IOC Report
QuXveZg4s6.elf

loading gif

Files

File Path
Type
Category
Malicious
QuXveZg4s6.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.Gnv1WU (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/QuXveZg4s6.elf
/tmp/QuXveZg4s6.elf
/tmp/QuXveZg4s6.elf
-
/tmp/QuXveZg4s6.elf
-

URLs

Name
IP
Malicious
91.92.240.85:23
malicious
http://91.92.240.85/bins.sh;
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
91.92.240.85
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f5578fd5000
page read and write
7f5578f88000
page read and write
555cf05c7000
page read and write
555cf25e3000
page read and write
7f5578aef000
page read and write
7f5578fd5000
page read and write
7f5578f90000
page read and write
555cf25e3000
page read and write
555cf05cf000
page read and write
7f5578aef000
page read and write
7f548002d000
page execute and read and write
7ffd8acdf000
page read and write
7f5578f88000
page read and write
7f5480026000
page execute and read and write
7f557849e000
page read and write
555cf05c7000
page read and write
7ffd8add0000
page execute read
7f5480016000
page execute read
7ffd8add0000
page execute read
7f557872d000
page read and write
7f5578e5f000
page read and write
7ffd8acdf000
page read and write
7f5570000000
page read and write
7f5570021000
page read and write
7f5578e5f000
page read and write
555cf35fc000
page read and write
7f5480026000
page execute and read and write
7f548002e000
page read and write
7f5578f90000
page read and write
7f548002d000
page execute and read and write
555cf05cf000
page read and write
7f5570021000
page read and write
7f5578490000
page read and write
7f548002e000
page read and write
555cf0344000
page execute read
7f5480016000
page execute read
7f557872d000
page read and write
555cf25cd000
page execute and read and write
555cf0344000
page execute read
7f5577c8d000
page read and write
555cf35fc000
page read and write
7f5577c8d000
page read and write
7f5578b14000
page read and write
7f5570000000
page read and write
7f557849e000
page read and write
7f5578b14000
page read and write
7f5578490000
page read and write
555cf25cd000
page execute and read and write
There are 38 hidden memdumps, click here to show them.