IOC Report
zerppc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/zerppc.elf
/tmp/zerppc.elf
/tmp/zerppc.elf
-
/tmp/zerppc.elf
-

Domains

Name
IP
Malicious
yellowchink.pirate
45.156.86.24
malicious
chinklabs.dyn
185.150.24.67
malicious
burnthe.libre
45.156.86.24
malicious
chinklabs.dyn. [malformed]
unknown
malicious
netfags.geek. [malformed]
unknown
malicious
burnthe.libre. [malformed]
unknown
malicious
yellowchink.pirate. [malformed]
unknown
malicious

IPs

IP
Domain
Country
Malicious
185.150.24.67
chinklabs.dyn
Netherlands
malicious
45.156.86.24
yellowchink.pirate
Germany
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
55557d4f3000
page read and write
55557b42e000
page execute and read and write
7ffd076ab000
page read and write
7ffd077b2000
page execute read
7fe7747bd000
page read and write
7fe774fce000
page read and write
7fe77598f000
page read and write
7fe68000d000
page execute read
555579428000
page read and write
7fe774fc0000
page read and write
5555791a5000
page execute read
7fe775644000
page read and write
55557b444000
page read and write
555579430000
page read and write
7fe775ac0000
page read and write
7fe77525d000
page read and write
7fe770000000
page read and write
7fe68001e000
page read and write
7fe775ab8000
page read and write
7fe77561f000
page read and write
7fe775b05000
page read and write
7fe770021000
page read and write
7fe68001d000
page read and write
There are 13 hidden memdumps, click here to show them.