IOC Report
zerspc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/zerspc.elf
/tmp/zerspc.elf
/tmp/zerspc.elf
-
/tmp/zerspc.elf
-

Domains

Name
IP
Malicious
netfags.geek
45.156.86.24
malicious
yellowchink.pirate
45.156.86.24
malicious
chinklabs.dyn
185.150.24.67
malicious
burnthe.libre
45.156.86.24
malicious
chinklabs.dyn. [malformed]
unknown
malicious
netfags.geek. [malformed]
unknown
malicious
yellowchink.pirate. [malformed]
unknown
malicious

IPs

IP
Domain
Country
Malicious
185.150.24.67
chinklabs.dyn
Netherlands
malicious
45.156.86.24
netfags.geek
Germany
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f6e026d0000
page read and write
7f6e0222f000
page read and write
7f6cfc02e000
page read and write
560efa891000
page execute and read and write
7f6e02254000
page read and write
7ffc409c4000
page execute read
560ef888a000
page read and write
7f6e01bd0000
page read and write
7f6e01bde000
page read and write
7f6cfc01d000
page execute read
7ffc40984000
page read and write
560ef865c000
page execute read
560efa8a8000
page read and write
7f6e0259f000
page read and write
560efba49000
page read and write
7f6dfc000000
page read and write
7f6e026c8000
page read and write
7f6e02715000
page read and write
7f6cfc02f000
page read and write
7f6e01e6d000
page read and write
560ef8893000
page read and write
7f6dfc021000
page read and write
7f6e013cd000
page read and write
There are 13 hidden memdumps, click here to show them.