IOC Report
iKNw6OUwtY.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.GHk0AUMJUj /tmp/tmp.1hKv6OiAhJ /tmp/tmp.3CI9tfFBCc
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.GHk0AUMJUj
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.GHk0AUMJUj
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.GHk0AUMJUj /tmp/tmp.1hKv6OiAhJ /tmp/tmp.3CI9tfFBCc
/tmp/iKNw6OUwtY.elf
/tmp/iKNw6OUwtY.elf
/tmp/iKNw6OUwtY.elf
-
/tmp/iKNw6OUwtY.elf
-
/tmp/iKNw6OUwtY.elf
-
/tmp/iKNw6OUwtY.elf
-
There are 15 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
93.123.39.20
unknown
Bulgaria
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4580412000
page execute read
malicious
7f4580412000
page execute read
malicious
7f4600021000
page read and write
55ff95bd0000
page read and write
7f4600000000
page read and write
7f4606d5f000
page read and write
7f46073da000
page read and write
7f460670e000
page read and write
7f46073e2000
page read and write
55ff92c63000
page read and write
7f46073e2000
page read and write
7f4600021000
page read and write
7f4606700000
page read and write
7f4605ef8000
page read and write
55ff92c59000
page read and write
7f4606d82000
page read and write
7f4606d82000
page read and write
7fffd70fb000
page read and write
55ff92c59000
page read and write
55ff94c61000
page execute and read and write
7fffd71ef000
page execute read
55ff94c61000
page execute and read and write
7f46073da000
page read and write
7f4580452000
page read and write
7f46069be000
page read and write
7fffd71ef000
page execute read
7f4606d9f000
page read and write
55ff94c78000
page read and write
55ff95bd0000
page read and write
7f46072b1000
page read and write
55ff929d1000
page execute read
7f46072b1000
page read and write
7f4605ef8000
page read and write
7f4606d9f000
page read and write
55ff94c78000
page read and write
55ff92c63000
page read and write
7f4607427000
page read and write
7f4580458000
page read and write
7f46070d0000
page read and write
7f4606d5f000
page read and write
7fffd70fb000
page read and write
7f4600000000
page read and write
7f46070d0000
page read and write
55ff929d1000
page execute read
7f46069be000
page read and write
7f4607427000
page read and write
7f4580458000
page read and write
7f460670e000
page read and write
7f4580452000
page read and write
7f4606700000
page read and write
There are 40 hidden memdumps, click here to show them.