Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/arm6.nn.elf
|
/tmp/arm6.nn.elf
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.iEXim8CPaV /tmp/tmp.7NdVdInXSp /tmp/tmp.0CJDfwaPWW
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cat
|
cat /tmp/tmp.iEXim8CPaV
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cat
|
cat /tmp/tmp.iEXim8CPaV
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.iEXim8CPaV /tmp/tmp.7NdVdInXSp /tmp/tmp.0CJDfwaPWW
|
There are 11 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://94.156.227.233/curl.sh
|
unknown
|
||
http://94.156.227.233/lol.sh
|
unknown
|
||
http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
|
unknown
|
||
http://94.156.227.233/
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
54.171.230.55
|
unknown
|
United States
|
||
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.43
|
unknown
|
United Kingdom
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7ffa5c032000
|
page execute read
|
|||
7ffb62323000
|
page read and write
|
|||
7ffb62694000
|
page read and write
|
|||
7ffb6299e000
|
page read and write
|
|||
55e2f8ac3000
|
page read and write
|
|||
7ffb629c2000
|
page read and write
|
|||
7ffb61d56000
|
page read and write
|
|||
7ffb62875000
|
page read and write
|
|||
55e2f7a66000
|
page read and write
|
|||
7ffb5bfff000
|
page read and write
|
|||
7ffb62346000
|
page read and write
|
|||
55e2f57f7000
|
page execute read
|
|||
7ffb5c021000
|
page read and write
|
|||
7ffb624b2000
|
page read and write
|
|||
7ffb62a07000
|
page read and write
|
|||
55e2f7a4f000
|
page execute and read and write
|
|||
7ffa5c03b000
|
page read and write
|
|||
55e2f5a51000
|
page read and write
|
|||
55e2f5a48000
|
page read and write
|
|||
7ffc6dd2f000
|
page read and write
|
|||
7ffb620b8000
|
page read and write
|
|||
7ffc6dda9000
|
page execute read
|
|||
7ffb61cc4000
|
page read and write
|
|||
7ffa5c045000
|
page read and write
|
|||
7ffb614bc000
|
page read and write
|
There are 15 hidden memdumps, click here to show them.