IOC Report
SecuriteInfo.com.Linux.Siggen.9999.2998.17754.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/SecuriteInfo.com.Linux.Siggen.9999.2998.17754.elf
/tmp/SecuriteInfo.com.Linux.Siggen.9999.2998.17754.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.FcDnqNnqRH /tmp/tmp.XCl5U1fQ7V /tmp/tmp.kSZXmZgSgz
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.FcDnqNnqRH /tmp/tmp.XCl5U1fQ7V /tmp/tmp.kSZXmZgSgz

URLs

Name
IP
Malicious
http://upx.sf.net
unknown

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4384415000
page execute read
malicious
7f4409b8a000
page read and write
55fa24a39000
page read and write
55fa24966000
page read and write
55fa22947000
page read and write
7ffcbd7e4000
page execute read
7f440b06c000
page read and write
7f440ad62000
page read and write
7f440a3a0000
page read and write
7f4384457000
page read and write
55fa226bf000
page execute read
7ffcbd7da000
page read and write
7f440b074000
page read and write
7f440a650000
page read and write
55fa22951000
page read and write
7f440aa31000
page read and write
7f440af43000
page read and write
7f440a9f1000
page read and write
7f440b0b9000
page read and write
7f4404021000
page read and write
7f4384140000
page execute and read and write
7f440a392000
page read and write
7f440aa14000
page read and write
55fa2494f000
page execute and read and write
7f4404000000
page read and write
There are 15 hidden memdumps, click here to show them.