Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
zJk9UEOnQ7
|
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
|
initial sample
|
||
/proc/5310/oom_score_adj
|
ASCII text
|
dropped
|
||
/run/sshd.pid
|
ASCII text
|
dropped
|
||
/var/cache/motd-news
|
ASCII text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/bin/dash
|
n/a
|
||
/usr/bin/cat
|
cat /tmp/tmp.91tEJtbEWc
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/cat
|
cat /tmp/tmp.91tEJtbEWc
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.91tEJtbEWc /tmp/tmp.Zus0sicMvy /tmp/tmp.qH6x8mL5YT
|
||
/tmp/zJk9UEOnQ7
|
/tmp/zJk9UEOnQ7
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/tmp/zJk9UEOnQ7
|
n/a
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/sbin/sshd
|
/usr/sbin/sshd -t
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/sbin/sshd
|
/usr/sbin/sshd -D
|
There are 36 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://127.0.0.1:52869/picdesc.xml
|
91.214.119.55
|
||
http://37.0.9.202/bins/Hilix.mips
|
unknown
|
||
http://127.0.0.1:52869/wanipcn.xml
|
91.214.119.55
|
||
http://schemas.xmlsoap.org/soap/encoding/
|
unknown
|
||
https://ubuntu.com/blog/microk8s-memory-optimisation
|
unknown
|
||
http://schemas.xmlsoap.org/soap/envelope/
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
185.220.10.243
|
unknown
|
Spain
|
||
45.63.53.210
|
unknown
|
United States
|
||
103.92.122.33
|
unknown
|
India
|
||
177.200.187.233
|
unknown
|
Brazil
|
||
45.130.62.177
|
unknown
|
Israel
|
||
185.114.210.159
|
unknown
|
Switzerland
|
||
45.199.228.247
|
unknown
|
Seychelles
|
||
45.21.146.145
|
unknown
|
United States
|
||
105.103.188.148
|
unknown
|
Algeria
|
||
197.143.201.55
|
unknown
|
Algeria
|
||
91.90.138.87
|
unknown
|
Israel
|
||
197.19.253.197
|
unknown
|
Tunisia
|
||
197.44.77.183
|
unknown
|
Egypt
|
||
185.38.220.159
|
unknown
|
Poland
|
||
68.49.212.219
|
unknown
|
United States
|
||
45.153.14.26
|
unknown
|
Russian Federation
|
||
156.43.68.96
|
unknown
|
United Kingdom
|
||
172.255.87.27
|
unknown
|
United States
|
||
45.246.175.184
|
unknown
|
Egypt
|
||
45.246.175.186
|
unknown
|
Egypt
|
||
185.203.160.64
|
unknown
|
Iran (ISLAMIC Republic Of)
|
||
91.130.14.16
|
unknown
|
Austria
|
||
91.130.14.18
|
unknown
|
Austria
|
||
91.167.86.160
|
unknown
|
France
|
||
185.204.16.74
|
unknown
|
Czech Republic
|
||
185.21.99.33
|
unknown
|
Austria
|
||
185.166.97.85
|
unknown
|
Switzerland
|
||
91.167.86.167
|
unknown
|
France
|
||
91.178.113.232
|
unknown
|
Belgium
|
||
164.85.190.86
|
unknown
|
Brazil
|
||
91.183.234.36
|
unknown
|
Belgium
|
||
91.67.33.164
|
unknown
|
Germany
|
||
41.5.41.242
|
unknown
|
South Africa
|
||
91.67.33.166
|
unknown
|
Germany
|
||
8.40.221.25
|
unknown
|
United States
|
||
45.44.104.180
|
unknown
|
Canada
|
||
185.78.7.94
|
unknown
|
United Kingdom
|
||
91.163.145.86
|
unknown
|
France
|
||
45.237.182.82
|
unknown
|
Brazil
|
||
92.212.74.4
|
unknown
|
Germany
|
||
91.219.76.54
|
unknown
|
Netherlands
|
||
59.1.116.39
|
unknown
|
Korea Republic of
|
||
45.221.254.31
|
unknown
|
Benin
|
||
197.51.4.224
|
unknown
|
Egypt
|
||
91.184.212.207
|
unknown
|
Cyprus
|
||
45.50.54.54
|
unknown
|
United States
|
||
45.111.37.150
|
unknown
|
Egypt
|
||
201.67.116.239
|
unknown
|
Brazil
|
||
91.211.55.231
|
unknown
|
Russian Federation
|
||
45.145.30.185
|
unknown
|
Turkey
|
||
66.55.202.243
|
unknown
|
United States
|
||
119.104.84.1
|
unknown
|
Japan
|
||
45.227.105.109
|
unknown
|
Brazil
|
||
156.158.50.68
|
unknown
|
Tanzania United Republic of
|
||
197.211.66.63
|
unknown
|
South Africa
|
||
197.92.49.8
|
unknown
|
South Africa
|
||
2.135.247.91
|
unknown
|
Kazakhstan
|
||
45.127.206.114
|
unknown
|
Indonesia
|
||
45.106.6.117
|
unknown
|
Egypt
|
||
96.78.116.253
|
unknown
|
United States
|
||
89.61.196.207
|
unknown
|
Germany
|
||
185.50.154.127
|
unknown
|
United Kingdom
|
||
24.29.246.12
|
unknown
|
United States
|
||
91.100.152.119
|
unknown
|
Denmark
|
||
41.227.43.22
|
unknown
|
Tunisia
|
||
45.94.158.129
|
unknown
|
Ukraine
|
||
45.117.212.64
|
unknown
|
India
|
||
70.49.63.170
|
unknown
|
Canada
|
||
160.181.79.212
|
unknown
|
South Africa
|
||
140.123.127.169
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
202.203.120.2
|
unknown
|
China
|
||
45.104.92.38
|
unknown
|
Egypt
|
||
185.156.114.171
|
unknown
|
Norway
|
||
185.228.32.110
|
unknown
|
Austria
|
||
45.104.148.70
|
unknown
|
Egypt
|
||
183.236.151.32
|
unknown
|
China
|
||
185.86.223.119
|
unknown
|
Iceland
|
||
45.30.40.163
|
unknown
|
United States
|
||
126.11.178.137
|
unknown
|
Japan
|
||
41.3.151.166
|
unknown
|
South Africa
|
||
91.66.119.226
|
unknown
|
Germany
|
||
45.91.88.230
|
unknown
|
Romania
|
||
45.9.118.68
|
unknown
|
Netherlands
|
||
103.200.224.62
|
unknown
|
China
|
||
45.48.194.85
|
unknown
|
United States
|
||
41.217.104.32
|
unknown
|
Nigeria
|
||
91.198.173.169
|
unknown
|
Switzerland
|
||
208.73.200.152
|
unknown
|
United States
|
||
185.78.207.26
|
unknown
|
United Kingdom
|
||
185.171.27.35
|
unknown
|
Turkey
|
||
185.156.114.187
|
unknown
|
Norway
|
||
185.248.70.63
|
unknown
|
Netherlands
|
||
156.13.155.42
|
unknown
|
New Zealand
|
||
185.19.109.116
|
unknown
|
United Kingdom
|
||
156.49.160.41
|
unknown
|
Sweden
|
||
185.25.208.150
|
unknown
|
United Kingdom
|
||
45.21.146.194
|
unknown
|
United States
|
||
45.246.175.149
|
unknown
|
Egypt
|
||
45.242.108.56
|
unknown
|
Egypt
|
||
42.122.248.206
|
unknown
|
China
|
There are 90 hidden IPs, click here to show them.