IOC Report
la.bot.arm6.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm6.elf
/tmp/la.bot.arm6.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.zR0ufuBGwt /tmp/tmp.vTMpXvqaTZ /tmp/tmp.ljEx9lCsQQ
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.zR0ufuBGwt /tmp/tmp.vTMpXvqaTZ /tmp/tmp.ljEx9lCsQQ

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffe91b0d000
page read and write
7fd6d3011000
page read and write
7fd6d3566000
page read and write
7fd6d33d4000
page read and write
7fd6d2e82000
page read and write
7fd6d2c17000
page read and write
7fd6cc021000
page read and write
7fd5cc02c000
page execute read
5615b3344000
page execute read
5615b559c000
page execute and read and write
7fd6d34fd000
page read and write
7fd5cc03b000
page read and write
7fd5cc034000
page read and write
7fd6cbfff000
page read and write
5615b359e000
page read and write
7fd6d2823000
page read and write
5615b73f1000
page read and write
7fd6d2ea5000
page read and write
7fd6d28b5000
page read and write
5615b3595000
page read and write
7fd6d201b000
page read and write
7fd6d3521000
page read and write
5615b55b3000
page read and write
7fd6d31f3000
page read and write
7ffe91b56000
page execute read
There are 15 hidden memdumps, click here to show them.