IOC Report
fwkeLXlthW.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/fwkeLXlthW.elf
/tmp/fwkeLXlthW.elf
/tmp/fwkeLXlthW.elf
-
/tmp/fwkeLXlthW.elf
-
/tmp/fwkeLXlthW.elf
-
/tmp/fwkeLXlthW.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.fFD4gfLXFO /tmp/tmp.QPFGv5zNHi /tmp/tmp.4V1i9LBHGg
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.fFD4gfLXFO /tmp/tmp.QPFGv5zNHi /tmp/tmp.4V1i9LBHGg

URLs

Name
IP
Malicious
http:///curl.sh
unknown

Domains

Name
IP
Malicious
netfags.geek
204.76.203.103

IPs

IP
Domain
Country
Malicious
215.54.79.38
unknown
United States
144.105.67.23
unknown
United States
88.215.40.244
unknown
United Kingdom
81.43.97.158
unknown
Spain
82.212.122.233
unknown
Jordan
2.139.30.114
unknown
Spain
209.172.252.43
unknown
United States
108.74.98.78
unknown
United States
29.0.125.212
unknown
United States
72.96.114.77
unknown
United States
140.64.124.58
unknown
United States
110.105.167.94
unknown
China
142.5.15.102
unknown
Canada
176.166.68.246
unknown
France
150.179.5.22
unknown
United States
190.107.73.125
unknown
Ecuador
23.107.229.36
unknown
United States
136.79.226.115
unknown
United States
21.222.128.196
unknown
United States
43.35.26.239
unknown
Japan
23.48.63.151
unknown
United States
188.126.222.137
unknown
Norway
182.253.111.178
unknown
Indonesia
37.148.164.42
unknown
Netherlands
90.230.68.3
unknown
Sweden
66.8.213.3
unknown
United States
67.128.250.123
unknown
United States
218.71.71.218
unknown
China
119.32.4.19
unknown
China
165.238.94.79
unknown
United States
124.59.35.192
unknown
Korea Republic of
95.145.60.10
unknown
United Kingdom
138.61.193.227
unknown
United States
31.175.178.231
unknown
Poland
3.195.201.246
unknown
United States
214.201.113.48
unknown
United States
210.218.52.187
unknown
Korea Republic of
115.67.138.168
unknown
Thailand
167.121.190.24
unknown
United States
64.217.87.82
unknown
United States
102.164.141.163
unknown
Senegal
92.113.213.64
unknown
Ukraine
50.29.6.128
unknown
United States
125.10.26.12
unknown
Japan
19.113.76.234
unknown
United States
70.55.215.180
unknown
Canada
199.238.2.219
unknown
United States
147.218.244.229
unknown
United States
40.127.230.139
unknown
United States
20.92.204.238
unknown
United States
35.231.129.119
unknown
United States
188.2.197.83
unknown
Serbia
160.48.38.0
unknown
Germany
137.95.37.249
unknown
United States
168.127.110.32
unknown
United States
153.117.26.95
unknown
United States
24.136.239.25
unknown
United States
213.149.148.141
unknown
Bulgaria
206.151.212.211
unknown
United States
14.56.65.131
unknown
Korea Republic of
115.211.231.240
unknown
China
189.211.105.23
unknown
Mexico
47.110.97.152
unknown
China
84.83.58.102
unknown
Netherlands
155.34.103.71
unknown
United States
9.139.112.62
unknown
United States
135.68.150.40
unknown
United States
145.188.155.114
unknown
Netherlands
141.121.70.26
unknown
United States
102.85.176.131
unknown
Uganda
155.161.167.64
unknown
United States
45.40.237.75
unknown
China
99.40.245.223
unknown
United States
189.215.217.227
unknown
Mexico
89.160.178.106
unknown
Iceland
34.117.172.118
unknown
United States
28.47.248.3
unknown
United States
107.179.162.139
unknown
Canada
167.163.139.80
unknown
United States
24.2.247.120
unknown
United States
197.8.143.204
unknown
Tunisia
138.142.32.223
unknown
United States
129.192.94.145
unknown
United States
198.102.122.231
unknown
United States
63.150.171.147
unknown
United States
195.90.130.149
unknown
Russian Federation
170.165.80.36
unknown
Singapore
49.37.225.6
unknown
India
91.139.32.95
unknown
Czech Republic
78.236.83.125
unknown
France
189.241.215.78
unknown
Mexico
203.123.218.189
unknown
Korea Republic of
117.34.26.25
unknown
China
198.180.237.144
unknown
United States
131.154.145.175
unknown
Italy
32.96.234.6
unknown
United States
56.41.250.185
unknown
United States
110.189.104.58
unknown
China
6.82.23.187
unknown
United States
94.221.71.144
unknown
Germany
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
fffe6000
page read and write
8058000
page read and write
8056000
page execute read
901f000
page read and write
fffe6000
page read and write
901f000
page read and write
8057000
page read and write
f7fb2000
page execute read
8057000
page read and write
8058000
page read and write
9020000
page read and write
f7fb2000
page execute read
8056000
page execute read
There are 3 hidden memdumps, click here to show them.