IOC Report
m68k.elf

loading gif

Files

File Path
Type
Category
Malicious
m68k.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/Infected.log
ASCII text, with CRLF line terminators
dropped
/tmp/qemu-open.hfQ5bZ (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/m68k.elf
/tmp/m68k.elf
/tmp/m68k.elf
-
/tmp/m68k.elf
-

URLs

Name
IP
Malicious
181.214.231.152:96666
malicious
https://developers.google.com/search/docs/advanced/crawling/overview-google-crawlers)
unknown
http://www.spidersoft.com)
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
http://www.google.com/mobile/adsbot.html)
unknown

IPs

IP
Domain
Country
Malicious
181.214.231.152
unknown
Chile
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fc9d804b000
page execute read
malicious
7fc9d804b000
page execute read
malicious
555e5121f000
page read and write
555e50928000
page read and write
555e4e659000
page execute read
7fca5de4e000
page read and write
7fc9d8057000
page read and write
7fca58000000
page read and write
7fc9d804e000
page read and write
555e4e659000
page execute read
7fca5e199000
page read and write
555e4e88b000
page read and write
7fca5e30f000
page read and write
7fca5d7ca000
page read and write
7fca5e2ca000
page read and write
555e50891000
page execute and read and write
7ffdf3dfb000
page execute read
555e5121f000
page read and write
7ffdf3dfb000
page execute read
7fca5de4e000
page read and write
7fca58000000
page read and write
7fca5e199000
page read and write
7fca5cfc7000
page read and write
555e50891000
page execute and read and write
7ffdf3d09000
page read and write
7fca5d7ca000
page read and write
7fca5cfc7000
page read and write
7fca5de29000
page read and write
7fca58021000
page read and write
7fca5da67000
page read and write
7fc9d804e000
page read and write
7fca5d7d8000
page read and write
7fca5e2ca000
page read and write
7fca5d7d8000
page read and write
7fca5e2c2000
page read and write
7fc9d8057000
page read and write
7fca5da67000
page read and write
555e50928000
page read and write
555e4e893000
page read and write
555e4e88b000
page read and write
7fca5de29000
page read and write
7fca5e30f000
page read and write
7ffdf3d09000
page read and write
555e4e893000
page read and write
7fca5e2c2000
page read and write
7fca58021000
page read and write
There are 36 hidden memdumps, click here to show them.