IOC Report
bNfT1T8DVz.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/bNfT1T8DVz.elf
/tmp/bNfT1T8DVz.elf
/tmp/bNfT1T8DVz.elf
-
/tmp/bNfT1T8DVz.elf
-
/usr/lib/systemd/systemd
-
/usr/lib/snapd/snap-failure
/usr/lib/snapd/snap-failure snapd
/usr/lib/snapd/snap-failure
-
/usr/bin/systemctl
systemctl stop snapd.socket
/usr/lib/snapd/snap-failure
-

Domains

Name
IP
Malicious
netfags.geek
5.181.80.59

IPs

IP
Domain
Country
Malicious
5.181.80.140
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
560e7efd6000
page read and write
7f104dff6000
page read and write
7f0f48023000
page execute read
7f104e3ea000
page read and write
7f104e678000
page read and write
7ffdaee88000
page read and write
7ffdaef88000
page execute read
7f104ecd0000
page read and write
7f104e9c6000
page read and write
7f104e088000
page read and write
7f104e7e4000
page read and write
7f104ecf4000
page read and write
560e80fd4000
page execute and read and write
7f104ed39000
page read and write
560e7efcd000
page read and write
7f0f4802b000
page read and write
7f104e655000
page read and write
7f104eba7000
page read and write
7f1047fff000
page read and write
7f104d7ee000
page read and write
560e80feb000
page read and write
7f0f4802c000
page read and write
560e81cae000
page read and write
7f1048021000
page read and write
560e7ed7c000
page execute read
There are 15 hidden memdumps, click here to show them.