IOC Report
la.bot.arm5.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm5.elf
/tmp/la.bot.arm5.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4faffff000
page read and write
7f4fb7e38000
page read and write
7f4fb7aea000
page read and write
7f4fb8019000
page read and write
55d339a99000
page read and write
7ffc7f9d6000
page read and write
55d33983f000
page execute read
7f4fb7c56000
page read and write
7f4fb6c60000
page read and write
7f4fb81ab000
page read and write
7f4fb0021000
page read and write
7f4fb8142000
page read and write
7f4fb8166000
page read and write
7f4eb0039000
page read and write
7f4eb0032000
page read and write
7f4fb785c000
page read and write
7f4eb0029000
page execute read
55d33baae000
page read and write
7f4fb7468000
page read and write
55d33bc74000
page read and write
7ffc7f9f0000
page execute read
7f4fb7ac7000
page read and write
55d339a90000
page read and write
55d33ba97000
page execute and read and write
7f4fb74fa000
page read and write
There are 15 hidden memdumps, click here to show them.