IOC Report
la.bot.arm5.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm5.elf
/tmp/la.bot.arm5.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f744bcb4000
page read and write
7f744ba26000
page read and write
7f744b632000
page read and write
7f744c1e3000
page read and write
55a76a491000
page execute and read and write
7ffee46cb000
page read and write
7ffee4780000
page execute read
7f7344029000
page execute read
7f744c375000
page read and write
55a76b2c7000
page read and write
55a76a4a8000
page read and write
7f744c330000
page read and write
55a76848a000
page read and write
7f744ae2a000
page read and write
7f7443fff000
page read and write
7f744c30c000
page read and write
7f744b6c4000
page read and write
7f744be20000
page read and write
7f7344039000
page read and write
55a768239000
page execute read
7f7344032000
page read and write
7f7444021000
page read and write
55a768493000
page read and write
7f744c002000
page read and write
7f744bc91000
page read and write
There are 15 hidden memdumps, click here to show them.