IOC Report
la.bot.powerpc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.powerpc.elf
/tmp/la.bot.powerpc.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4abc017000
page execute read
malicious
7fffe240e000
page read and write
7f4bb059d000
page read and write
55ee36835000
page execute read
7f4bb0da0000
page read and write
55ee3a5e7000
page read and write
7f4bb18e5000
page read and write
7f4bb13ff000
page read and write
55ee38ad4000
page read and write
7f4bb0dae000
page read and write
55ee36ac0000
page read and write
7fffe253f000
page execute read
7f4bb176f000
page read and write
7f4abc027000
page read and write
7f4bb103d000
page read and write
55ee38abe000
page execute and read and write
7f4bb1424000
page read and write
7f4abc030000
page read and write
7f4bb18a0000
page read and write
55ee36ab8000
page read and write
7f4bb1898000
page read and write
7f4bac000000
page read and write
7f4bac021000
page read and write
There are 13 hidden memdumps, click here to show them.