IOC Report

loading gif

Files

File Path
Type
Category
Malicious
UnHAnaAW.x86
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/cache/motd-news
ASCII text
dropped
clean

Processes

Path
Cmdline
Malicious
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.zD6SFGNQb7
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.zD6SFGNQb7
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/rm
rm -f /tmp/tmp.zD6SFGNQb7 /tmp/tmp.MPIRMYR9iI /tmp/tmp.rMRfKpgfLJ
clean
/tmp/UnHAnaAW.x86
/tmp/UnHAnaAW.x86
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
/tmp/UnHAnaAW.x86
n/a
clean
There are 18 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://95.181.161.119/bins/x86
unknown
clean
http://schemas.xmlsoap.org/soap/encoding/
unknown
clean
http://95.181.161.119/zyxel.sh;
unknown
clean
https://ubuntu.com/blog/microk8s-memory-optimisation
unknown
clean
http://192.168.0.14:80/cgi-bin/ViewLog.asp
95.214.234.102
clean
http://schemas.xmlsoap.org/soap/envelope/
unknown
clean

IPs

IP
Domain
Country
Malicious
183.162.114.95
unknown
China
clean
41.143.204.132
unknown
Morocco
clean
94.81.248.212
unknown
Italy
clean
85.108.172.24
unknown
Turkey
clean
32.108.18.108
unknown
United States
clean
159.210.217.171
unknown
Italy
clean
128.246.74.142
unknown
Germany
clean
85.246.119.54
unknown
Portugal
clean
95.215.48.43
unknown
Ukraine
clean
94.64.142.135
unknown
Greece
clean
205.9.96.150
unknown
United States
clean
161.172.49.137
unknown
United States
clean
31.199.232.10
unknown
Italy
clean
31.100.145.19
unknown
United Kingdom
clean
85.124.31.216
unknown
Austria
clean
95.51.134.80
unknown
Poland
clean
176.252.26.170
unknown
United Kingdom
clean
197.120.220.111
unknown
Egypt
clean
85.157.241.243
unknown
Finland
clean
85.50.194.182
unknown
Spain
clean
31.59.81.101
unknown
Iran (ISLAMIC Republic Of)
clean
112.252.196.37
unknown
China
clean
207.197.18.234
unknown
United States
clean
85.140.83.179
unknown
Russian Federation
clean
220.116.183.170
unknown
Korea Republic of
clean
94.171.13.63
unknown
Netherlands
clean
62.68.231.179
unknown
Egypt
clean
173.214.157.199
unknown
United States
clean
95.217.66.167
unknown
Germany
clean
112.80.112.4
unknown
China
clean
85.119.64.1
unknown
Turkey
clean
112.168.231.13
unknown
Korea Republic of
clean
48.64.241.50
unknown
United States
clean
62.44.89.188
unknown
United Kingdom
clean
85.218.240.62
unknown
Denmark
clean
85.251.57.32
unknown
Spain
clean
171.226.193.180
unknown
Viet Nam
clean
41.206.191.242
unknown
South Africa
clean
31.220.220.243
unknown
United Kingdom
clean
205.162.203.241
unknown
United States
clean
157.121.78.209
unknown
United States
clean
85.112.35.33
unknown
Russian Federation
clean
94.8.166.137
unknown
United Kingdom
clean
197.252.76.136
unknown
Sudan
clean
95.24.169.220
unknown
Russian Federation
clean
85.196.204.174
unknown
Estonia
clean
94.67.223.113
unknown
Greece
clean
64.157.90.134
unknown
United States
clean
85.205.176.70
unknown
Germany
clean
85.206.15.28
unknown
Lithuania
clean
95.28.117.17
unknown
Russian Federation
clean
94.224.166.163
unknown
Belgium
clean
31.14.164.20
unknown
Syrian Arab Republic
clean
95.51.134.96
unknown
Poland
clean
41.245.154.150
unknown
Nigeria
clean
62.39.77.39
unknown
France
clean
62.40.187.78
unknown
Austria
clean
197.103.64.230
unknown
South Africa
clean
156.115.143.157
unknown
Switzerland
clean
136.21.200.189
unknown
United States
clean
31.91.17.4
unknown
United Kingdom
clean
31.161.195.254
unknown
Netherlands
clean
85.64.123.38
unknown
Israel
clean
94.85.243.31
unknown
Italy
clean
212.8.62.189
unknown
Ukraine
clean
95.215.48.60
unknown
Ukraine
clean
95.94.139.71
unknown
Portugal
clean
94.94.61.76
unknown
Italy
clean
146.55.160.218
unknown
United States
clean
31.46.162.107
unknown
Hungary
clean
90.27.204.130
unknown
France
clean
95.111.20.237
unknown
Bulgaria
clean
62.153.147.111
unknown
Germany
clean
31.143.175.13
unknown
Turkey
clean
104.204.57.212
unknown
United States
clean
157.37.178.135
unknown
India
clean
31.66.126.243
unknown
United Kingdom
clean
104.62.108.192
unknown
United States
clean
112.91.103.34
unknown
China
clean
62.235.224.87
unknown
Belgium
clean
107.10.100.22
unknown
United States
clean
38.199.28.199
unknown
United States
clean
167.171.172.39
unknown
United States
clean
184.105.254.45
unknown
United States
clean
78.141.232.146
unknown
Netherlands
clean
94.175.48.233
unknown
United Kingdom
clean
197.173.180.16
unknown
South Africa
clean
216.28.163.240
unknown
United States
clean
88.189.112.235
unknown
France
clean
39.199.223.197
unknown
Indonesia
clean
88.139.140.68
unknown
France
clean
31.61.72.78
unknown
Poland
clean
62.202.185.171
unknown
Switzerland
clean
95.205.130.87
unknown
Sweden
clean
84.188.59.213
unknown
Germany
clean
99.10.28.94
unknown
United States
clean
78.141.232.150
unknown
Netherlands
clean
94.42.225.74
unknown
Poland
clean
31.137.99.217
unknown
Netherlands
clean
157.184.0.159
unknown
United States
clean
There are 90 hidden IPs, click here to show them.