IOC Report
AIFbR8t1fj.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/AIFbR8t1fj.elf
/tmp/AIFbR8t1fj.elf
/tmp/AIFbR8t1fj.elf
-
/tmp/AIFbR8t1fj.elf
-

URLs

Name
IP
Malicious
91.92.240.85:23
malicious
http://91.92.240.85/bins.sh;
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
91.92.240.85
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffe21d46000
page read and write
7f65000e7000
page read and write
55e199f88000
page read and write
7f6500376000
page read and write
7f6500c1e000
page read and write
55e19b335000
page read and write
7f6500738000
page read and write
7f64f8021000
page read and write
55e199f88000
page read and write
7f6478423000
page read and write
55e19b335000
page read and write
7f6500738000
page read and write
7f64ff8d6000
page read and write
7f647842b000
page read and write
7f65000d9000
page read and write
7f650075d000
page read and write
55e197f73000
page read and write
7f6500aa8000
page read and write
7f6478413000
page execute read
7f65000e7000
page read and write
7f64f8000000
page read and write
7f6478423000
page read and write
7f6500376000
page read and write
7f6500bd9000
page read and write
55e197f6b000
page read and write
55e199f71000
page execute and read and write
55e197d55000
page execute read
55e197f73000
page read and write
7f64f8021000
page read and write
7f647842b000
page read and write
7ffe21d94000
page execute read
7f6500aa8000
page read and write
55e197d55000
page execute read
7f6500bd1000
page read and write
7f6478413000
page execute read
7ffe21d46000
page read and write
7f6500c1e000
page read and write
7f6500bd9000
page read and write
55e199f71000
page execute and read and write
7f64ff8d6000
page read and write
7f65000d9000
page read and write
55e197f6b000
page read and write
7ffe21d94000
page execute read
7f650075d000
page read and write
7f64f8000000
page read and write
7f6500bd1000
page read and write
There are 36 hidden memdumps, click here to show them.