IOC Report
efefa7.elf

loading gifFilesProcessesDomainsIPsMemdumps1010Label

Files

File Path
Type
Category
Malicious
Download
efefa7.elf
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/proc/6212/task/6212/comm
very short file (no magic)
dropped
/tmp/qemu-open.Cip1DW (deleted)
ASCII text
dropped
/tmp/qemu-open.KGNrcW (deleted)
data
dropped
/tmp/qemu-open.TPu1FT (deleted)
ASCII text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
/tmp/efefa7.elf
/tmp/efefa7.elf
/tmp/efefa7.elf
-
/tmp/efefa7.elf
-
/tmp/efefa7.elf
-
/tmp/efefa7.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.FO5ZfineMZ /tmp/tmp.v0FO74aAEU /tmp/tmp.XjvKqPdygn
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.FO5ZfineMZ
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.FO5ZfineMZ
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.FO5ZfineMZ /tmp/tmp.v0FO74aAEU /tmp/tmp.XjvKqPdygn
There are 15 hidden processes, click here to show them.

Domains

Name
IP
Malicious
raw.awaken-network.net
141.98.10.142
raw.awaken-network.net. [malformed]
unknown

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
141.98.10.142
raw.awaken-network.net
Lithuania
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
7f86b24f3000
page read and write
56330aa7d000
page execute read
7f86b168c000
page read and write
56330ccec000
page read and write
56330d118000
page read and write
56330acd7000
page read and write
7f86b2682000
page read and write
7f85ac032000
page execute read
56330acd7000
page read and write
7f85ac032000
page execute read
56330d118000
page read and write
7f86b1f26000
page read and write
7fff06f5e000
page execute read
7f85ac158000
page read and write
56330d13c000
page read and write
56330ccd5000
page execute and read and write
7f86b2288000
page read and write
7f86b2b92000
page read and write
7f85ac048000
page read and write
7f86b2a45000
page read and write
7f86b2bd7000
page read and write
7f85ac048000
page read and write
7f86b2864000
page read and write
7f86b2516000
page read and write
7f86b1f26000
page read and write
7f86b2b6e000
page read and write
56330ccec000
page read and write
7f86b168c000
page read and write
7f86abfff000
page read and write
7f86b2516000
page read and write
7f86b24f3000
page read and write
7f85ac03b000
page read and write
7f86b2b92000
page read and write
7f86b2b92000
page read and write
7f86ac021000
page read and write
7f85ac048000
page read and write
7f86b2b6e000
page read and write
7f85ac032000
page execute read
7f86ac021000
page read and write
7fff06f5e000
page execute read
56330acd7000
page read and write
56330acce000
page read and write
7fff06f5e000
page execute read
7fff06e8c000
page read and write
7f86b2288000
page read and write
7f86b2682000
page read and write
7f86b2516000
page read and write
7f86b1e94000
page read and write
7fff06e8c000
page read and write
56330acce000
page read and write
7f86b2a45000
page read and write
7f86b2bd7000
page read and write
7f86abfff000
page read and write
56330ccd5000
page execute and read and write
7f86ac021000
page read and write
56330ccec000
page read and write
56330d15f000
page read and write
7f86b2a45000
page read and write
56330aa7d000
page execute read
7f86b2864000
page read and write
7f86b24f3000
page read and write
7f86abfff000
page read and write
7f85ac03b000
page read and write
7f86b2864000
page read and write
7f85ac03b000
page read and write
7f86b2b6e000
page read and write
7f86b2682000
page read and write
7f86b1e94000
page read and write
7fff06e8c000
page read and write
56330aa7d000
page execute read
56330ccd5000
page execute and read and write
7f86b2288000
page read and write
56330acce000
page read and write
7f86b2bd7000
page read and write
7f86b1f26000
page read and write
7f86b168c000
page read and write
7f86b1e94000
page read and write
There are 67 hidden memdumps, click here to show them.