IOC Report
la.bot.arm7.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm7.elf
/tmp/la.bot.arm7.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f8a14034000
page execute read
malicious
7f8b13fff000
page read and write
7ffc7fe27000
page read and write
7f8a14046000
page read and write
7f8b1af47000
page read and write
7f8b1addb000
page read and write
7f8b1b129000
page read and write
55c5d965c000
page read and write
55c5d7647000
page read and write
55c5d9645000
page execute and read and write
55c5dac48000
page read and write
7f8b1ab4d000
page read and write
7f8b19f51000
page read and write
7f8b1adb8000
page read and write
55c5d763e000
page read and write
7ffc7ff00000
page execute read
55c5d73ed000
page execute read
7f8a1403d000
page read and write
7f8b1b30a000
page read and write
7f8b14021000
page read and write
7f8b1b49c000
page read and write
7f8b1a7eb000
page read and write
7f8b1b457000
page read and write
7f8b1a759000
page read and write
7f8b1b433000
page read and write
There are 15 hidden memdumps, click here to show them.