IOC Report
mips.elf

loading gif

Files

File Path
Type
Category
Malicious
mips.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.Rb1RG0 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/mips.elf
/tmp/mips.elf
/tmp/mips.elf
-
/tmp/mips.elf
-

URLs

Name
IP
Malicious
150.241.95.250:25565
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
150.241.95.250
unknown
Spain
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7fe3a8418000
page execute read
malicious
7fe3a8418000
page execute read
malicious
7fe42dc6b000
page read and write
7fe42e310000
page read and write
7fe428000000
page read and write
7fe42e19a000
page read and write
560bb4513000
page execute read
7fe42dc88000
page read and write
7fe42e19a000
page read and write
7fe42e2cb000
page read and write
560bb47a5000
page read and write
7fe42dc48000
page read and write
7fe3a845e000
page read and write
7fe3a8458000
page read and write
560bb67ba000
page read and write
7fe42d8a7000
page read and write
7fe42e2c3000
page read and write
7fe42d5f7000
page read and write
7ffdaffb7000
page read and write
560bb67a3000
page execute and read and write
7fe42dc88000
page read and write
560bb479b000
page read and write
7fe428000000
page read and write
560bb479b000
page read and write
7fe3a845e000
page read and write
7fe42d5f7000
page read and write
7fe42dfb9000
page read and write
7fe428021000
page read and write
7fe42d5e9000
page read and write
7ffdaffcb000
page execute read
7fe42d8a7000
page read and write
7fe42cde1000
page read and write
560bb67a3000
page execute and read and write
560bb67ba000
page read and write
7fe3a8458000
page read and write
7fe42e2c3000
page read and write
7ffdaffcb000
page execute read
7fe42e310000
page read and write
7fe42dc48000
page read and write
7fe42d5e9000
page read and write
7fe428021000
page read and write
7ffdaffb7000
page read and write
7fe42dfb9000
page read and write
560bb4513000
page execute read
560bb87d9000
page read and write
560bb87d9000
page read and write
7fe42cde1000
page read and write
7fe42dc6b000
page read and write
7fe42e2cb000
page read and write
560bb47a5000
page read and write
There are 40 hidden memdumps, click here to show them.