IOC Report

loading gif

Files

File Path
Type
Category
Malicious
MPnFvIsvJp
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/proc/5308/oom_score_adj
ASCII text
dropped
clean
/run/sshd.pid
ASCII text
dropped
clean
/var/cache/motd-news
ASCII text
dropped
clean

Processes

Path
Cmdline
Malicious
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.nd5wZIclrj
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.nd5wZIclrj
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/rm
rm -f /tmp/tmp.nd5wZIclrj /tmp/tmp.zShyQQ7qTu /tmp/tmp.3SdD1ZBLJc
clean
/tmp/MPnFvIsvJp
/tmp/MPnFvIsvJp
clean
/tmp/MPnFvIsvJp
n/a
clean
/tmp/MPnFvIsvJp
n/a
clean
/tmp/MPnFvIsvJp
n/a
clean
/tmp/MPnFvIsvJp
n/a
clean
/tmp/MPnFvIsvJp
n/a
clean
/tmp/MPnFvIsvJp
n/a
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -t
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -D
clean
There are 19 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://ubuntu.com/blog/microk8s-memory-optimisation
unknown
clean

IPs

IP
Domain
Country
Malicious
53.112.165.99
unknown
Germany
clean
162.249.159.72
unknown
United States
clean
38.189.106.217
unknown
United States
clean
146.117.193.114
unknown
unknown
clean
197.45.56.18
unknown
Egypt
clean
79.112.91.127
unknown
Romania
clean
159.230.61.6
unknown
United States
clean
104.119.90.60
unknown
United States
clean
73.210.5.139
unknown
United States
clean
185.13.32.132
unknown
Russian Federation
clean
95.195.139.140
unknown
Sweden
clean
109.142.99.132
unknown
Belgium
clean
84.141.10.139
unknown
Germany
clean
2.144.217.201
unknown
Iran (ISLAMIC Republic Of)
clean
254.124.160.89
unknown
Reserved
clean
157.72.111.104
unknown
Japan
clean
166.2.57.61
unknown
United States
clean
196.98.136.157
unknown
Kenya
clean
105.214.52.124
unknown
South Africa
clean
76.177.163.230
unknown
United States
clean
18.69.142.225
unknown
United States
clean
47.253.16.98
unknown
United States
clean
222.209.131.174
unknown
China
clean
118.144.105.142
unknown
China
clean
73.26.71.206
unknown
United States
clean
216.44.168.130
unknown
United States
clean
207.34.254.92
unknown
Canada
clean
109.236.158.185
unknown
Germany
clean
4.26.92.139
unknown
United States
clean
78.143.58.117
unknown
Germany
clean
158.255.70.161
unknown
France
clean
249.229.94.227
unknown
Reserved
clean
118.28.147.193
unknown
China
clean
121.127.142.57
unknown
Korea Republic of
clean
82.231.167.86
unknown
France
clean
90.252.197.202
unknown
United Kingdom
clean
207.176.202.218
unknown
United States
clean
18.30.10.250
unknown
United States
clean
223.8.151.73
unknown
China
clean
192.20.120.58
unknown
United States
clean
200.167.253.216
unknown
Brazil
clean
86.68.72.129
unknown
France
clean
213.146.201.32
unknown
Portugal
clean
83.45.140.221
unknown
Spain
clean
152.26.195.240
unknown
United States
clean
221.0.56.164
unknown
China
clean
133.55.183.163
unknown
Japan
clean
2.17.213.1
unknown
European Union
clean
248.29.159.14
unknown
Reserved
clean
41.152.76.213
unknown
Egypt
clean
201.19.52.194
unknown
Brazil
clean
240.42.170.232
unknown
Reserved
clean
139.156.150.80
unknown
Netherlands
clean
118.64.199.38
unknown
China
clean
121.145.80.39
unknown
Korea Republic of
clean
98.59.61.81
unknown
United States
clean
196.61.253.222
unknown
South Africa
clean
205.153.15.252
unknown
United States
clean
223.10.93.212
unknown
China
clean
223.93.79.103
unknown
China
clean
175.12.84.190
unknown
China
clean
183.25.200.23
unknown
China
clean
93.137.66.222
unknown
Croatia (LOCAL Name: Hrvatska)
clean
189.40.178.46
unknown
Brazil
clean
180.140.66.56
unknown
China
clean
203.176.141.81
unknown
Cambodia
clean
45.146.92.203
unknown
Germany
clean
19.197.93.3
unknown
United States
clean
212.191.184.166
unknown
Poland
clean
60.23.101.154
unknown
China
clean
73.49.124.155
unknown
United States
clean
142.212.99.59
unknown
Canada
clean
79.106.115.210
unknown
Albania
clean
32.251.50.182
unknown
United States
clean
253.83.161.80
unknown
Reserved
clean
17.208.85.231
unknown
United States
clean
174.105.227.80
unknown
United States
clean
250.12.81.189
unknown
Reserved
clean
247.235.238.231
unknown
Reserved
clean
78.254.217.14
unknown
France
clean
216.239.120.101
unknown
United States
clean
243.115.4.52
unknown
Reserved
clean
89.146.240.88
unknown
Germany
clean
221.170.37.56
unknown
Japan
clean
73.191.86.218
unknown
United States
clean
94.11.229.252
unknown
United Kingdom
clean
1.201.22.138
unknown
Korea Republic of
clean
31.156.41.151
unknown
Italy
clean
211.43.179.175
unknown
Korea Republic of
clean
120.202.209.113
unknown
China
clean
186.106.106.120
unknown
Chile
clean
161.116.72.74
unknown
Spain
clean
195.225.21.96
unknown
Norway
clean
84.85.119.56
unknown
Netherlands
clean
184.169.138.101
unknown
United States
clean
81.235.47.61
unknown
Sweden
clean
59.247.33.40
unknown
China
clean
62.76.192.45
unknown
Russian Federation
clean
178.179.16.172
unknown
Russian Federation
clean
23.26.94.58
unknown
United States
clean
There are 90 hidden IPs, click here to show them.