IOC Report
bezWhgH7DL.elf

loading gif

Files

File Path
Type
Category
Malicious
bezWhgH7DL.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.WtO6PH (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/bezWhgH7DL.elf
/tmp/bezWhgH7DL.elf
/tmp/bezWhgH7DL.elf
-
/tmp/bezWhgH7DL.elf
-
/tmp/bezWhgH7DL.elf
-
/tmp/bezWhgH7DL.elf
-

Domains

Name
IP
Malicious
minuoddos.top
91.92.244.58
malicious

IPs

IP
Domain
Country
Malicious
91.92.244.58
minuoddos.top
Bulgaria
malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f5f4de18000
page read and write
5647ddf66000
page read and write
7f5f4e28c000
page read and write
7f5f4ddf3000
page read and write
5647ddf4f000
page execute and read and write
7f5f4d794000
page read and write
7f5f4e294000
page read and write
7f5e48021000
page execute read
5647ddf4f000
page execute and read and write
5647dbd1a000
page execute read
7f5f4da31000
page read and write
7f5f4d794000
page read and write
7f5f4d7a2000
page read and write
7f5f4de18000
page read and write
7f5f4e2d9000
page read and write
7f5f4ddf3000
page read and write
7f5f4ddf3000
page read and write
7f5f4d794000
page read and write
7f5e48023000
page read and write
7ffcf99f6000
page execute read
5647ddf66000
page read and write
5647ddf4f000
page execute and read and write
5647dbf48000
page read and write
5647dbf51000
page read and write
7f5e48023000
page read and write
7f5f4e163000
page read and write
7f5f4d7a2000
page read and write
7f5e48021000
page execute read
7f5f48021000
page read and write
7ffcf99f6000
page execute read
7f5f48021000
page read and write
5647ded12000
page read and write
7f5f4e294000
page read and write
7f5f48021000
page read and write
7f5f48000000
page read and write
7f5e48022000
page read and write
7f5e48023000
page read and write
7f5f4e2d9000
page read and write
7f5e48022000
page read and write
7f5f4d7a2000
page read and write
7ffcf99f6000
page execute read
7f5e48022000
page read and write
7f5f4e2d9000
page read and write
7ffcf99e8000
page read and write
7f5f4de18000
page read and write
7f5f4cf91000
page read and write
7f5f4da31000
page read and write
7f5f4e163000
page read and write
5647ded12000
page read and write
7f5f4cf91000
page read and write
7f5f4e163000
page read and write
7f5f4da31000
page read and write
5647ded12000
page read and write
7f5f4e28c000
page read and write
5647dbf48000
page read and write
5647dbf51000
page read and write
7ffcf99e8000
page read and write
5647ddf66000
page read and write
7f5e48021000
page execute read
7ffcf99e8000
page read and write
7f5f4e28c000
page read and write
5647dbf48000
page read and write
7f5f4cf91000
page read and write
5647dbf51000
page read and write
5647dbd1a000
page execute read
7f5f4e294000
page read and write
5647dbd1a000
page execute read
7f5f48000000
page read and write
7f5f48000000
page read and write
There are 59 hidden memdumps, click here to show them.