IOC Report
zerm68k.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/zerm68k.elf
/tmp/zerm68k.elf
/tmp/zerm68k.elf
-
/tmp/zerm68k.elf
-

Domains

Name
IP
Malicious
netfags.geek
45.156.86.24
malicious
yellowchink.pirate
45.156.86.24
malicious
chinklabs.dyn
185.150.24.67
malicious
burnthe.libre
45.156.86.24
malicious
netfags.geek. [malformed]
unknown
malicious
burnthe.libre. [malformed]
unknown
malicious
yellowchink.pirate. [malformed]
unknown
malicious

IPs

IP
Domain
Country
Malicious
185.150.24.67
chinklabs.dyn
Netherlands
malicious
45.156.86.24
netfags.geek
Germany
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
55d11d07c000
page read and write
7f57a9e54000
page read and write
7f57a9d2b000
page read and write
7f572400f000
page read and write
7ffd15240000
page read and write
7f57a95f9000
page read and write
55d119f31000
page read and write
7f5724010000
page read and write
7f57a4021000
page read and write
7f57a99bb000
page read and write
7f57a9e5c000
page read and write
7f57a936a000
page read and write
55d11bf2f000
page execute and read and write
7f572400d000
page execute read
7f57a99e0000
page read and write
7f57a8b59000
page read and write
7f57a9ea1000
page read and write
55d119f29000
page read and write
7f57a935c000
page read and write
7f57a4000000
page read and write
55d11bfc6000
page read and write
55d119cf7000
page execute read
7ffd153c6000
page execute read
There are 13 hidden memdumps, click here to show them.