IOC Report
rfixnaMj52.elf

loading gif

Files

File Path
Type
Category
Malicious
rfixnaMj52.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.z1piFU (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/rfixnaMj52.elf
/tmp/rfixnaMj52.elf
/tmp/rfixnaMj52.elf
n/a
/tmp/rfixnaMj52.elf
n/a

URLs

Name
IP
Malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

IPs

IP
Domain
Country
Malicious
31.214.243.29
unknown
Germany
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom