IOC Report
amd64.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/amd64.elf
/tmp/amd64.elf
/tmp/amd64.elf
-
/proc/self/exe
/proc/self/exe
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.81eTWBWmI7 /tmp/tmp.o9DTYjt50x /tmp/tmp.si5gMoxVnA

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
156.234.42.40
unknown
Seychelles
109.202.202.202
unknown
Switzerland
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7c4000
page execute read
7f7607dbf000
page read and write
ce8000
page read and write
7f75d5f0f000
page read and write
7f75c5d8e000
page read and write
7ffe20bf4000
page execute read
7f760a60f000
page read and write
7ffe20aad000
page read and write
7f760a195000
page read and write
7f75f5f0f000
page read and write
7f760a6ee000
page read and write
7f75c3c7d000
page read and write
c000400000
page read and write
c77000
page read and write
7f75c3d8e000
page read and write
7f75c3d7d000
page read and write
There are 6 hidden memdumps, click here to show them.