IOC Report
zermpsl.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/zermpsl.elf
/tmp/zermpsl.elf
/tmp/zermpsl.elf
-
/tmp/zermpsl.elf
-

Domains

Name
IP
Malicious
yellowchink.pirate
45.156.86.24
malicious
chinklabs.dyn
185.150.24.67
malicious
burnthe.libre
45.156.86.24
malicious
chinklabs.dyn. [malformed]
unknown
malicious
netfags.geek. [malformed]
unknown
malicious
burnthe.libre. [malformed]
unknown
malicious

IPs

IP
Domain
Country
Malicious
185.150.24.67
chinklabs.dyn
Netherlands
malicious
45.156.86.24
yellowchink.pirate
Germany
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fbb79ecb000
page read and write
7fbaf440f000
page execute read
7ffde1589000
page read and write
55bd0c601000
page execute read
7fbb79f18000
page read and write
55bd0c893000
page read and write
55bd0eba4000
page read and write
7fbb794af000
page read and write
7fbb791f1000
page read and write
55bd0e891000
page execute and read and write
7fbb74021000
page read and write
7fbb791ff000
page read and write
7fbb79873000
page read and write
7fbb79bc1000
page read and write
7fbb79da2000
page read and write
7fbb79850000
page read and write
7fbb79ed3000
page read and write
7ffde15d9000
page execute read
55bd0e8a8000
page read and write
7fbb789e9000
page read and write
7fbaf4451000
page read and write
7fbaf4450000
page read and write
7fbb79890000
page read and write
7fbb74000000
page read and write
55bd0c889000
page read and write
There are 15 hidden memdumps, click here to show them.