IOCReport

loading gif

Files

File Path
Type
Category
Malicious
Mozi.m
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/crash/_usr_share_apport_apport-checkreports.1000.crash
ASCII text
dropped
clean
/var/crash/_usr_share_apport_apport-gtk.1000.crash
ASCII text
dropped
clean

Processes

Path
Cmdline
Malicious
/tmp/Mozi.m
/usr/bin/qemu-mips /tmp/Mozi.m
clean
/sbin/upstart
n/a
clean
/bin/sh
/bin/sh -e /proc/self/fd/9
clean
/bin/sh
n/a
clean
/bin/date
date
clean
/bin/sh
n/a
clean
/usr/share/apport/apport-checkreports
/usr/bin/python3 /usr/share/apport/apport-checkreports --system
clean
/sbin/upstart
n/a
clean
/bin/sh
/bin/sh -e /proc/self/fd/9
clean
/bin/sh
n/a
clean
/bin/date
date
clean
/bin/sh
n/a
clean
/usr/share/apport/apport-gtk
/usr/bin/python3 /usr/share/apport/apport-gtk
clean
/sbin/upstart
n/a
clean
/bin/sh
/bin/sh -e /proc/self/fd/9
clean
/bin/sh
n/a
clean
/bin/date
date
clean
/bin/sh
n/a
clean
/usr/share/apport/apport-gtk
/usr/bin/python3 /usr/share/apport/apport-gtk
clean
There are 9 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://%s:%d/bin.sh;chmod
unknown
malicious
http://%s:%d/Mozi.m;/tmp/Mozi.m
unknown
malicious
http://%s:%d/bin.sh
unknown
malicious
http://%s:%d/Mozi.m;
unknown
malicious
http://%s:%d/Mozi.m;$
unknown
malicious
http://%s:%d/Mozi.m
unknown
malicious
http://ipinfo.io/ip
unknown
clean
http://%s:%d/Mozi.a;chmod
unknown
clean
http://schemas.xmlsoap.org/soap/encoding/
unknown
clean
http://purenetworks.com/HNAP1/
unknown
clean
http://schemas.xmlsoap.org/soap/envelope/
unknown
clean
http://upx.sf.net
unknown
clean
http://HTTP/1.1
unknown
clean
http://%s:%d/Mozi.a;sh$
unknown
clean
http://127.0.0.1
unknown
clean
http://baidu.com/%s/%s/%d/%s/%s/%s/%s)
unknown
clean
http://schemas.xmlsoap.org/soap/envelope//
unknown
clean
http://127.0.0.1sendcmd
unknown
clean
There are 8 hidden URLs, click here to show them.