IOC Report
.i.elf

loading gif

Files

File Path
Type
Category
Malicious
.i.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
initial sample
malicious
/tmp/qemu-open.Toqlb3 (deleted)
ASCII text
dropped
/tmp/qemu-open.YHx8X9 (deleted)
data
dropped

Processes

Path
Cmdline
Malicious
/tmp/.i.elf
/tmp/.i.elf
/tmp/.i.elf
-
/tmp/.i.elf
-
/tmp/.i.elf
-
/bin/sh
sh -c "iptables -A INPUT -p tcp --destination-port 23 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 23 -j DROP
/tmp/.i.elf
-
/bin/sh
sh -c "iptables -A INPUT -p tcp --destination-port 7547 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 7547 -j DROP
/tmp/.i.elf
-
/bin/sh
sh -c "iptables -A INPUT -p tcp --destination-port 5555 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 5555 -j DROP
/tmp/.i.elf
-
/bin/sh
sh -c "iptables -A INPUT -p tcp --destination-port 5358 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 5358 -j DROP
/tmp/.i.elf
-
/bin/sh
sh -c "iptables -D INPUT -j CWMP_CR"
/bin/sh
-
/usr/sbin/iptables
iptables -D INPUT -j CWMP_CR
/tmp/.i.elf
-
/bin/sh
sh -c "iptables -X CWMP_CR"
/bin/sh
-
/usr/sbin/iptables
iptables -X CWMP_CR
/tmp/.i.elf
-
/bin/sh
sh -c "iptables -I INPUT -p udp --dport 27986 -j ACCEPT"
/bin/sh
-
/usr/sbin/iptables
iptables -I INPUT -p udp --dport 27986 -j ACCEPT
There are 21 hidden processes, click here to show them.

Domains

Name
IP
Malicious
router.bittorrent.com
unknown
router.utorrent.com
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
561067ce5000
page read and write
7ff0fc160000
page execute and read and write
7ff182c57000
page read and write
7ff18346d000
page read and write
7ffccd4d4000
page execute read
561067ce5000
page read and write
7ff183afe000
page read and write
7ff17c000000
page read and write
7ff0fc47b000
page read and write
7ff18346d000
page read and write
7ff18345f000
page read and write
7ff0fc47b000
page read and write
7ff183afe000
page read and write
561064217000
page execute read
7ff18371d000
page read and write
7ff184141000
page read and write
5610664a7000
page execute and read and write
7ff184010000
page read and write
7ff17c021000
page read and write
7ff0fc435000
page execute read
7ff183abe000
page read and write
56106449f000
page read and write
5610664be000
page read and write
5610664be000
page read and write
7ff184186000
page read and write
7ff17c021000
page read and write
7ff184139000
page read and write
7ffccd4be000
page read and write
7ff0fc160000
page execute and read and write
7ffccd4be000
page read and write
56106449f000
page read and write
5610644a9000
page read and write
7ff184141000
page read and write
561067d05000
page read and write
7ff184010000
page read and write
7ff18345f000
page read and write
7ff183e2f000
page read and write
7ff18371d000
page read and write
5610664a7000
page execute and read and write
7ff184139000
page read and write
7ff183ae1000
page read and write
7ff184186000
page read and write
7ff183abe000
page read and write
7ff183e2f000
page read and write
5610644a9000
page read and write
561064217000
page execute read
7ff0fc435000
page execute read
7ff183ae1000
page read and write
7ff17c000000
page read and write
7ff182c57000
page read and write
7ffccd4d4000
page execute read
There are 41 hidden memdumps, click here to show them.