IOC Report
la.bot.sh4.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.sh4.elf
/tmp/la.bot.sh4.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7a2c415000
page execute read
malicious
7f7ab408a000
page read and write
55bf3b0ad000
page read and write
55bf3a373000
page read and write
7f7a2c425000
page read and write
7f7aac000000
page read and write
7ffe10542000
page read and write
55bf38356000
page read and write
55bf3835e000
page read and write
7f7ab3a14000
page read and write
7ffe105ed000
page execute read
7f7ab3a06000
page read and write
7f7ab4506000
page read and write
7f7ab3203000
page read and write
7f7ab4065000
page read and write
7f7ab44fe000
page read and write
7f7ab43d5000
page read and write
55bf38140000
page execute read
7f7ab3ca3000
page read and write
7f7ab454b000
page read and write
55bf3a35c000
page execute and read and write
7f7aac021000
page read and write
7f7a2c42e000
page read and write
There are 13 hidden memdumps, click here to show them.