IOC Report
BQBkS6XgmA.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/BQBkS6XgmA.elf
/tmp/BQBkS6XgmA.elf
/tmp/BQBkS6XgmA.elf
-
/tmp/BQBkS6XgmA.elf
-
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 21e3a5141-81ff-45e8-a564-651b5b7002ba
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 21e3a5141-81ff-45e8-a564-651b5b7002ba
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 21e3a5141-81ff-45e8-a564-651b5b7002ba
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 21e3a5141-81ff-45e8-a564-651b5b7002ba
/usr/bin/xfce4-session
-
/usr/bin/xfdesktop
xfdesktop --display :1.0 --sm-client-id 21e3a5141-81ff-45e8-a564-651b5b7002ba
There are 3 hidden processes, click here to show them.

Domains

Name
IP
Malicious
aomacamada.ddns.net
203.145.46.240
malicious
net-killer.ddns.net
203.145.46.240
malicious
net-killer.ooguy.com
203.145.46.240
malicious
aomacamada.ddns.net. [malformed]
unknown
malicious
net-killer.ooguy.com. [malformed]
unknown
malicious
net-killer.ddns.net. [malformed]
unknown
malicious
Vet-killer.io.v. [malformed]
unknown
malicious
domain-botnet.servehttp.com
51.79.217.59

IPs

IP
Domain
Country
Malicious
203.145.46.240
aomacamada.ddns.net
unknown
malicious
51.79.217.59
domain-botnet.servehttp.com
Canada

Memdumps

Base Address
Regiontype
Protect
Malicious
8067000
page read and write
f7fe8000
page execute read
95f2000
page read and write
ff9bb000
page read and write
95f2000
page read and write
8063000
page read and write
ff9bb000
page read and write
805e000
page execute read
f7fe8000
page execute read
8063000
page read and write
8067000
page read and write
805e000
page execute read
There are 2 hidden memdumps, click here to show them.