IOC Report
sparc.elf

loading gif

Files

File Path
Type
Category
Malicious
sparc.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/Infected.log
ASCII text, with CRLF line terminators
dropped
/tmp/qemu-open.Lo2pCW (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/sparc.elf
/tmp/sparc.elf
/tmp/sparc.elf
-
/tmp/sparc.elf
-

URLs

Name
IP
Malicious
https://developers.google.com/search/docs/advanced/crawling/overview-google-crawlers)
unknown
http://www.spidersoft.com)
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
181.214.231.152:96666
http://www.google.com/mobile/adsbot.html)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
181.214.231.152
unknown
Chile
malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fd7ec063000
page execute read
malicious
7fd7ec063000
page execute read
malicious
55e0290b0000
page read and write
55e02c9e3000
page read and write
7fd8ec000000
page read and write
55e02b0b7000
page execute and read and write
7fd8f3ed2000
page read and write
7fd8f37a0000
page read and write
7fd8f3511000
page read and write
55e02b0b7000
page execute and read and write
7fd7ec07d000
page read and write
55e028e82000
page execute read
7ffdf1302000
page execute read
7fd8f37a0000
page read and write
7fd8f2d00000
page read and write
7fd7ec07d000
page read and write
7fd8f3503000
page read and write
7fd8f3b62000
page read and write
7ffdf124e000
page read and write
7fd8f3b62000
page read and write
55e028e82000
page execute read
55e0290b0000
page read and write
7fd8f4048000
page read and write
7fd8ec021000
page read and write
7fd8f3b87000
page read and write
7fd8f3ed2000
page read and write
7fd8f4003000
page read and write
7fd8ec000000
page read and write
55e02c9e3000
page read and write
7fd8ec021000
page read and write
7fd7ec075000
page read and write
55e0290b9000
page read and write
7fd8f3503000
page read and write
55e0290b9000
page read and write
7fd8f3ffb000
page read and write
55e02b0ce000
page read and write
7fd8f4003000
page read and write
7fd8f3ffb000
page read and write
7ffdf1302000
page execute read
7fd7ec075000
page read and write
55e02b0ce000
page read and write
7ffdf124e000
page read and write
7fd8f3511000
page read and write
7fd8f3b87000
page read and write
7fd8f2d00000
page read and write
7fd8f4048000
page read and write
There are 36 hidden memdumps, click here to show them.