IOC Report
3oLSV0THh9.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/3oLSV0THh9.elf
/tmp/3oLSV0THh9.elf
/tmp/3oLSV0THh9.elf
-
/tmp/3oLSV0THh9.elf
-
/tmp/3oLSV0THh9.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.r7l0P1vr5K /tmp/tmp.z3o51mUUvb /tmp/tmp.1yRtow1rFD
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.r7l0P1vr5K /tmp/tmp.z3o51mUUvb /tmp/tmp.1yRtow1rFD

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
64.23.184.217
unknown
United States
malicious
185.125.190.26
unknown
United Kingdom
34.243.160.129
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
416000
page execute read
malicious
416000
page execute read
malicious
416000
page execute read
malicious
fd1000
page read and write
619000
page read and write
fd1000
page read and write
7ffc5a387000
page execute read
7ffc5a387000
page execute read
7ffc5a2f1000
page read and write
7ffc5a2f1000
page read and write
7ffc5a387000
page execute read
61f000
page read and write
61f000
page read and write
61f000
page read and write
619000
page read and write
619000
page read and write
fd1000
page read and write
7ffc5a2f1000
page read and write
There are 8 hidden memdumps, click here to show them.