Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.jsBOQLhsc4 /tmp/tmp.t5OlO1GOui /tmp/tmp.9AT74cqH1E
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.jsBOQLhsc4 /tmp/tmp.t5OlO1GOui /tmp/tmp.9AT74cqH1E
|
||
/tmp/nklarm6.elf
|
/tmp/nklarm6.elf
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http:///wget.sh
|
unknown
|
||
http:///curl.sh
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
34.249.145.219
|
unknown
|
United States
|
||
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f6374842000
|
page read and write
|
|||
5624d948c000
|
page read and write
|
|||
5624d9475000
|
page execute and read and write
|
|||
7f6373f38000
|
page read and write
|
|||
7f6374332000
|
page read and write
|
|||
7f626c030000
|
page read and write
|
|||
7f6374514000
|
page read and write
|
|||
7f636bfff000
|
page read and write
|
|||
7f6373b44000
|
page read and write
|
|||
5624da1f0000
|
page read and write
|
|||
7f63741a3000
|
page read and write
|
|||
7fff6f3ff000
|
page execute read
|
|||
7f637481e000
|
page read and write
|
|||
5624d7477000
|
page read and write
|
|||
7fff6f307000
|
page read and write
|
|||
7f63746f5000
|
page read and write
|
|||
5624d721d000
|
page execute read
|
|||
7f637333c000
|
page read and write
|
|||
7f636c021000
|
page read and write
|
|||
7f626c03a000
|
page read and write
|
|||
7f6374887000
|
page read and write
|
|||
7f626c028000
|
page execute read
|
|||
7f6373bd6000
|
page read and write
|
|||
7f63741c6000
|
page read and write
|
|||
5624d746e000
|
page read and write
|
There are 15 hidden memdumps, click here to show them.