IOC Report
botnet.x86.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/botnet.x86.elf
/tmp/botnet.x86.elf
/tmp/botnet.x86.elf
-
/bin/sh
sh -c "rm -rf bin/busybox && mkdir bin; >bin/busybox && mv /tmp/botnet.x86.elf bin/busybox; chmod 777 bin/busybox"
/bin/sh
-
/usr/bin/rm
rm -rf bin/busybox
/bin/sh
-
/usr/bin/mkdir
mkdir bin
/bin/sh
-
/usr/bin/mv
mv /tmp/botnet.x86.elf bin/busybox
/bin/sh
-
/usr/bin/chmod
chmod 777 bin/busybox
/tmp/botnet.x86.elf
-
/tmp/botnet.x86.elf
-
There are 3 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
147.240.98.140
unknown
United States
140.174.195.252
unknown
United States
108.163.174.127
unknown
Canada
4.66.254.72
unknown
United States
123.198.173.228
unknown
Japan
162.247.109.7
unknown
United States
65.146.107.160
unknown
United States
192.4.191.104
unknown
United States
138.103.123.101
unknown
Sweden
126.61.236.66
unknown
Japan
167.172.53.228
unknown
United States
71.80.177.167
unknown
United States
161.146.210.239
unknown
Australia
213.87.254.237
unknown
Russian Federation
59.176.61.151
unknown
India
112.38.202.148
unknown
China
140.73.187.99
unknown
United States
167.183.204.45
unknown
United States
48.137.53.247
unknown
United States
205.176.110.69
unknown
United States
146.234.208.53
unknown
Germany
144.81.144.235
unknown
United States
198.205.255.34
unknown
United States
138.15.156.89
unknown
United States
84.18.54.134
unknown
Jordan
199.20.211.242
unknown
United States
99.180.30.106
unknown
United States
14.204.114.75
unknown
China
155.207.5.150
unknown
Greece
20.79.56.65
unknown
United States
52.249.136.56
unknown
United States
126.70.159.224
unknown
Japan
150.57.209.77
unknown
Japan
51.254.229.103
unknown
France
107.220.40.243
unknown
United States
36.217.4.33
unknown
China
212.153.90.207
unknown
Netherlands
199.61.173.224
unknown
United States
1.81.74.71
unknown
China
179.143.23.151
unknown
Brazil
63.43.186.162
unknown
United States
209.61.75.148
unknown
United States
72.185.198.81
unknown
United States
53.220.96.74
unknown
Germany
62.182.127.43
unknown
Ukraine
87.66.142.57
unknown
Belgium
39.47.228.101
unknown
Pakistan
205.216.180.149
unknown
United States
64.104.25.139
unknown
United States
192.45.75.134
unknown
United States
112.227.145.105
unknown
China
157.159.82.182
unknown
France
59.211.238.211
unknown
China
196.238.211.1
unknown
Tunisia
106.134.42.158
unknown
Japan
223.72.208.214
unknown
China
168.194.165.131
unknown
Brazil
93.90.131.184
unknown
Germany
197.106.96.172
unknown
South Africa
62.16.115.11
unknown
Russian Federation
129.180.45.126
unknown
Australia
126.83.9.147
unknown
Japan
103.163.150.225
unknown
unknown
12.28.172.44
unknown
United States
93.123.8.172
unknown
Bulgaria
175.218.4.47
unknown
Korea Republic of
9.127.103.127
unknown
United States
208.38.179.181
unknown
United States
178.98.200.100
unknown
United Kingdom
99.63.76.216
unknown
United States
129.14.137.62
unknown
United States
188.117.130.154
unknown
Poland
142.101.233.178
unknown
Canada
60.226.22.167
unknown
Australia
159.176.68.167
unknown
United States
5.204.50.6
unknown
Hungary
74.250.40.157
unknown
United States
189.131.123.78
unknown
Mexico
77.48.38.241
unknown
Czech Republic
135.73.117.254
unknown
United States
209.254.218.180
unknown
United States
93.142.48.116
unknown
Croatia (LOCAL Name: Hrvatska)
174.249.253.209
unknown
United States
4.167.81.27
unknown
United States
138.95.47.91
unknown
United States
205.118.131.211
unknown
United States
87.132.30.13
unknown
Germany
110.191.127.233
unknown
China
165.131.16.230
unknown
United States
211.118.148.182
unknown
Korea Republic of
181.177.138.161
unknown
Bolivia
151.34.8.167
unknown
Italy
200.83.85.38
unknown
Chile
163.147.110.128
unknown
Japan
134.15.87.145
unknown
United States
163.245.32.223
unknown
United States
218.160.45.210
unknown
Taiwan; Republic of China (ROC)
125.97.154.69
unknown
China
93.121.209.227
unknown
France
8.239.93.173
unknown
United States
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
413000
page execute read
malicious
23c1000
page read and write
514000
page read and write
516000
page read and write
7ffc52f92000
page read and write
7ffc52fab000
page execute read