IOC Report

loading gif

Files

File Path
Type
Category
Malicious
zJk9UEOnQ7
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/proc/5310/oom_score_adj
ASCII text
dropped
clean
/run/sshd.pid
ASCII text
dropped
clean
/var/cache/motd-news
ASCII text
dropped
clean

Processes

Path
Cmdline
Malicious
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.91tEJtbEWc
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.91tEJtbEWc
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/rm
rm -f /tmp/tmp.91tEJtbEWc /tmp/tmp.Zus0sicMvy /tmp/tmp.qH6x8mL5YT
clean
/tmp/zJk9UEOnQ7
/tmp/zJk9UEOnQ7
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/tmp/zJk9UEOnQ7
n/a
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -t
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/sshd
/usr/sbin/sshd -D
clean
There are 36 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://127.0.0.1:52869/picdesc.xml
91.214.119.55
malicious
http://37.0.9.202/bins/Hilix.mips
unknown
malicious
http://127.0.0.1:52869/wanipcn.xml
91.214.119.55
malicious
http://schemas.xmlsoap.org/soap/encoding/
unknown
clean
https://ubuntu.com/blog/microk8s-memory-optimisation
unknown
clean
http://schemas.xmlsoap.org/soap/envelope/
unknown
clean

IPs

IP
Domain
Country
Malicious
185.220.10.243
unknown
Spain
clean
45.63.53.210
unknown
United States
clean
103.92.122.33
unknown
India
clean
177.200.187.233
unknown
Brazil
clean
45.130.62.177
unknown
Israel
clean
185.114.210.159
unknown
Switzerland
clean
45.199.228.247
unknown
Seychelles
clean
45.21.146.145
unknown
United States
clean
105.103.188.148
unknown
Algeria
clean
197.143.201.55
unknown
Algeria
clean
91.90.138.87
unknown
Israel
clean
197.19.253.197
unknown
Tunisia
clean
197.44.77.183
unknown
Egypt
clean
185.38.220.159
unknown
Poland
clean
68.49.212.219
unknown
United States
clean
45.153.14.26
unknown
Russian Federation
clean
156.43.68.96
unknown
United Kingdom
clean
172.255.87.27
unknown
United States
clean
45.246.175.184
unknown
Egypt
clean
45.246.175.186
unknown
Egypt
clean
185.203.160.64
unknown
Iran (ISLAMIC Republic Of)
clean
91.130.14.16
unknown
Austria
clean
91.130.14.18
unknown
Austria
clean
91.167.86.160
unknown
France
clean
185.204.16.74
unknown
Czech Republic
clean
185.21.99.33
unknown
Austria
clean
185.166.97.85
unknown
Switzerland
clean
91.167.86.167
unknown
France
clean
91.178.113.232
unknown
Belgium
clean
164.85.190.86
unknown
Brazil
clean
91.183.234.36
unknown
Belgium
clean
91.67.33.164
unknown
Germany
clean
41.5.41.242
unknown
South Africa
clean
91.67.33.166
unknown
Germany
clean
8.40.221.25
unknown
United States
clean
45.44.104.180
unknown
Canada
clean
185.78.7.94
unknown
United Kingdom
clean
91.163.145.86
unknown
France
clean
45.237.182.82
unknown
Brazil
clean
92.212.74.4
unknown
Germany
clean
91.219.76.54
unknown
Netherlands
clean
59.1.116.39
unknown
Korea Republic of
clean
45.221.254.31
unknown
Benin
clean
197.51.4.224
unknown
Egypt
clean
91.184.212.207
unknown
Cyprus
clean
45.50.54.54
unknown
United States
clean
45.111.37.150
unknown
Egypt
clean
201.67.116.239
unknown
Brazil
clean
91.211.55.231
unknown
Russian Federation
clean
45.145.30.185
unknown
Turkey
clean
66.55.202.243
unknown
United States
clean
119.104.84.1
unknown
Japan
clean
45.227.105.109
unknown
Brazil
clean
156.158.50.68
unknown
Tanzania United Republic of
clean
197.211.66.63
unknown
South Africa
clean
197.92.49.8
unknown
South Africa
clean
2.135.247.91
unknown
Kazakhstan
clean
45.127.206.114
unknown
Indonesia
clean
45.106.6.117
unknown
Egypt
clean
96.78.116.253
unknown
United States
clean
89.61.196.207
unknown
Germany
clean
185.50.154.127
unknown
United Kingdom
clean
24.29.246.12
unknown
United States
clean
91.100.152.119
unknown
Denmark
clean
41.227.43.22
unknown
Tunisia
clean
45.94.158.129
unknown
Ukraine
clean
45.117.212.64
unknown
India
clean
70.49.63.170
unknown
Canada
clean
160.181.79.212
unknown
South Africa
clean
140.123.127.169
unknown
Taiwan; Republic of China (ROC)
clean
202.203.120.2
unknown
China
clean
45.104.92.38
unknown
Egypt
clean
185.156.114.171
unknown
Norway
clean
185.228.32.110
unknown
Austria
clean
45.104.148.70
unknown
Egypt
clean
183.236.151.32
unknown
China
clean
185.86.223.119
unknown
Iceland
clean
45.30.40.163
unknown
United States
clean
126.11.178.137
unknown
Japan
clean
41.3.151.166
unknown
South Africa
clean
91.66.119.226
unknown
Germany
clean
45.91.88.230
unknown
Romania
clean
45.9.118.68
unknown
Netherlands
clean
103.200.224.62
unknown
China
clean
45.48.194.85
unknown
United States
clean
41.217.104.32
unknown
Nigeria
clean
91.198.173.169
unknown
Switzerland
clean
208.73.200.152
unknown
United States
clean
185.78.207.26
unknown
United Kingdom
clean
185.171.27.35
unknown
Turkey
clean
185.156.114.187
unknown
Norway
clean
185.248.70.63
unknown
Netherlands
clean
156.13.155.42
unknown
New Zealand
clean
185.19.109.116
unknown
United Kingdom
clean
156.49.160.41
unknown
Sweden
clean
185.25.208.150
unknown
United Kingdom
clean
45.21.146.194
unknown
United States
clean
45.246.175.149
unknown
Egypt
clean
45.242.108.56
unknown
Egypt
clean
42.122.248.206
unknown
China
clean
There are 90 hidden IPs, click here to show them.