IOC Report
wx6NGH4iz5.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/wx6NGH4iz5.elf
/tmp/wx6NGH4iz5.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Jsum8kwrB4 /tmp/tmp.r9mNQhdtOY /tmp/tmp.eg73ircuuU
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Jsum8kwrB4 /tmp/tmp.r9mNQhdtOY /tmp/tmp.eg73ircuuU

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4d3c026000
page execute read
7f4e44b41000
page read and write
7f4d3c038000
page read and write
7f4e43788000
page read and write
7ffdadee0000
page read and write
7f4d3c02e000
page read and write
7f4e44384000
page read and write
55f15e4ca000
page read and write
7f4e44960000
page read and write
7ffdadf66000
page execute read
55f162048000
page read and write
55f1604e8000
page read and write
7f4e43f90000
page read and write
7f4e44c8e000
page read and write
7f4e445ef000
page read and write
55f1604d1000
page execute and read and write
55f15e4d3000
page read and write
55f15e279000
page execute read
7f4e3c021000
page read and write
7f4e44cd3000
page read and write
7f4e44612000
page read and write
7f4e44c6a000
page read and write
7f4e3bfff000
page read and write
7f4e44022000
page read and write
7f4e4477e000
page read and write
There are 15 hidden memdumps, click here to show them.