IOC Report
Okami.mpsl.elf

loading gif

Files

File Path
Type
Category
Malicious
Okami.mpsl.elf
ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/run/systemd/resolve/stub-resolv.conf
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/Okami.mpsl.elf
/tmp/Okami.mpsl.elf
/tmp/Okami.mpsl.elf
-
/tmp/Okami.mpsl.elf
-
/tmp/Okami.mpsl.elf
-

URLs

Name
IP
Malicious
http://www.billybobbot.com/crawler/)
unknown
malicious
http://www.baidu.com/search/spider.html)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

IPs

IP
Domain
Country
Malicious
93.123.85.246
unknown
Bulgaria
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fe058416000
page execute read
malicious
7fe058416000
page execute read
malicious
7fe058416000
page execute read
malicious
55d37d434000
page read and write
7fe0deae3000
page read and write
55d37f449000
page read and write
7fe0d8000000
page read and write
7fe0df16b000
page read and write
7fe0d8000000
page read and write
7fe0deaa3000
page read and write
7fe0ddc3c000
page read and write
55d37f449000
page read and write
7fe0df126000
page read and write
55d37f432000
page execute and read and write
55d37d42a000
page read and write
7fe0ddc3c000
page read and write
7fe0de452000
page read and write
7fe05845d000
page read and write
7fe0de702000
page read and write
7fffa59af000
page read and write
7fffa59f5000
page execute read
7fffa59af000
page read and write
7fe0deac6000
page read and write
7fe0deaa3000
page read and write
7fffa59af000
page read and write
55d37d42a000
page read and write
7fe0deae3000
page read and write
7fe0df11e000
page read and write
7fffa59f5000
page execute read
55d37d1a2000
page execute read
7fe0deaa3000
page read and write
55d37d1a2000
page execute read
7fe05845d000
page read and write
55d37d434000
page read and write
7fe0dee14000
page read and write
7fe0d8021000
page read and write
7fe0de444000
page read and write
7fe0df126000
page read and write
7fe0df126000
page read and write
7fe0ddc3c000
page read and write
7fe0deff5000
page read and write
55d37f432000
page execute and read and write
7fe0de452000
page read and write
7fe0de702000
page read and write
55d38105d000
page read and write
7fe0d8021000
page read and write
7fe0de444000
page read and write
7fe0de452000
page read and write
7fffa59f5000
page execute read
55d38105d000
page read and write
7fe0dee14000
page read and write
7fe0deff5000
page read and write
7fe0d8000000
page read and write
7fe058457000
page read and write
7fe0de444000
page read and write
55d37d434000
page read and write
7fe05845d000
page read and write
7fe058457000
page read and write
7fe0deae3000
page read and write
7fe0df11e000
page read and write
7fe058457000
page read and write
7fe0de702000
page read and write
55d38105d000
page read and write
55d37d1a2000
page execute read
7fe0deac6000
page read and write
7fe0d8021000
page read and write
55d37d42a000
page read and write
7fe0dee14000
page read and write
7fe0deff5000
page read and write
55d37f449000
page read and write
7fe0df16b000
page read and write
7fe0df11e000
page read and write
55d37f432000
page execute and read and write
7fe0deac6000
page read and write
7fe0df16b000
page read and write
There are 65 hidden memdumps, click here to show them.