IOC Report
XcDUbJG404.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/XcDUbJG404.elf
/tmp/XcDUbJG404.elf
/tmp/XcDUbJG404.elf
-
/tmp/XcDUbJG404.elf
-
/tmp/XcDUbJG404.elf
-
/tmp/XcDUbJG404.elf
-
/tmp/XcDUbJG404.elf
-
/tmp/XcDUbJG404.elf
-

Domains

Name
IP
Malicious
d.celerlink.buzz
181.214.250.54
malicious

IPs

IP
Domain
Country
Malicious
181.214.250.54
d.celerlink.buzz
Chile
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
40d000
page execute read
malicious
40d000
page execute read
malicious
40d000
page execute read
malicious
40d000
page execute read
malicious
40d000
page execute read
malicious
40d000
page execute read
malicious
40d000
page execute read
malicious
7ffd423cb000
page execute read
7ffd422b0000
page read and write
510000
page read and write
7ffd422b0000
page read and write
50e000
page read and write
7ffd422b0000
page read and write
7ffd423cb000
page execute read
1a54000
page read and write
7ffd423cb000
page execute read
1a54000
page read and write
1a54000
page read and write
50e000
page read and write
1a54000
page read and write
7ffd422b0000
page read and write
7ffd423cb000
page execute read
510000
page read and write
510000
page read and write
510000
page read and write
7ffd422b0000
page read and write
7ffd422b0000
page read and write
1a54000
page read and write
7ffd423cb000
page execute read
510000
page read and write
7ffd423cb000
page execute read
50e000
page read and write
50e000
page read and write
50e000
page read and write
50e000
page read and write
7ffd422b0000
page read and write
1a54000
page read and write
50e000
page read and write
510000
page read and write
510000
page read and write
7ffd423cb000
page execute read
1a54000
page read and write
There are 32 hidden memdumps, click here to show them.