Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/botnet.x86.elf
|
/tmp/botnet.x86.elf
|
||
/tmp/botnet.x86.elf
|
-
|
||
/bin/sh
|
sh -c "rm -rf bin/busybox && mkdir bin; >bin/busybox && mv /tmp/botnet.x86.elf bin/busybox; chmod 777 bin/busybox"
|
||
/bin/sh
|
-
|
||
/usr/bin/rm
|
rm -rf bin/busybox
|
||
/bin/sh
|
-
|
||
/usr/bin/mkdir
|
mkdir bin
|
||
/bin/sh
|
-
|
||
/usr/bin/mv
|
mv /tmp/botnet.x86.elf bin/busybox
|
||
/bin/sh
|
-
|
||
/usr/bin/chmod
|
chmod 777 bin/busybox
|
||
/tmp/botnet.x86.elf
|
-
|
||
/tmp/botnet.x86.elf
|
-
|
There are 3 hidden processes, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
147.240.98.140
|
unknown
|
United States
|
||
140.174.195.252
|
unknown
|
United States
|
||
108.163.174.127
|
unknown
|
Canada
|
||
4.66.254.72
|
unknown
|
United States
|
||
123.198.173.228
|
unknown
|
Japan
|
||
162.247.109.7
|
unknown
|
United States
|
||
65.146.107.160
|
unknown
|
United States
|
||
192.4.191.104
|
unknown
|
United States
|
||
138.103.123.101
|
unknown
|
Sweden
|
||
126.61.236.66
|
unknown
|
Japan
|
||
167.172.53.228
|
unknown
|
United States
|
||
71.80.177.167
|
unknown
|
United States
|
||
161.146.210.239
|
unknown
|
Australia
|
||
213.87.254.237
|
unknown
|
Russian Federation
|
||
59.176.61.151
|
unknown
|
India
|
||
112.38.202.148
|
unknown
|
China
|
||
140.73.187.99
|
unknown
|
United States
|
||
167.183.204.45
|
unknown
|
United States
|
||
48.137.53.247
|
unknown
|
United States
|
||
205.176.110.69
|
unknown
|
United States
|
||
146.234.208.53
|
unknown
|
Germany
|
||
144.81.144.235
|
unknown
|
United States
|
||
198.205.255.34
|
unknown
|
United States
|
||
138.15.156.89
|
unknown
|
United States
|
||
84.18.54.134
|
unknown
|
Jordan
|
||
199.20.211.242
|
unknown
|
United States
|
||
99.180.30.106
|
unknown
|
United States
|
||
14.204.114.75
|
unknown
|
China
|
||
155.207.5.150
|
unknown
|
Greece
|
||
20.79.56.65
|
unknown
|
United States
|
||
52.249.136.56
|
unknown
|
United States
|
||
126.70.159.224
|
unknown
|
Japan
|
||
150.57.209.77
|
unknown
|
Japan
|
||
51.254.229.103
|
unknown
|
France
|
||
107.220.40.243
|
unknown
|
United States
|
||
36.217.4.33
|
unknown
|
China
|
||
212.153.90.207
|
unknown
|
Netherlands
|
||
199.61.173.224
|
unknown
|
United States
|
||
1.81.74.71
|
unknown
|
China
|
||
179.143.23.151
|
unknown
|
Brazil
|
||
63.43.186.162
|
unknown
|
United States
|
||
209.61.75.148
|
unknown
|
United States
|
||
72.185.198.81
|
unknown
|
United States
|
||
53.220.96.74
|
unknown
|
Germany
|
||
62.182.127.43
|
unknown
|
Ukraine
|
||
87.66.142.57
|
unknown
|
Belgium
|
||
39.47.228.101
|
unknown
|
Pakistan
|
||
205.216.180.149
|
unknown
|
United States
|
||
64.104.25.139
|
unknown
|
United States
|
||
192.45.75.134
|
unknown
|
United States
|
||
112.227.145.105
|
unknown
|
China
|
||
157.159.82.182
|
unknown
|
France
|
||
59.211.238.211
|
unknown
|
China
|
||
196.238.211.1
|
unknown
|
Tunisia
|
||
106.134.42.158
|
unknown
|
Japan
|
||
223.72.208.214
|
unknown
|
China
|
||
168.194.165.131
|
unknown
|
Brazil
|
||
93.90.131.184
|
unknown
|
Germany
|
||
197.106.96.172
|
unknown
|
South Africa
|
||
62.16.115.11
|
unknown
|
Russian Federation
|
||
129.180.45.126
|
unknown
|
Australia
|
||
126.83.9.147
|
unknown
|
Japan
|
||
103.163.150.225
|
unknown
|
unknown
|
||
12.28.172.44
|
unknown
|
United States
|
||
93.123.8.172
|
unknown
|
Bulgaria
|
||
175.218.4.47
|
unknown
|
Korea Republic of
|
||
9.127.103.127
|
unknown
|
United States
|
||
208.38.179.181
|
unknown
|
United States
|
||
178.98.200.100
|
unknown
|
United Kingdom
|
||
99.63.76.216
|
unknown
|
United States
|
||
129.14.137.62
|
unknown
|
United States
|
||
188.117.130.154
|
unknown
|
Poland
|
||
142.101.233.178
|
unknown
|
Canada
|
||
60.226.22.167
|
unknown
|
Australia
|
||
159.176.68.167
|
unknown
|
United States
|
||
5.204.50.6
|
unknown
|
Hungary
|
||
74.250.40.157
|
unknown
|
United States
|
||
189.131.123.78
|
unknown
|
Mexico
|
||
77.48.38.241
|
unknown
|
Czech Republic
|
||
135.73.117.254
|
unknown
|
United States
|
||
209.254.218.180
|
unknown
|
United States
|
||
93.142.48.116
|
unknown
|
Croatia (LOCAL Name: Hrvatska)
|
||
174.249.253.209
|
unknown
|
United States
|
||
4.167.81.27
|
unknown
|
United States
|
||
138.95.47.91
|
unknown
|
United States
|
||
205.118.131.211
|
unknown
|
United States
|
||
87.132.30.13
|
unknown
|
Germany
|
||
110.191.127.233
|
unknown
|
China
|
||
165.131.16.230
|
unknown
|
United States
|
||
211.118.148.182
|
unknown
|
Korea Republic of
|
||
181.177.138.161
|
unknown
|
Bolivia
|
||
151.34.8.167
|
unknown
|
Italy
|
||
200.83.85.38
|
unknown
|
Chile
|
||
163.147.110.128
|
unknown
|
Japan
|
||
134.15.87.145
|
unknown
|
United States
|
||
163.245.32.223
|
unknown
|
United States
|
||
218.160.45.210
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
125.97.154.69
|
unknown
|
China
|
||
93.121.209.227
|
unknown
|
France
|
||
8.239.93.173
|
unknown
|
United States
|
There are 90 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
413000
|
page execute read
|
|||
23c1000
|
page read and write
|
|||
514000
|
page read and write
|
|||
516000
|
page read and write
|
|||
7ffc52f92000
|
page read and write
|
|||
7ffc52fab000
|
page execute read
|