Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/Mozi.m.elf
|
/tmp/Mozi.m.elf
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://%s:%d/bin.sh;chmod
|
unknown
|
||
http://ipinfo.io/ip
|
unknown
|
||
http://%s:%d/Mozi.a;chmod
|
unknown
|
||
http://%s:%d/Mozi.m;/tmp/Mozi.m
|
unknown
|
||
http://schemas.xmlsoap.org/soap/encoding/
|
unknown
|
||
http://%s:%d/bin.sh
|
unknown
|
||
http://purenetworks.com/HNAP1/
|
unknown
|
||
http://%s:%d/Mozi.m;
|
unknown
|
||
http://%s:%d/Mozi.m;$
|
unknown
|
||
http://schemas.xmlsoap.org/soap/envelope/
|
unknown
|
||
http://upx.sf.net
|
unknown
|
||
http://HTTP/1.1
|
unknown
|
||
http://%s:%d/Mozi.a;sh$
|
unknown
|
||
http://127.0.0.1
|
unknown
|
||
http://baidu.com/%s/%s/%d/%s/%s/%s/%s)
|
unknown
|
||
http://schemas.xmlsoap.org/soap/envelope//
|
unknown
|
||
http://%s:%d/Mozi.m
|
unknown
|
||
http://127.0.0.1sendcmd
|
unknown
|
There are 8 hidden URLs, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.43
|
unknown
|
United Kingdom
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
5610dba45000
|
page execute and read and write
|
|||
7ffcf67ec000
|
page execute read
|
|||
7f3ebc947000
|
page read and write
|
|||
7f3ebde31000
|
page read and write
|
|||
7f3e38422000
|
page execute read
|
|||
5610d9a47000
|
page read and write
|
|||
7f3eb8000000
|
page read and write
|
|||
5610d9a3d000
|
page read and write
|
|||
7f3ebdd00000
|
page read and write
|
|||
7f3ebd7ae000
|
page read and write
|
|||
7f3ebd7ee000
|
page read and write
|
|||
7f3ebd7d1000
|
page read and write
|
|||
7f3ebde76000
|
page read and write
|
|||
7f3ebd15d000
|
page read and write
|
|||
7ffcf6775000
|
page read and write
|
|||
5610dcafb000
|
page read and write
|
|||
7f3e384c3000
|
page read and write
|
|||
7f3ebde29000
|
page read and write
|
|||
7f3ebd40d000
|
page read and write
|
|||
7f3eb77ff000
|
page read and write
|
|||
5610dba5c000
|
page read and write
|
|||
5610d97b5000
|
page execute read
|
|||
7f3ebdb1f000
|
page read and write
|
|||
7f3eb8021000
|
page read and write
|
|||
7f3ebd14f000
|
page read and write
|
There are 15 hidden memdumps, click here to show them.