IOC Report
XooIXdKFaW.elf

loading gif

Files

File Path
Type
Category
Malicious
XooIXdKFaW.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.4EuFNk (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/XooIXdKFaW.elf
/tmp/XooIXdKFaW.elf
/tmp/XooIXdKFaW.elf
-
/tmp/XooIXdKFaW.elf
-

URLs

Name
IP
Malicious
91.92.240.85:23
malicious
http://91.92.240.85/bins.sh;
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
91.92.240.85
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
56067dece000
page read and write
7f04938cb000
page read and write
7ffd64150000
page read and write
7f048c021000
page read and write
7f048c021000
page read and write
7ffd64150000
page read and write
7f0493d6c000
page read and write
7f0493c3b000
page read and write
7f04938f0000
page read and write
56067a403000
page read and write
7f040c01f000
page read and write
56067c4a0000
page read and write
56067dece000
page read and write
7f0493509000
page read and write
56067c4a0000
page read and write
56067a40b000
page read and write
7f0493509000
page read and write
56067c409000
page execute and read and write
7ffd641ee000
page execute read
7f040c016000
page execute read
7f04938cb000
page read and write
7f040c018000
page read and write
7f040c016000
page execute read
56067c409000
page execute and read and write
7f049327a000
page read and write
7f049326c000
page read and write
56067a1d1000
page execute read
7f040c01f000
page read and write
7f0493d64000
page read and write
7f048c000000
page read and write
7f0493db1000
page read and write
7f040c018000
page read and write
7f0493db1000
page read and write
7f0492a69000
page read and write
7f0493d64000
page read and write
7f0492a69000
page read and write
7f048c000000
page read and write
7f04938f0000
page read and write
7f049326c000
page read and write
7f049327a000
page read and write
56067a40b000
page read and write
56067a403000
page read and write
56067a1d1000
page execute read
7ffd641ee000
page execute read
7f0493c3b000
page read and write
7f0493d6c000
page read and write
There are 36 hidden memdumps, click here to show them.