read and write
f7f47000
page execute read
8064000
page read and write
8060000
page read and write
8064000
page read and write
9a55000
page read and write
805b000
page execute read
9a55000
page read and write
f7f47000
page execute read
805b000
page execute read
8060000
page read and write
ff946000
page read and write
There are 2 hidden memdumps, click here to show them.