IOC Report
arm6.nn.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/arm6.nn.elf
/tmp/arm6.nn.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.iEXim8CPaV /tmp/tmp.7NdVdInXSp /tmp/tmp.0CJDfwaPWW
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.iEXim8CPaV
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.iEXim8CPaV
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.iEXim8CPaV /tmp/tmp.7NdVdInXSp /tmp/tmp.0CJDfwaPWW
There are 11 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://94.156.227.233/curl.sh
unknown
http://94.156.227.233/lol.sh
unknown
http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
unknown
http://94.156.227.233/
unknown

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffa5c032000
page execute read
malicious
7ffb62323000
page read and write
7ffb62694000
page read and write
7ffb6299e000
page read and write
55e2f8ac3000
page read and write
7ffb629c2000
page read and write
7ffb61d56000
page read and write
7ffb62875000
page read and write
55e2f7a66000
page read and write
7ffb5bfff000
page read and write
7ffb62346000
page read and write
55e2f57f7000
page execute read
7ffb5c021000
page read and write
7ffb624b2000
page read and write
7ffb62a07000
page read and write
55e2f7a4f000
page execute and read and write
7ffa5c03b000
page read and write
55e2f5a51000
page read and write
55e2f5a48000
page read and write
7ffc6dd2f000
page read and write
7ffb620b8000
page read and write
7ffc6dda9000
page execute read
7ffb61cc4000
page read and write
7ffa5c045000
page read and write
7ffb614bc000
page read and write
There are 15 hidden memdumps, click here to show them.