IOC Report
la.bot.arm5.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm5.elf
/tmp/la.bot.arm5.elf
/tmp/la.bot.arm5.elf
-
/tmp/la.bot.arm5.elf
-
/tmp/la.bot.arm5.elf
-
/tmp/la.bot.arm5.elf
-
/tmp/la.bot.arm5.elf
-

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7f0df4ec9000
page read and write
55b372e19000
page read and write
7f0df4e37000
page read and write
7f0df59e8000
page read and write
7fff02629000
page read and write
7f0df5807000
page read and write
7f0df462f000
page read and write
7f0df5625000
page read and write
7f0df522b000
page read and write
55b370617000
page read and write
7f0df5496000
page read and write
55b370620000
page read and write
55b3703c6000
page execute read
7f0df5b35000
page read and write
55b37261e000
page execute and read and write
7f0cf003a000
page read and write
7fff0263a000
page execute read
7f0cf0031000
page read and write
7f0cf0029000
page execute read
7f0df54b9000
page read and write
7f0deffff000
page read and write
7f0df0021000
page read and write
55b372635000
page read and write
7f0df5b7a000
page read and write
7f0df5b11000
page read and write
There are 15 hidden memdumps, click here to show them.