IOC Report
GdfWOGzXow.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/GdfWOGzXow.elf
/tmp/GdfWOGzXow.elf
/tmp/GdfWOGzXow.elf
-
/tmp/GdfWOGzXow.elf
-

URLs

Name
IP
Malicious
http://www.billybobbot.com/crawler/)
unknown
malicious
147.185.221.19:30455
malicious
http://www.baidu.com/search/spider.html)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
147.185.221.19
unknown
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f672802b000
page execute read
malicious
7f672802b000
page execute read
malicious
7f6828021000
page read and write
7f68301a9000
page read and write
7f68301a9000
page read and write
555d03cfb000
page read and write
7f6828021000
page read and write
7ffee5e77000
page execute read
7f682f9a1000
page read and write
7f6827fff000
page read and write
555d0720e000
page read and write
7ffee5e27000
page read and write
555d03cf2000
page read and write
7f683082b000
page read and write
7f683059d000
page read and write
7f6830808000
page read and write
7f683082b000
page read and write
7f6830eec000
page read and write
7f6728039000
page read and write
7f6728033000
page read and write
7f6830eec000
page read and write
7f6827fff000
page read and write
555d03cfb000
page read and write
7f6830e83000
page read and write
7f683023b000
page read and write
7f6728033000
page read and write
555d03cf2000
page read and write
7ffee5e77000
page execute read
7f6830ea7000
page read and write
555d05cf9000
page execute and read and write
555d0720e000
page read and write
7f6830b79000
page read and write
7f6830b79000
page read and write
7f682f9a1000
page read and write
555d03aa1000
page execute read
555d05cf9000
page execute and read and write
555d03aa1000
page execute read
7f6728039000
page read and write
7f6830808000
page read and write
555d05d10000
page read and write
7f6830d5a000
page read and write
7ffee5e27000
page read and write
555d05d10000
page read and write
7f683023b000
page read and write
7f683059d000
page read and write
7f6830ea7000
page read and write
7f6830d5a000
page read and write
7f6830997000
page read and write
7f6830997000
page read and write
7f6830e83000
page read and write
There are 40 hidden memdumps, click here to show them.