IOC Report
SecuriteInfo.com.Linux.Themoon.19.12839.496.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/SecuriteInfo.com.Linux.Themoon.19.12839.496.elf
/tmp/SecuriteInfo.com.Linux.Themoon.19.12839.496.elf

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f730401e000
page execute read
55ffa9fa4000
page read and write
7ffea493c000
page read and write
7f740c70f000
page read and write
7f740c39c000
page read and write
55ffabfac000
page execute and read and write
7f740c6ca000
page read and write
55ffacc01000
page read and write
7f740c02b000
page read and write
7f740ba5e000
page read and write
7f740bdc0000
page read and write
7f740c1ba000
page read and write
55ffabfc2000
page read and write
7f740b9cc000
page read and write
7f7404021000
page read and write
7f740c6a6000
page read and write
7f740b1c4000
page read and write
7f7403fff000
page read and write
55ffa9d53000
page execute read
55ffa9fad000
page read and write
7f740c57d000
page read and write
7f730402a000
page read and write
7f740c04e000
page read and write
7ffea4943000
page execute read
There are 14 hidden memdumps, click here to show them.