IOC Report
2Cn3vPj6IQ.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.aUv57CL66Y /tmp/tmp.UA3VF1uYDn /tmp/tmp.IR6MvBedQm
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.aUv57CL66Y /tmp/tmp.UA3VF1uYDn /tmp/tmp.IR6MvBedQm
/tmp/2Cn3vPj6IQ.elf
/tmp/2Cn3vPj6IQ.elf

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffcfcb86000
page execute read
7fb73d64e000
page read and write
5630dc7b8000
page read and write
5630dd836000
page read and write
7fb73dcc2000
page read and write
5630da7a3000
page read and write
5630da799000
page read and write
7fb73e367000
page read and write
7fb6b844a000
page read and write
7fb73e31a000
page read and write
7fb73e322000
page read and write
7fb6b8405000
page execute read
7fb73dc9f000
page read and write
7fb73d8fe000
page read and write
7fb73ce38000
page read and write
5630dc7a1000
page execute and read and write
7fb73e010000
page read and write
7fb73e1f1000
page read and write
5630da511000
page execute read
7fb738021000
page read and write
7fb738000000
page read and write
7fb73d640000
page read and write
7fb7377ff000
page read and write
7fb73dcdf000
page read and write
7ffcfcb75000
page read and write
There are 15 hidden memdumps, click here to show them.