IOC Report
la.bot.m68k.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.m68k.elf
/tmp/la.bot.m68k.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f381001a000
page execute read
malicious
7f3897e45000
page read and write
556e69205000
page execute read
7f3810026000
page read and write
7f389730e000
page read and write
556e6bcf6000
page read and write
7f3890021000
page read and write
7f389795f000
page read and write
556e6943f000
page read and write
7f3897e00000
page read and write
556e6b43d000
page execute and read and write
7f3897ccf000
page read and write
556e69437000
page read and write
7f381001c000
page read and write
7f3890000000
page read and write
7f389759d000
page read and write
556e6b4d4000
page read and write
7ffcba880000
page read and write
7f3897df8000
page read and write
7f3897300000
page read and write
7f3896afd000
page read and write
7f3897984000
page read and write
7ffcba8b2000
page execute read
There are 13 hidden memdumps, click here to show them.