IOC Report
la.bot.arm6.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm6.elf
/tmp/la.bot.arm6.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4c345c8000
page read and write
7f4c345a4000
page read and write
5583f597c000
page read and write
7f4b2c034000
page read and write
7f4c2bfff000
page read and write
7f4c3460d000
page read and write
7ffd3b2ed000
page read and write
7f4b2c02c000
page execute read
7f4c33f4c000
page read and write
7ffd3b3bd000
page execute read
7f4c330c2000
page read and write
5583f5973000
page read and write
7f4c3429a000
page read and write
7f4b2c03b000
page read and write
7f4c340b8000
page read and write
7f4c33cbe000
page read and write
5583f7991000
page read and write
7f4c3447b000
page read and write
7f4c338ca000
page read and write
5583f5722000
page execute read
5583f797a000
page execute and read and write
7f4c2c021000
page read and write
5583f8ca0000
page read and write
7f4c3395c000
page read and write
7f4c33f29000
page read and write
There are 15 hidden memdumps, click here to show them.