IOC Report
pYZckE379D.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/pYZckE379D.elf
/tmp/pYZckE379D.elf

URLs

Name
IP
Malicious
http://193.239.147.201/zyxel.sh;
unknown
http://193.239.147.201/bins/x86
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

Memdumps

Base Address
Regiontype
Protect
Malicious
7f111c02d000
page execute read
malicious
7f1220bbe000
page read and write
7fff33f67000
page read and write
7f1220324000
page read and write
7f1220b2c000
page read and write
7f122131a000
page read and write
7f12214fc000
page read and write
55a4acba4000
page execute read
7f122182a000
page read and write
55a4aedfc000
page execute and read and write
7f12211ae000
page read and write
7f121c021000
page read and write
7f111c03f000
page read and write
55a4b0daa000
page read and write
7fff33fc0000
page execute read
7f1220f20000
page read and write
7f12216dd000
page read and write
7f111c035000
page read and write
55a4acdfe000
page read and write
7f122118b000
page read and write
7f1221806000
page read and write
7f122186f000
page read and write
7f121bfff000
page read and write
55a4aee13000
page read and write
55a4acdf5000
page read and write
There are 15 hidden memdumps, click here to show them.