IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Hilix.arm7
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/proc/5290/oom_score_adj
ASCII text
dropped
clean
/proc/5405/oom_score_adj
ASCII text
dropped
clean
/proc/5407/oom_score_adj
ASCII text
dropped
clean
/run/sshd.pid
ASCII text
dropped
clean

Processes

Path
Cmdline
Malicious
/tmp/Hilix.arm7
/tmp/Hilix.arm7
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/tmp/Hilix.arm7
n/a
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -t
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -D
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -t
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -D
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -t
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -D
clean
There are 22 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://127.0.0.1:52869/picdesc.xml
185.235.182.35
malicious
http://37.0.9.202/bins/Hilix.mips
unknown
malicious
http://127.0.0.1:52869/wanipcn.xml
185.235.182.35
malicious
http://schemas.xmlsoap.org/soap/encoding/
unknown
clean
http://schemas.xmlsoap.org/soap/envelope/
unknown
clean

IPs

IP
Domain
Country
Malicious
45.104.67.35
unknown
Egypt
clean
45.147.166.20
unknown
Czech Republic
clean
216.78.45.202
unknown
United States
clean
124.31.169.14
unknown
China
clean
91.31.35.104
unknown
Germany
clean
139.74.185.195
unknown
Finland
clean
45.202.220.158
unknown
Seychelles
clean
43.85.41.34
unknown
Japan
clean
45.23.237.231
unknown
United States
clean
122.145.97.123
unknown
Japan
clean
45.44.167.1
unknown
Canada
clean
45.219.30.118
unknown
Morocco
clean
185.231.215.230
unknown
Germany
clean
41.37.180.38
unknown
Egypt
clean
98.48.231.147
unknown
United States
clean
101.160.47.9
unknown
Australia
clean
197.89.97.62
unknown
South Africa
clean
45.12.189.24
unknown
United Kingdom
clean
185.49.104.0
unknown
Iran (ISLAMIC Republic Of)
clean
182.219.78.33
unknown
Korea Republic of
clean
185.15.150.47
unknown
Spain
clean
119.29.176.99
unknown
China
clean
178.206.173.128
unknown
Russian Federation
clean
91.219.76.67
unknown
Netherlands
clean
185.106.118.57
unknown
Russian Federation
clean
185.160.193.237
unknown
Lebanon
clean
41.127.73.178
unknown
South Africa
clean
45.243.89.42
unknown
Egypt
clean
185.60.44.215
unknown
Russian Federation
clean
185.199.179.22
unknown
Switzerland
clean
91.45.165.251
unknown
Germany
clean
91.167.86.166
unknown
France
clean
185.103.6.246
unknown
United Kingdom
clean
185.199.120.216
unknown
Serbia
clean
60.164.193.221
unknown
China
clean
91.120.152.23
unknown
Hungary
clean
141.118.215.7
unknown
Canada
clean
185.106.118.84
unknown
Russian Federation
clean
91.209.253.47
unknown
Saudi Arabia
clean
185.102.172.198
unknown
Netherlands
clean
185.106.118.88
unknown
Russian Federation
clean
185.41.19.241
unknown
Norway
clean
104.6.30.146
unknown
United States
clean
217.244.31.20
unknown
Germany
clean
41.240.109.234
unknown
Sudan
clean
170.69.95.123
unknown
United States
clean
41.117.228.155
unknown
South Africa
clean
91.7.145.16
unknown
Germany
clean
2.199.168.22
unknown
Italy
clean
45.93.168.230
unknown
Iran (ISLAMIC Republic Of)
clean
130.43.171.48
unknown
United Kingdom
clean
202.132.234.94
unknown
Taiwan; Republic of China (ROC)
clean
91.41.176.9
unknown
Germany
clean
91.118.21.130
unknown
Austria
clean
91.179.103.175
unknown
Belgium
clean
91.243.156.169
unknown
Spain
clean
185.19.109.132
unknown
United Kingdom
clean
185.108.193.73
unknown
Russian Federation
clean
41.171.231.152
unknown
South Africa
clean
63.156.139.155
unknown
United States
clean
91.121.98.244
unknown
France
clean
113.63.35.130
unknown
China
clean
91.131.88.122
unknown
Austria
clean
131.85.67.23
unknown
United States
clean
185.25.208.138
unknown
United Kingdom
clean
41.227.43.23
unknown
Tunisia
clean
45.214.217.169
unknown
Zambia
clean
91.136.66.241
unknown
United Kingdom
clean
91.130.62.100
unknown
Austria
clean
197.217.213.27
unknown
Angola
clean
91.21.45.255
unknown
Germany
clean
43.116.248.47
unknown
Japan
clean
197.252.76.102
unknown
Sudan
clean
137.180.202.181
unknown
United States
clean
156.76.237.19
unknown
United States
clean
197.195.100.248
unknown
Egypt
clean
44.214.129.38
unknown
United States
clean
91.158.194.94
unknown
Finland
clean
113.78.107.195
unknown
China
clean
185.113.220.220
unknown
Turkey
clean
197.12.31.221
unknown
Tunisia
clean
45.197.31.32
unknown
Seychelles
clean
185.251.30.158
unknown
Romania
clean
125.231.33.171
unknown
Taiwan; Republic of China (ROC)
clean
156.16.3.236
unknown
unknown
clean
91.147.188.148
unknown
Saudi Arabia
clean
45.221.254.62
unknown
Benin
clean
185.10.95.107
unknown
Germany
clean
91.190.247.23
unknown
Germany
clean
35.7.247.69
unknown
United States
clean
185.218.251.226
unknown
France
clean
91.137.158.179
unknown
Hungary
clean
58.8.118.229
unknown
Thailand
clean
23.199.141.103
unknown
United States
clean
160.226.233.255
unknown
South Africa
clean
45.13.195.4
unknown
Russian Federation
clean
173.132.255.217
unknown
United States
clean
73.217.64.0
unknown
United States
clean
185.187.222.109
unknown
Italy
clean
197.144.115.203
unknown
Morocco
clean
There are 90 hidden IPs, click here to show them.