IOC Report
zerarm5.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/zerarm5.elf
/tmp/zerarm5.elf
/tmp/zerarm5.elf
-
/tmp/zerarm5.elf
-

Domains

Name
IP
Malicious
yellowchink.pirate
45.156.86.24
malicious
chinklabs.dyn
185.150.24.67
malicious
netfags.geek. [malformed]
unknown
malicious

IPs

IP
Domain
Country
Malicious
185.150.24.67
chinklabs.dyn
Netherlands
malicious
45.156.86.24
yellowchink.pirate
Germany
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3abfbb7000
page read and write
7f39b802b000
page read and write
7f3abebc1000
page read and write
7ffd6e74f000
page execute read
56149b975000
page execute read
7f3abfd99000
page read and write
7f3abf3c9000
page read and write
7f3abfa28000
page read and write
7f3ab8021000
page read and write
7f3abfa4b000
page read and write
56149dbe4000
page read and write
56149bbc6000
page read and write
7f3ab7fff000
page read and write
56149dbcd000
page execute and read and write
7f3ac00c7000
page read and write
7f3abff7a000
page read and write
7f3abf7bd000
page read and write
7f39b8023000
page execute read
56149f8e2000
page read and write
7f3ac010c000
page read and write
56149bbcf000
page read and write
7f39b802c000
page read and write
7f3abf45b000
page read and write
7f3ac00a3000
page read and write
7ffd6e6d5000
page read and write
There are 15 hidden memdumps, click here to show them.