IOC Report
95O08zY2Tm.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Io4EEZFj12 /tmp/tmp.RsAqjhlGOn /tmp/tmp.hS8GqpGKMP
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.Io4EEZFj12
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.Io4EEZFj12
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Io4EEZFj12 /tmp/tmp.RsAqjhlGOn /tmp/tmp.hS8GqpGKMP
/tmp/95O08zY2Tm.elf
/tmp/95O08zY2Tm.elf
/tmp/95O08zY2Tm.elf
-
/tmp/95O08zY2Tm.elf
-
There are 13 hidden processes, click here to show them.

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
2.58.95.131
unknown
Germany
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
612000
page read and write
7ffd9ac25000
page read and write
612000
page read and write
410000
page execute read
619000
page read and write
7ffd9ac7c000
page execute read
7ffd9ac25000
page read and write
7ffd9ac7c000
page execute read
619000
page read and write
410000
page execute read