IOC Report
x86_64.bin.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/x86_64.bin.elf
/tmp/x86_64.bin.elf
/tmp/x86_64.bin.elf
-

URLs

Name
IP
Malicious
http://upx.sf.
unknown
malicious
http://upx.sf.n
unknown
malicious
http://185.196.10.215:12234/hi.sh
unknown
malicious
http://upx.sf.net
unknown
malicious
http://upx.sf
unknown
malicious
http://upx.sf.nethttp://upx.sf.netCONFIG:
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
http://help.yahoo.com/help/us/shop/merchant/)Mozilla/5.0
unknown
http://help.yahoo.com/help/us/shop/merchant/)
unknown
http://upx.sf.neU
unknown
http://help.yahoo.com/help/us/ysearch/slurp)Mozilla/5.0
unknown
http://www.google.com/bot.html)Mozilla/5.0
unknown
http://http://uhttp://uphttp://upxhttp://upx.http://upx.shttp://upx.sfhttp://upx.sf.nethttp://upx.sf
unknown
http://www.googlebot.com/bot.html)
unknown
http://www.googlebot.com/bot.html)Mozilla/4.0
unknown
There are 6 hidden URLs, click here to show them.

IPs

IP
Domain
Country
Malicious
198.50.207.21
unknown
Canada
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3af197f000
page read and write
7f3aaaf0e000
page read and write
7f3aad01f000
page read and write
7f3aab01f000
page read and write
7f3add1a0000
page read and write
7f3af1426000
page read and write
7f3abd1a0000
page read and write
df5000
page read and write
7fffd5420000
page read and write
a4f000
page execute read
7f3aab00e000
page read and write
7fffd5590000
page execute read
7f3af18a0000
page read and write
7f3aef050000
page read and write
c000800000
page read and write
There are 5 hidden memdumps, click here to show them.