IOC Report
zmap.arm.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/zmap.arm.elf
/tmp/zmap.arm.elf
/tmp/zmap.arm.elf
-
/tmp/zmap.arm.elf
-

Domains

Name
IP
Malicious
server.dico-inside.com
154.216.16.38

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
154.216.16.38
server.dico-inside.com
Seychelles
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ff4fc02a000
page execute read
malicious
7ff4fc02a000
page execute read
malicious
7ff604197000
page read and write
55ce03af2000
page read and write
7ff603c42000
page read and write
7ff4fc032000
page read and write
55ce01955000
page read and write
7ff5fc021000
page read and write
7ff5fc021000
page read and write
7ff602c4c000
page read and write
7ff6034e6000
page read and write
7ff603e24000
page read and write
7ff603e24000
page read and write
7ff604197000
page read and write
7ff6034e6000
page read and write
7ff60412e000
page read and write
7ff60412e000
page read and write
7ff603848000
page read and write
7ff603ad6000
page read and write
7ff603454000
page read and write
7ff4fc035000
page read and write
55ce03af2000
page read and write
55ce01955000
page read and write
7ff604152000
page read and write
7ff604152000
page read and write
7ff5fbfff000
page read and write
7ff603848000
page read and write
7ff4fc032000
page read and write
7fff6b866000
page read and write
55ce0194c000
page read and write
55ce0396a000
page read and write
7ff603ab3000
page read and write
7ff603454000
page read and write
7ff5fbfff000
page read and write
55ce0194c000
page read and write
7ff602c4c000
page read and write
55ce016fb000
page execute read
7ff603ab3000
page read and write
7ff603c42000
page read and write
7ff603ad6000
page read and write
55ce016fb000
page execute read
7ff4fc035000
page read and write
7fff6b873000
page execute read
55ce03953000
page execute and read and write
55ce0396a000
page read and write
7fff6b866000
page read and write
7ff604005000
page read and write
7ff604005000
page read and write
7fff6b873000
page execute read
55ce03953000
page execute and read and write
There are 40 hidden memdumps, click here to show them.