IOC Report
mips.elf

loading gif

Files

File Path
Type
Category
Malicious
mips.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
initial sample
malicious
/tmp/Infected.log
ASCII text, with CRLF line terminators
dropped
/tmp/qemu-open.MCHRbp (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/mips.elf
/tmp/mips.elf
/tmp/mips.elf
-
/tmp/mips.elf
-

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious
https://developers.google.com/search/docs/advanced/crawling/overview-google-crawlers)
unknown
http://www.spidersoft.com)
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
http://www.google.com/mobile/adsbot.html)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
181.214.231.152
unknown
Chile

Memdumps

Base Address
Regiontype
Protect
Malicious
7f0774454000
page execute read
malicious
7f0774454000
page execute read
malicious
7f07fbcf0000
page read and write
7f07f4000000
page read and write
7f07fc373000
page read and write
5556038f9000
page read and write
7f07fbd30000
page read and write
7f07f4021000
page read and write
7f07fb691000
page read and write
7f07fc061000
page read and write
7f07f4021000
page read and write
7f07fbcf0000
page read and write
555600032000
page read and write
7f07fb691000
page read and write
7f077449f000
page read and write
7f07fc36b000
page read and write
7fff3f05b000
page read and write
7f07fbd13000
page read and write
7f077449f000
page read and write
7f07fb94f000
page read and write
555602047000
page read and write
7fff3f05b000
page read and write
7f0774180000
page execute and read and write
5555ffda0000
page execute read
7f07fbd30000
page read and write
7f0774180000
page execute and read and write
7f07fc373000
page read and write
555600032000
page read and write
7f07fc3b8000
page read and write
7f07fae89000
page read and write
7f07fc36b000
page read and write
7f07fc242000
page read and write
555602030000
page execute and read and write
7f07fc242000
page read and write
7f07fb69f000
page read and write
7fff3f165000
page execute read
7f07fae89000
page read and write
7f07fb69f000
page read and write
555602030000
page execute and read and write
5556038f9000
page read and write
555600028000
page read and write
555602047000
page read and write
7fff3f165000
page execute read
7f07f4000000
page read and write
7f07fbd13000
page read and write
7f07fb94f000
page read and write
7f07fc061000
page read and write
555600028000
page read and write
5555ffda0000
page execute read
7f07fc3b8000
page read and write
There are 40 hidden memdumps, click here to show them.