Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
s0OthAxkuM.elf
|
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, not stripped
|
initial sample
|
||
/tmp/qemu-open.PBbP0K (deleted)
|
ASCII text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/s0OthAxkuM.elf
|
/tmp/s0OthAxkuM.elf
|
||
/tmp/s0OthAxkuM.elf
|
-
|
||
/tmp/s0OthAxkuM.elf
|
-
|
||
/tmp/s0OthAxkuM.elf
|
-
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.p3RgJauZEP /tmp/tmp.bAhgN5J8zq /tmp/tmp.1TdM82QiHF
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.p3RgJauZEP /tmp/tmp.bAhgN5J8zq /tmp/tmp.1TdM82QiHF
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
176.123.4.187
|
unknown
|
Moldova Republic of
|
||
54.171.230.55
|
unknown
|
United States
|
||
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.43
|
unknown
|
United Kingdom
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f070001c000
|
page execute read
|
|||
7f070001c000
|
page execute read
|
|||
7f070001c000
|
page execute read
|
|||
557073409000
|
page read and write
|
|||
7f0785bd2000
|
page read and write
|
|||
557070495000
|
page read and write
|
|||
557072493000
|
page execute and read and write
|
|||
7f0785bd2000
|
page read and write
|
|||
7f0786da4000
|
page read and write
|
|||
7f07863e3000
|
page read and write
|
|||
7f07863e3000
|
page read and write
|
|||
557070495000
|
page read and write
|
|||
55707048d000
|
page read and write
|
|||
7f0786ed5000
|
page read and write
|
|||
7f0780000000
|
page read and write
|
|||
7f0786672000
|
page read and write
|
|||
7f07863d5000
|
page read and write
|
|||
7ffc9c7a1000
|
page execute read
|
|||
55707048d000
|
page read and write
|
|||
7ffc9c66c000
|
page read and write
|
|||
7f07863d5000
|
page read and write
|
|||
55707048d000
|
page read and write
|
|||
7f0786ed5000
|
page read and write
|
|||
7f0786ecd000
|
page read and write
|
|||
7f0786f1a000
|
page read and write
|
|||
7f0780021000
|
page read and write
|
|||
7f0700025000
|
page read and write
|
|||
7ffc9c7a1000
|
page execute read
|
|||
7f0780000000
|
page read and write
|
|||
7f0700025000
|
page read and write
|
|||
557072493000
|
page execute and read and write
|
|||
7f070001e000
|
page read and write
|
|||
7f0786ecd000
|
page read and write
|
|||
7f07863d5000
|
page read and write
|
|||
55707252a000
|
page read and write
|
|||
557073409000
|
page read and write
|
|||
7f0786672000
|
page read and write
|
|||
7f0786f1a000
|
page read and write
|
|||
557070495000
|
page read and write
|
|||
557073409000
|
page read and write
|
|||
55707252a000
|
page read and write
|
|||
7f0700025000
|
page read and write
|
|||
7f07863e3000
|
page read and write
|
|||
55707025b000
|
page execute read
|
|||
55707025b000
|
page execute read
|
|||
7f0786da4000
|
page read and write
|
|||
55707252a000
|
page read and write
|
|||
7f0786da4000
|
page read and write
|
|||
7f0785bd2000
|
page read and write
|
|||
7f0780000000
|
page read and write
|
|||
7ffc9c66c000
|
page read and write
|
|||
7f0780021000
|
page read and write
|
|||
7f070001e000
|
page read and write
|
|||
7f0786672000
|
page read and write
|
|||
7f0786ecd000
|
page read and write
|
|||
7f0786f1a000
|
page read and write
|
|||
7f0786a34000
|
page read and write
|
|||
7f0786a59000
|
page read and write
|
|||
55707025b000
|
page execute read
|
|||
7f0780021000
|
page read and write
|
|||
7ffc9c66c000
|
page read and write
|
|||
557072493000
|
page execute and read and write
|
|||
7f0786a59000
|
page read and write
|
|||
7f0786a34000
|
page read and write
|
|||
7f0786a59000
|
page read and write
|
|||
7ffc9c7a1000
|
page execute read
|
|||
7f0786a34000
|
page read and write
|
|||
7f070001e000
|
page read and write
|
|||
7f0786ed5000
|
page read and write
|
There are 59 hidden memdumps, click here to show them.