IOC Report
botx.arm5.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.3LOcx3WieS /tmp/tmp.AUKazW78aa /tmp/tmp.dGTBmEiLBw
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.3LOcx3WieS /tmp/tmp.AUKazW78aa /tmp/tmp.dGTBmEiLBw
/tmp/botx.arm5.elf
/tmp/botx.arm5.elf

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fc910021000
page execute read
malicious
7fca18bde000
page read and write
557208e9f000
page read and write
7fca18b99000
page read and write
7fca17e9b000
page read and write
7fca0ffff000
page read and write
557208e96000
page read and write
7fca17f2d000
page read and write
7fca17693000
page read and write
7fca1886b000
page read and write
55720bdb3000
page read and write
7fca1828f000
page read and write
7fca18a4c000
page read and write
7fca10021000
page read and write
55720aeb4000
page read and write
7fca18689000
page read and write
7fff5d72a000
page read and write
55720ae9e000
page execute and read and write
7fff5d7f7000
page execute read
7fca184fa000
page read and write
557208c45000
page execute read
7fca1851d000
page read and write
7fca18b75000
page read and write
7fc91002a000
page read and write
There are 14 hidden memdumps, click here to show them.