IOC Report
la.bot.arm6.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm6.elf
/tmp/la.bot.arm6.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fd9f8031000
page execute read
malicious
55b3b369b000
page read and write
7fdafe5fd000
page read and write
55b3b5699000
page execute and read and write
7fdaf8021000
page read and write
7fdaf7fff000
page read and write
7fdafe594000
page read and write
55b3b3441000
page execute read
7fdafdf3c000
page read and write
7fdafe46b000
page read and write
7ffee9707000
page execute read
55b3b3692000
page read and write
7fd9f803a000
page read and write
7fdafdf19000
page read and write
7fdafd94c000
page read and write
7fdafe5b8000
page read and write
7fdafd8ba000
page read and write
55b3b6afd000
page read and write
7ffee9688000
page read and write
7fdafe0a8000
page read and write
7fd9f8042000
page read and write
7fdafd0b2000
page read and write
7fdafdcae000
page read and write
7fdafe28a000
page read and write
55b3b56b0000
page read and write
There are 15 hidden memdumps, click here to show them.