IOC Report
la.bot.arm.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm.elf
/tmp/la.bot.arm.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f40b4fdf000
page read and write
7f40b4745000
page read and write
7f40b5c4b000
page read and write
7f40b5c27000
page read and write
7f40b0021000
page read and write
558ed1ff8000
page execute and read and write
7f3fb0029000
page execute read
7ffdd158f000
page read and write
7f40affff000
page read and write
558ecfffa000
page read and write
7f3fb0039000
page read and write
7f3fb0032000
page read and write
7f40b5c90000
page read and write
558ecfda0000
page execute read
7f40b55cf000
page read and write
7f40b55ac000
page read and write
7f40b573b000
page read and write
7f40b4f4d000
page read and write
7f40b5341000
page read and write
7ffdd15e7000
page execute read
558ecfff1000
page read and write
7f40b591d000
page read and write
7f40b5afe000
page read and write
558ed200f000
page read and write
558ed2aae000
page read and write
There are 15 hidden memdumps, click here to show them.