IOC Report
6ZGQp03KWF.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/6ZGQp03KWF.elf
/tmp/6ZGQp03KWF.elf
/tmp/6ZGQp03KWF.elf
-
/tmp/6ZGQp03KWF.elf
-

URLs

Name
IP
Malicious
91.92.240.85:23
malicious
http://91.92.240.85/bins.sh;
unknown

IPs

IP
Domain
Country
Malicious
91.92.240.85
unknown
Bulgaria
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffc549e7000
page read and write
7ffc54a00000
page execute read
7f6ed4021000
page read and write
7f6ed4021000
page read and write
7f6ed8822000
page read and write
5649c7082000
page read and write
5649c6e28000
page execute read
7f6ed94fc000
page read and write
7f6ed93d3000
page read and write
5649c7079000
page read and write
7ffc54a00000
page execute read
5649c7082000
page read and write
7f6ed3f7e000
page read and write
5649ca09b000
page read and write
5649c9080000
page execute and read and write
7f6ed8ea4000
page read and write
7f6dd3fbe000
page read and write
7f6ed8e81000
page read and write
7f6ed88b4000
page read and write
7f6ed8c16000
page read and write
7f6ed93d3000
page read and write
7f6ed91f2000
page read and write
5649ca079000
page read and write
7f6ed9520000
page read and write
7f6ed9565000
page read and write
7f6dd3fae000
page execute read
5649c9097000
page read and write
5649ca09b000
page read and write
7ffc549e7000
page read and write
7f6ed8822000
page read and write
7f6ed94fc000
page read and write
7f6ed8c16000
page read and write
7f6ed91f2000
page read and write
7f6ed3f7e000
page read and write
5649c9080000
page execute and read and write
7f6ed9010000
page read and write
5649c6e28000
page execute read
7f6ed9010000
page read and write
5649c9097000
page read and write
7f6dd3fae000
page execute read
7f6ed9565000
page read and write
7f6dd3fb6000
page read and write
7f6ed8e81000
page read and write
7f6ed4000000
page read and write
7f6dd3fb6000
page read and write
5649c7079000
page read and write
7f6ed88b4000
page read and write
7f6dd3fbe000
page read and write
7f6ed9520000
page read and write
7f6ed8ea4000
page read and write
7f6ed4000000
page read and write
There are 41 hidden memdumps, click here to show them.