IOC Report
armv6l.elf

loading gif

Files

File Path
Type
Category
Malicious
armv6l.elf
ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, no section header
initial sample
malicious
/tmp/Infected.log
ASCII text, with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
/tmp/armv6l.elf
/tmp/armv6l.elf
/tmp/armv6l.elf
-
/tmp/armv6l.elf
-

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious
https://developers.google.com/search/docs/advanced/crawling/overview-google-crawlers)
unknown
http://www.spidersoft.com)
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
http://www.google.com/mobile/adsbot.html)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
181.214.231.152
unknown
Chile

Memdumps

Base Address
Regiontype
Protect
Malicious
7f77d4064000
page execute read
malicious
7f77d4064000
page execute read
malicious
7f78d8d88000
page read and write
7f78d8a26000
page read and write
55734f43f000
page execute read
7f78d8994000
page read and write
7f78d9182000
page read and write
7f78d8d88000
page read and write
7f78d818c000
page read and write
7f78d966e000
page read and write
7ffe965f7000
page execute read
55734f690000
page read and write
7f78d4021000
page read and write
7ffe96587000
page read and write
7f78d9692000
page read and write
7f77d4075000
page read and write
7f78d9692000
page read and write
7f78d96d7000
page read and write
557352472000
page read and write
557352472000
page read and write
7f78d9182000
page read and write
55734f690000
page read and write
7f78d3fff000
page read and write
7ffe96587000
page read and write
7ffe965f7000
page execute read
55734f699000
page read and write
7f78d4021000
page read and write
7f78d9364000
page read and write
55734f699000
page read and write
5573516ae000
page read and write
7f78d8994000
page read and write
5573516ae000
page read and write
7f78d818c000
page read and write
7f78d8ff3000
page read and write
7f78d8a26000
page read and write
557351697000
page execute and read and write
7f77d4075000
page read and write
7f78d8ff3000
page read and write
7f78d9545000
page read and write
7f78d96d7000
page read and write
7f78d9545000
page read and write
7f78d3fff000
page read and write
7f78d9364000
page read and write
557351697000
page execute and read and write
7f78d9016000
page read and write
7f78d9016000
page read and write
7f78d966e000
page read and write
55734f43f000
page execute read
There are 38 hidden memdumps, click here to show them.