IOC Report
.i.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/.i.elf
/tmp/.i.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.7DLQF7GCqO /tmp/tmp.sTLAcw9Ktx /tmp/tmp.5zYVV3nucA
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.7DLQF7GCqO /tmp/tmp.sTLAcw9Ktx /tmp/tmp.5zYVV3nucA

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f9718850000
page read and write
56069b582000
page execute and read and write
56069b599000
page read and write
7f9717b76000
page read and write
7f971736e000
page read and write
7f9718858000
page read and write
7f9717b84000
page read and write
7f97181d5000
page read and write
7f9710021000
page read and write
5606992f2000
page execute read
56069957a000
page read and write
7f971889d000
page read and write
7f9718727000
page read and write
560699584000
page read and write
7ffc30f2c000
page read and write
7ffc30f31000
page execute read
56069bd6a000
page read and write
7f9718546000
page read and write
7f9710000000
page read and write
7f9690115000
page execute read
7f97181f8000
page read and write
7f9718215000
page read and write
7f9717e34000
page read and write
There are 13 hidden memdumps, click here to show them.