Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/la.bot.sh4.elf
|
/tmp/la.bot.sh4.elf
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http:///wget.sh
|
unknown
|
||
http:///curl.sh
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.43
|
unknown
|
United Kingdom
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7ffe71dac000
|
page read and write
|
|||
5634f2ddf000
|
page execute and read and write
|
|||
5634f0de1000
|
page read and write
|
|||
7f816a048000
|
page read and write
|
|||
7f8168d45000
|
page read and write
|
|||
7f816a040000
|
page read and write
|
|||
5634f2df6000
|
page read and write
|
|||
7f8169548000
|
page read and write
|
|||
7f80e4410000
|
page execute read
|
|||
7f8169bcc000
|
page read and write
|
|||
7f816a08d000
|
page read and write
|
|||
7f8164000000
|
page read and write
|
|||
7f8164021000
|
page read and write
|
|||
7f8169ba7000
|
page read and write
|
|||
7f8169f17000
|
page read and write
|
|||
5634f0dd9000
|
page read and write
|
|||
5634f32a9000
|
page read and write
|
|||
7f81697e5000
|
page read and write
|
|||
7f8169556000
|
page read and write
|
|||
7f80e4418000
|
page read and write
|
|||
7f80e4411000
|
page read and write
|
|||
5634f0bc3000
|
page execute read
|
|||
7ffe71de8000
|
page execute read
|
There are 13 hidden memdumps, click here to show them.