IOC Report
spc.elf

loading gif

Files

File Path
Type
Category
Malicious
spc.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/tmp/qemu-open.bnzLQf (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/spc.elf
/tmp/spc.elf
/tmp/spc.elf
-
/tmp/spc.elf
-
/tmp/spc.elf
-
/tmp/spc.elf
-

Domains

Name
IP
Malicious
193.84.71.119
unknown
malicious

IPs

IP
Domain
Country
Malicious
193.84.71.119
unknown
Poland
malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f9560020000
page execute read
malicious
7f9560020000
page execute read
malicious
7f9560020000
page execute read
malicious
55f5e35f5000
page execute and read and write
55f5e35f5000
page execute and read and write
7f9668685000
page read and write
55f5e45aa000
page read and write
7f96687b6000
page read and write
55f5e15f7000
page read and write
7f96687b6000
page read and write
7ffe2f94a000
page execute read
7f9660021000
page read and write
7f966833a000
page read and write
7f9668685000
page read and write
55f5e15ee000
page read and write
7f9660000000
page read and write
7ffe2f925000
page read and write
7f9560032000
page read and write
7f96687fb000
page read and write
55f5e13c0000
page execute read
7f9660021000
page read and write
7f9668685000
page read and write
7f9668315000
page read and write
7f96674b3000
page read and write
7ffe2f94a000
page execute read
7ffe2f925000
page read and write
7f9560032000
page read and write
7f9660000000
page read and write
7f9660000000
page read and write
55f5e15f7000
page read and write
7f9667cb6000
page read and write
7f9560032000
page read and write
7ffe2f925000
page read and write
55f5e360c000
page read and write
7f9560030000
page read and write
7ffe2f94a000
page execute read
55f5e13c0000
page execute read
55f5e13c0000
page execute read
7f9667cb6000
page read and write
7f9667f53000
page read and write
7f96674b3000
page read and write
7f9660021000
page read and write
55f5e360c000
page read and write
7f96687b6000
page read and write
55f5e360c000
page read and write
7f9667cb6000
page read and write
7f96687fb000
page read and write
55f5e45aa000
page read and write
55f5e15ee000
page read and write
7f9560030000
page read and write
7f9667f53000
page read and write
55f5e15ee000
page read and write
55f5e35f5000
page execute and read and write
7f9560030000
page read and write
7f9667cc4000
page read and write
7f9667cc4000
page read and write
7f9667f53000
page read and write
7f966833a000
page read and write
55f5e45aa000
page read and write
7f96687ae000
page read and write
7f966833a000
page read and write
7f9667cc4000
page read and write
7f9668315000
page read and write
7f96687fb000
page read and write
7f96687ae000
page read and write
55f5e15f7000
page read and write
7f96674b3000
page read and write
7f96687ae000
page read and write
7f9668315000
page read and write
There are 59 hidden memdumps, click here to show them.