IOC Report
m68k.elf

loading gif

Files

File Path
Type
Category
Malicious
m68k.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/Infected.log
ASCII text, with CRLF line terminators
dropped
/tmp/qemu-open.enIqGb (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/m68k.elf
/tmp/m68k.elf
/tmp/m68k.elf
-
/tmp/m68k.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.0lLnnSd7nq /tmp/tmp.3Pjf9XhPIl /tmp/tmp.MRNLN2GR5r
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.0lLnnSd7nq /tmp/tmp.3Pjf9XhPIl /tmp/tmp.MRNLN2GR5r

URLs

Name
IP
Malicious
https://developers.google.com/search/docs/advanced/crawling/overview-google-crawlers)
unknown
http://www.spidersoft.com)
unknown
http://help.yahoo.com/help/us/ysearch/slurp)
unknown
http://www.google.com/bot.html)
unknown
181.214.231.152:96666
http://www.google.com/mobile/adsbot.html)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
181.214.231.152
unknown
Chile
malicious
54.217.10.153
unknown
United States
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ff6e004e000
page execute read
malicious
7ff6e004e000
page execute read
malicious
55e6a3c04000
page read and write
55e6a4011000
page read and write
55e6a1935000
page execute read
7ff768565000
page read and write
7ff7682d6000
page read and write
7ffe057f5000
page execute read
7ff760021000
page read and write
55e6a1b67000
page read and write
7ff6e0051000
page read and write
7ff768dc8000
page read and write
55e6a1b67000
page read and write
55e6a3b6d000
page execute and read and write
7ff6e0059000
page read and write
55e6a1b6f000
page read and write
7ff767ac5000
page read and write
7ff760000000
page read and write
7ffe05791000
page read and write
55e6a4011000
page read and write
7ff768927000
page read and write
7ff768dc0000
page read and write
7ffe05791000
page read and write
55e6a3c04000
page read and write
7ff7682c8000
page read and write
55e6a3b6d000
page execute and read and write
7ff6e0051000
page read and write
7ff6e0059000
page read and write
7ff768e0d000
page read and write
7ff760000000
page read and write
7ff768927000
page read and write
7ff7682c8000
page read and write
7ff768c97000
page read and write
7ff7682d6000
page read and write
7ff768dc8000
page read and write
7ff768565000
page read and write
55e6a1b6f000
page read and write
7ff76894c000
page read and write
7ffe057f5000
page execute read
7ff767ac5000
page read and write
7ff76894c000
page read and write
55e6a1935000
page execute read
7ff760021000
page read and write
7ff768c97000
page read and write
7ff768e0d000
page read and write
7ff768dc0000
page read and write
There are 36 hidden memdumps, click here to show them.