IOC Report
la.bot.powerpc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.powerpc.elf
/tmp/la.bot.powerpc.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
559fc21a6000
page read and write
7fe91a8f1000
page read and write
7fe91a475000
page read and write
7fe91a8e9000
page read and write
7fe91a936000
page read and write
7ffed9bee000
page execute read
559fc5f02000
page read and write
7fe91a7c0000
page read and write
559fc1f1b000
page execute read
7fe824013000
page execute read
7fe919df1000
page read and write
559fc41a4000
page execute and read and write
7fe91a08e000
page read and write
7fe82402a000
page read and write
559fc219e000
page read and write
7fe9195ee000
page read and write
7fe91a450000
page read and write
7fe919dff000
page read and write
7fe824023000
page read and write
7ffed9a94000
page read and write
7fe914021000
page read and write
559fc41ba000
page read and write
7fe914000000
page read and write
There are 13 hidden memdumps, click here to show them.