IOC Report
ARMV4L.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/ARMV4L.elf
/tmp/ARMV4L.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.e4l7OIZOzN /tmp/tmp.fY8Qp3PLd9 /tmp/tmp.Iur8H9u9s8
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.e4l7OIZOzN
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.e4l7OIZOzN
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.e4l7OIZOzN /tmp/tmp.fY8Qp3PLd9 /tmp/tmp.Iur8H9u9s8
There are 11 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ff25462c000
page read and write
7ff2545c3000
page read and write
7ff14c020000
page execute read
560994bcd000
page execute read
7ff2540d7000
page read and write
7ff24c021000
page read and write
7ffc2218d000
page read and write
7ff24b7fe000
page read and write
7ff2530e1000
page read and write
7ff14c038000
page read and write
560996e3c000
page read and write
7ffc221fd000
page execute read
7ff2545e7000
page read and write
7ff253f48000
page read and write
560998c9d000
page read and write
7ff2542b9000
page read and write
7ff253cdd000
page read and write
7ff25449a000
page read and write
560994e27000
page read and write
7ff253f6b000
page read and write
560994e1e000
page read and write
7ff2538e9000
page read and write
7ff25397b000
page read and write
560996e25000
page execute and read and write
7ff24bfff000
page read and write
There are 15 hidden memdumps, click here to show them.