IOC Report
Mozi.m.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.g2tmwYyzI1 /tmp/tmp.WIHK5A4Zbs /tmp/tmp.g81a0kguxI
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.g2tmwYyzI1 /tmp/tmp.WIHK5A4Zbs /tmp/tmp.g81a0kguxI
/tmp/Mozi.m.elf
/tmp/Mozi.m.elf

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffd4a589000
page read and write
7f8a00000000
page read and write
5594b13bb000
page read and write
7f8a06139000
page read and write
7ffd4a5b4000
page execute read
7f8a07311000
page read and write
5594b1129000
page execute read
7f8a07668000
page read and write
7f8980422000
page execute read
7f8a0694f000
page read and write
7f89804c3000
page read and write
7f8a00021000
page read and write
7f8a06941000
page read and write
5594b4e7b000
page read and write
7f8a06fe0000
page read and write
7f8a06fa0000
page read and write
7f8a06bff000
page read and write
7f8a0761b000
page read and write
7f8a07623000
page read and write
5594b33d0000
page read and write
7f8a074f2000
page read and write
5594b13b1000
page read and write
5594b33b9000
page execute and read and write
7f8a06fc3000
page read and write
There are 14 hidden memdumps, click here to show them.