IOC Report
sparc.elf

loading gif

Files

File Path
Type
Category
Malicious
sparc.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/Infected.log
ASCII text, with CRLF line terminators
dropped
/tmp/qemu-open.UI4Pt6 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/sparc.elf
/tmp/sparc.elf
/tmp/sparc.elf
-
/tmp/sparc.elf
-

URLs

Name
IP
Malicious
181.214.231.152:96666
malicious
https://developers.google.com/search/docs/advanced/crawling/overview-google-crawlers)
unknown
http://www.spidersoft.com)
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
http://www.google.com/mobile/adsbot.html)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
181.214.231.152
unknown
Chile
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f21d805f000
page execute read
malicious
7f21d805f000
page execute read
malicious
7ffd02826000
page read and write
5638c82f4000
page read and write
7f22e04c4000
page read and write
5638c80bd000
page execute read
7f22dfcb3000
page read and write
7f22e0b15000
page read and write
5638ca3cf000
page read and write
7f22e0ffb000
page read and write
5638ca3cf000
page read and write
5638ca309000
page read and write
7f22e04b6000
page read and write
7f22e0b3a000
page read and write
7f22e0fb6000
page read and write
5638ca2f2000
page execute and read and write
7f21d8071000
page read and write
7f22e0753000
page read and write
5638ca2f2000
page execute and read and write
7ffd02826000
page read and write
7ffd02936000
page execute read
5638c82f4000
page read and write
7f21d8071000
page read and write
7f22e0b3a000
page read and write
7f21d8079000
page read and write
7f22e0fae000
page read and write
7f22e0e85000
page read and write
7f22e0753000
page read and write
5638c82eb000
page read and write
7f21d8079000
page read and write
7f22d8000000
page read and write
7f22d8021000
page read and write
5638ca309000
page read and write
7f22e0fae000
page read and write
5638c80bd000
page execute read
7f22dfcb3000
page read and write
7f22d8021000
page read and write
7f22e04c4000
page read and write
7f22e0fb6000
page read and write
7ffd02936000
page execute read
7f22d8000000
page read and write
7f22e0b15000
page read and write
7f22e04b6000
page read and write
5638c82eb000
page read and write
7f22e0ffb000
page read and write
7f22e0e85000
page read and write
There are 36 hidden memdumps, click here to show them.