IOC Report
mzdWUcvUU2.elf

loading gif

Files

File Path
Type
Category
Malicious
mzdWUcvUU2.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.veEX00 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.rvUodmgBFz /tmp/tmp.kbcm3CnpXc /tmp/tmp.ntMrqaC4IJ
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.rvUodmgBFz /tmp/tmp.kbcm3CnpXc /tmp/tmp.ntMrqaC4IJ
/tmp/mzdWUcvUU2.elf
/tmp/mzdWUcvUU2.elf
/tmp/mzdWUcvUU2.elf
-
/tmp/mzdWUcvUU2.elf
-
/tmp/mzdWUcvUU2.elf
-

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
64.23.184.217
unknown
United States
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f148c422000
page execute read
malicious
7f148c422000
page execute read
malicious
7f148c422000
page execute read
malicious
55846e3c4000
page read and write
7f15135c4000
page read and write
7f1513c47000
page read and write
7f15135c4000
page read and write
7f1513b16000
page read and write
7f15135e7000
page read and write
7f1513935000
page read and write
7f1513604000
page read and write
7f1512f73000
page read and write
7ffd520e3000
page read and write
7f1513935000
page read and write
5584703c2000
page execute and read and write
7f1512f73000
page read and write
7f1513c8c000
page read and write
7f1512f65000
page read and write
7f1512f73000
page read and write
5584703d9000
page read and write
55846e3c4000
page read and write
55846e3ba000
page read and write
5584703c2000
page execute and read and write
7f150c000000
page read and write
7ffd520e3000
page read and write
7ffd5215e000
page execute read
7f148c433000
page read and write
55846e3ba000
page read and write
558470b9c000
page read and write
7ffd5215e000
page execute read
7f1513223000
page read and write
7f15135c4000
page read and write
7f1513c3f000
page read and write
7f1513c8c000
page read and write
7f1513c3f000
page read and write
7f148c433000
page read and write
7f1513223000
page read and write
55846e132000
page execute read
7f15135e7000
page read and write
7f150c021000
page read and write
7f1513604000
page read and write
7f151275d000
page read and write
7f148c433000
page read and write
5584703d9000
page read and write
558470bbd000
page read and write
558470b9c000
page read and write
55846e3c4000
page read and write
7f1513604000
page read and write
7f148c43c000
page read and write
55846e3ba000
page read and write
7f1513c47000
page read and write
7f1513b16000
page read and write
7f15135e7000
page read and write
7f1513223000
page read and write
5584703c2000
page execute and read and write
55846e132000
page execute read
7f1512f65000
page read and write
55846e132000
page execute read
7f148c43c000
page read and write
7f1512f65000
page read and write
7f1513c3f000
page read and write
7f150c021000
page read and write
7f1513935000
page read and write
558470bbd000
page read and write
7f148c43c000
page read and write
7f150c000000
page read and write
7f1513c47000
page read and write
7f1513c8c000
page read and write
558470bbd000
page read and write
7f151275d000
page read and write
7f150c000000
page read and write
7f1513b16000
page read and write
7f151275d000
page read and write
7ffd5215e000
page execute read
7f150c021000
page read and write
7ffd520e3000
page read and write
5584703d9000
page read and write
There are 67 hidden memdumps, click here to show them.