IOC Report
s0OthAxkuM.elf

loading gif

Files

File Path
Type
Category
Malicious
s0OthAxkuM.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.PBbP0K (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/s0OthAxkuM.elf
/tmp/s0OthAxkuM.elf
/tmp/s0OthAxkuM.elf
-
/tmp/s0OthAxkuM.elf
-
/tmp/s0OthAxkuM.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.p3RgJauZEP /tmp/tmp.bAhgN5J8zq /tmp/tmp.1TdM82QiHF
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.p3RgJauZEP /tmp/tmp.bAhgN5J8zq /tmp/tmp.1TdM82QiHF

IPs

IP
Domain
Country
Malicious
176.123.4.187
unknown
Moldova Republic of
malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f070001c000
page execute read
malicious
7f070001c000
page execute read
malicious
7f070001c000
page execute read
malicious
557073409000
page read and write
7f0785bd2000
page read and write
557070495000
page read and write
557072493000
page execute and read and write
7f0785bd2000
page read and write
7f0786da4000
page read and write
7f07863e3000
page read and write
7f07863e3000
page read and write
557070495000
page read and write
55707048d000
page read and write
7f0786ed5000
page read and write
7f0780000000
page read and write
7f0786672000
page read and write
7f07863d5000
page read and write
7ffc9c7a1000
page execute read
55707048d000
page read and write
7ffc9c66c000
page read and write
7f07863d5000
page read and write
55707048d000
page read and write
7f0786ed5000
page read and write
7f0786ecd000
page read and write
7f0786f1a000
page read and write
7f0780021000
page read and write
7f0700025000
page read and write
7ffc9c7a1000
page execute read
7f0780000000
page read and write
7f0700025000
page read and write
557072493000
page execute and read and write
7f070001e000
page read and write
7f0786ecd000
page read and write
7f07863d5000
page read and write
55707252a000
page read and write
557073409000
page read and write
7f0786672000
page read and write
7f0786f1a000
page read and write
557070495000
page read and write
557073409000
page read and write
55707252a000
page read and write
7f0700025000
page read and write
7f07863e3000
page read and write
55707025b000
page execute read
55707025b000
page execute read
7f0786da4000
page read and write
55707252a000
page read and write
7f0786da4000
page read and write
7f0785bd2000
page read and write
7f0780000000
page read and write
7ffc9c66c000
page read and write
7f0780021000
page read and write
7f070001e000
page read and write
7f0786672000
page read and write
7f0786ecd000
page read and write
7f0786f1a000
page read and write
7f0786a34000
page read and write
7f0786a59000
page read and write
55707025b000
page execute read
7f0780021000
page read and write
7ffc9c66c000
page read and write
557072493000
page execute and read and write
7f0786a59000
page read and write
7f0786a34000
page read and write
7f0786a59000
page read and write
7ffc9c7a1000
page execute read
7f0786a34000
page read and write
7f070001e000
page read and write
7f0786ed5000
page read and write
There are 59 hidden memdumps, click here to show them.