IOC Report
Okami.m68k.elf

loading gif

Files

File Path
Type
Category
Malicious
Okami.m68k.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/run/systemd/resolve/stub-resolv.conf
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/Okami.m68k.elf
/tmp/Okami.m68k.elf
/tmp/Okami.m68k.elf
-
/tmp/Okami.m68k.elf
-
/tmp/Okami.m68k.elf
-

URLs

Name
IP
Malicious
http://www.billybobbot.com/crawler/)
unknown
malicious
http://www.baidu.com/search/spider.html)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.246
unknown
Bulgaria

Memdumps

Base Address
Regiontype
Protect
Malicious
7ff59c013000
page execute read
malicious
7ff59c013000
page execute read
malicious
7ff59c013000
page execute read
malicious
55b40091d000
page read and write
7ff59c016000
page read and write
55b40291b000
page execute and read and write
7ff6213c5000
page read and write
55b40440e000
page read and write
55b40291b000
page execute and read and write
7fff538e8000
page execute read
7ff620f2c000
page read and write
7ff61c021000
page read and write
7ff61c000000
page read and write
55b400915000
page read and write
7fff538e8000
page execute read
55b400915000
page read and write
7ff620f51000
page read and write
55b4006e3000
page execute read
7ff621412000
page read and write
7ff6208cd000
page read and write
7ff59c016000
page read and write
7ff61c021000
page read and write
7ff6213c5000
page read and write
7ff621412000
page read and write
7ff6213cd000
page read and write
7ff620b6a000
page read and write
55b40440e000
page read and write
7ff620f2c000
page read and write
7ff61c000000
page read and write
7ff62129c000
page read and write
7ff620b6a000
page read and write
7ff620f51000
page read and write
7ff61c000000
page read and write
55b40440e000
page read and write
7fff538d3000
page read and write
55b4029b2000
page read and write
7ff6200ca000
page read and write
7ff6208db000
page read and write
7ff6208cd000
page read and write
55b40091d000
page read and write
55b4006e3000
page execute read
7ff6213c5000
page read and write
7ff6208cd000
page read and write
55b4029b2000
page read and write
7ff59c01c000
page read and write
55b4006e3000
page execute read
7ff61c021000
page read and write
7fff538d3000
page read and write
7ff6208db000
page read and write
7ff59c01c000
page read and write
55b40291b000
page execute and read and write
7ff6200ca000
page read and write
7ff6208db000
page read and write
7ff6213cd000
page read and write
55b4029b2000
page read and write
7ff620b6a000
page read and write
7ff59c016000
page read and write
55b40091d000
page read and write
7fff538d3000
page read and write
7ff6200ca000
page read and write
7ff62129c000
page read and write
55b400915000
page read and write
7ff620f2c000
page read and write
7fff538e8000
page execute read
7ff621412000
page read and write
7ff59c01c000
page read and write
7ff62129c000
page read and write
7ff6213cd000
page read and write
7ff620f51000
page read and write
There are 59 hidden memdumps, click here to show them.