IOC Report
OwBugJ5CiC.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/OwBugJ5CiC.elf
/tmp/OwBugJ5CiC.elf
/tmp/OwBugJ5CiC.elf
-
/tmp/OwBugJ5CiC.elf
-
/tmp/OwBugJ5CiC.elf
-

IPs

IP
Domain
Country
Malicious
95.164.4.65
unknown
Gibraltar

Memdumps

Base Address
Regiontype
Protect
Malicious
560efd8a8000
page execute and read and write
7f35cd66c000
page read and write
7f35cdb05000
page read and write
7f35cd2aa000
page read and write
7f35c8021000
page read and write
7f35cdb05000
page read and write
7f35cdb52000
page read and write
7f35cdb0d000
page read and write
7f35cd9dc000
page read and write
7f35c8000000
page read and write
7f35cdb05000
page read and write
560efd8bf000
page read and write
560efe6ce000
page read and write
560efe6ce000
page read and write
7f35cd691000
page read and write
7fffa1fd3000
page execute read
7f35cd01b000
page read and write
7f35c8000000
page read and write
560efb8a2000
page read and write
7f35cd01b000
page read and write
7fffa1fd3000
page execute read
7f35c8000000
page read and write
7f354840c000
page execute read
7f35cd00d000
page read and write
7f354841d000
page read and write
7f35cd00d000
page read and write
7f35cc80a000
page read and write
7f35cd00d000
page read and write
7f35cd66c000
page read and write
7f35cdb0d000
page read and write
7fffa1f55000
page read and write
7f354841d000
page read and write
560efb68c000
page execute read
7f354840c000
page execute read
7fffa1fd3000
page execute read
7f354841d000
page read and write
7fffa1f55000
page read and write
560efb8aa000
page read and write
7f35cd66c000
page read and write
560efd8bf000
page read and write
7f354841e000
page read and write
7f35cc80a000
page read and write
7f35cd9dc000
page read and write
7f35cdb0d000
page read and write
7f354840c000
page execute read
7fffa1f55000
page read and write
560efb8a2000
page read and write
560efb8aa000
page read and write
7f35c8021000
page read and write
7f354841e000
page read and write
560efb8aa000
page read and write
7f35cdb52000
page read and write
7f35c8021000
page read and write
7f35cd691000
page read and write
7f35cd2aa000
page read and write
560efd8a8000
page execute and read and write
7f354841e000
page read and write
7f35cd691000
page read and write
560efd8bf000
page read and write
560efb68c000
page execute read
560efd8a8000
page execute and read and write
7f35cc80a000
page read and write
560efe6ce000
page read and write
560efb68c000
page execute read
7f35cd2aa000
page read and write
7f35cdb52000
page read and write
560efb8a2000
page read and write
7f35cd9dc000
page read and write
7f35cd01b000
page read and write
There are 59 hidden memdumps, click here to show them.