IOC Report
fsa.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/fsa.elf
/tmp/fsa.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.eaYG9ch38r /tmp/tmp.qhU28QogYd /tmp/tmp.gr2Bn6czuc
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.eaYG9ch38r
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.eaYG9ch38r
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.eaYG9ch38r /tmp/tmp.qhU28QogYd /tmp/tmp.gr2Bn6czuc
There are 11 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
http://127.0.0.1:8080
unknown

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f8fc9912000
page read and write
c000400000
page read and write
7f8fc6cf6000
page read and write
7ffe327d6000
page execute read
7f8fc90cc000
page read and write
ad4000
page execute read
7f8fc99f1000
page read and write
7f8fb4e46000
page read and write
7f8fa4cc5000
page read and write
7ffe327c3000
page read and write
7f8fc9891000
page read and write
19b0000
page read and write
There are 2 hidden memdumps, click here to show them.