IOC Report
4CB2w5yQL3.elf

loading gif

Files

File Path
Type
Category
Malicious
4CB2w5yQL3.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/qemu-open.Wqaxm5 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/4CB2w5yQL3.elf
/tmp/4CB2w5yQL3.elf
/tmp/4CB2w5yQL3.elf
-
/tmp/4CB2w5yQL3.elf
-
/tmp/4CB2w5yQL3.elf
-

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
176.123.4.187
unknown
Moldova Republic of
malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fcd4002f000
page execute read
malicious
7fcd4002f000
page execute read
malicious
7fcd4002f000
page execute read
malicious
7fce47c89000
page read and write
7fce47c89000
page read and write
7fce47fd4000
page read and write
7fce4814a000
page read and write
7fce48105000
page read and write
7fce480fd000
page read and write
7fcd40040000
page read and write
7fce47c64000
page read and write
7fce40000000
page read and write
5616f4fdd000
page execute read
7fce48105000
page read and write
7fce40000000
page read and write
7fce47613000
page read and write
5616f7dc9000
page read and write
7fce47613000
page read and write
7fce40000000
page read and write
7fce480fd000
page read and write
7fce47605000
page read and write
7fcd40049000
page read and write
7fce40021000
page read and write
7fce48105000
page read and write
5616f520b000
page read and write
7fcd40049000
page read and write
7fce40021000
page read and write
5616f7dc9000
page read and write
7fce47c64000
page read and write
5616f5214000
page read and write
5616f7dc9000
page read and write
5616f7229000
page read and write
5616f7212000
page execute and read and write
7fce4814a000
page read and write
5616f7229000
page read and write
7fcd40040000
page read and write
7fce478a2000
page read and write
7fce478a2000
page read and write
5616f7229000
page read and write
5616f4fdd000
page execute read
5616f5214000
page read and write
7fce46e02000
page read and write
7fce47c89000
page read and write
7fce480fd000
page read and write
7fce40021000
page read and write
7ffccd5d8000
page execute read
7fce47613000
page read and write
7fce47fd4000
page read and write
5616f4fdd000
page execute read
7ffccd4df000
page read and write
7fce47605000
page read and write
5616f7212000
page execute and read and write
5616f5214000
page read and write
7fce47605000
page read and write
5616f7212000
page execute and read and write
7fce46e02000
page read and write
7fce47fd4000
page read and write
5616f520b000
page read and write
7fce4814a000
page read and write
7ffccd4df000
page read and write
5616f520b000
page read and write
7fce478a2000
page read and write
7fce47c64000
page read and write
7fcd40049000
page read and write
7ffccd5d8000
page execute read
7fcd40040000
page read and write
7fce46e02000
page read and write
7ffccd4df000
page read and write
7ffccd5d8000
page execute read
There are 59 hidden memdumps, click here to show them.