IOC Report
Okami.ppc.elf

loading gif

Files

File Path
Type
Category
Malicious
Okami.ppc.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/run/systemd/resolve/stub-resolv.conf
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/Okami.ppc.elf
/tmp/Okami.ppc.elf
/tmp/Okami.ppc.elf
-
/tmp/Okami.ppc.elf
-
/tmp/Okami.ppc.elf
-

URLs

Name
IP
Malicious
http://www.billybobbot.com/crawler/)
unknown
malicious
http://www.baidu.com/search/spider.html)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
93.123.85.246
unknown
Bulgaria

Memdumps

Base Address
Regiontype
Protect
Malicious
7f05a4012000
page execute read
malicious
7f05a4012000
page execute read
malicious
7f05a4012000
page execute read
malicious
7f0699742000
page read and write
7f069935b000
page read and write
7fff2a0d2000
page execute read
7f05a4023000
page read and write
7f06988bb000
page read and write
7f06988bb000
page read and write
557588eda000
page read and write
557588c4f000
page execute read
55758aeee000
page read and write
7f05a4029000
page read and write
7f06990cc000
page read and write
55758aeee000
page read and write
7f0699bb6000
page read and write
7f0699a8d000
page read and write
55758aed8000
page execute and read and write
7f069971d000
page read and write
55758b6d1000
page read and write
7f06990be000
page read and write
55758b6d1000
page read and write
557588c4f000
page execute read
7fff2a067000
page read and write
557588c4f000
page execute read
7f06990be000
page read and write
55758aed8000
page execute and read and write
7f0694021000
page read and write
7f0699bb6000
page read and write
55758aeee000
page read and write
7f05a4029000
page read and write
7fff2a0d2000
page execute read
557588eda000
page read and write
7f06990be000
page read and write
7f05a4029000
page read and write
7f06988bb000
page read and write
7f0694021000
page read and write
7f0699a8d000
page read and write
7f0699a8d000
page read and write
55758b6d1000
page read and write
7fff2a067000
page read and write
7f0699c03000
page read and write
557588ed2000
page read and write
7f0699bbe000
page read and write
55758b6b0000
page read and write
7f0694000000
page read and write
7f0699bb6000
page read and write
7f0699742000
page read and write
7f0694021000
page read and write
7f0699c03000
page read and write
7f0699bbe000
page read and write
7fff2a067000
page read and write
7f06990cc000
page read and write
7f069971d000
page read and write
557588ed2000
page read and write
7f0699742000
page read and write
55758aed8000
page execute and read and write
557588ed2000
page read and write
7f0699c03000
page read and write
7f06990cc000
page read and write
7f0694000000
page read and write
7fff2a0d2000
page execute read
7f0699bbe000
page read and write
7f05a4023000
page read and write
7f069935b000
page read and write
557588eda000
page read and write
7f069935b000
page read and write
7f069971d000
page read and write
7f05a4023000
page read and write
55758b6b0000
page read and write
7f0694000000
page read and write
There are 61 hidden memdumps, click here to show them.