IOC Report
la.bot.sh4.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.sh4.elf
/tmp/la.bot.sh4.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffe71dac000
page read and write
5634f2ddf000
page execute and read and write
5634f0de1000
page read and write
7f816a048000
page read and write
7f8168d45000
page read and write
7f816a040000
page read and write
5634f2df6000
page read and write
7f8169548000
page read and write
7f80e4410000
page execute read
7f8169bcc000
page read and write
7f816a08d000
page read and write
7f8164000000
page read and write
7f8164021000
page read and write
7f8169ba7000
page read and write
7f8169f17000
page read and write
5634f0dd9000
page read and write
5634f32a9000
page read and write
7f81697e5000
page read and write
7f8169556000
page read and write
7f80e4418000
page read and write
7f80e4411000
page read and write
5634f0bc3000
page execute read
7ffe71de8000
page execute read
There are 13 hidden memdumps, click here to show them.