IOC Report
4GtFbR4O3j.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/4GtFbR4O3j.elf
/tmp/4GtFbR4O3j.elf
/tmp/4GtFbR4O3j.elf
-
/tmp/4GtFbR4O3j.elf
-
/tmp/4GtFbR4O3j.elf
-
/tmp/4GtFbR4O3j.elf
-

Domains

Name
IP
Malicious
servernoworky.geek
94.156.248.18

IPs

IP
Domain
Country
Malicious
94.156.248.19
unknown
Bulgaria

Memdumps

Base Address
Regiontype
Protect
Malicious
7f57a4039000
page execute read
malicious
7f57a4039000
page execute read
malicious
7f58aaf3c000
page read and write
7ffeca76c000
page execute read
7f58a4021000
page read and write
55a12201a000
page execute read
7f58ab822000
page read and write
7ffeca712000
page read and write
7ffeca76c000
page execute read
55a124289000
page read and write
7f58ab88b000
page read and write
7f58ab518000
page read and write
55a122274000
page read and write
55a12226b000
page read and write
7f58ab336000
page read and write
7f58aab48000
page read and write
7ffeca712000
page read and write
55a124272000
page execute and read and write
7f58a3fff000
page read and write
7f58ab1ca000
page read and write
7f58aa340000
page read and write
7f58a3fff000
page read and write
7f58ab6f9000
page read and write
7f58ab336000
page read and write
7f58aabda000
page read and write
7f58ab846000
page read and write
55a124272000
page execute and read and write
7f58ab518000
page read and write
7f58ab6f9000
page read and write
7f58ab1ca000
page read and write
55a122274000
page read and write
7f58ab822000
page read and write
7f58a4021000
page read and write
7f58aaf3c000
page read and write
7f57a4054000
page read and write
7f58aa340000
page read and write
7f58aab48000
page read and write
7f58ab1a7000
page read and write
7f57a4056000
page read and write
7f58ab1a7000
page read and write
7f58ab88b000
page read and write
7f57a4046000
page read and write
7f58ab846000
page read and write
55a125dd5000
page read and write
55a124289000
page read and write
7f57a4054000
page read and write
55a12226b000
page read and write
7f58aabda000
page read and write
55a12201a000
page execute read
7f57a4046000
page read and write
55a125dd5000
page read and write
There are 41 hidden memdumps, click here to show them.