IOC Report
nklarm6.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.jsBOQLhsc4 /tmp/tmp.t5OlO1GOui /tmp/tmp.9AT74cqH1E
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.jsBOQLhsc4 /tmp/tmp.t5OlO1GOui /tmp/tmp.9AT74cqH1E
/tmp/nklarm6.elf
/tmp/nklarm6.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f6374842000
page read and write
5624d948c000
page read and write
5624d9475000
page execute and read and write
7f6373f38000
page read and write
7f6374332000
page read and write
7f626c030000
page read and write
7f6374514000
page read and write
7f636bfff000
page read and write
7f6373b44000
page read and write
5624da1f0000
page read and write
7f63741a3000
page read and write
7fff6f3ff000
page execute read
7f637481e000
page read and write
5624d7477000
page read and write
7fff6f307000
page read and write
7f63746f5000
page read and write
5624d721d000
page execute read
7f637333c000
page read and write
7f636c021000
page read and write
7f626c03a000
page read and write
7f6374887000
page read and write
7f626c028000
page execute read
7f6373bd6000
page read and write
7f63741c6000
page read and write
5624d746e000
page read and write
There are 15 hidden memdumps, click here to show them.