IOC Report
SecuriteInfo.com.ELF.Agent-BQZ.16715.24370.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.oBaB1zQMeX /tmp/tmp.NmodxJrXEu /tmp/tmp.LzhMMjFD4I
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.oBaB1zQMeX /tmp/tmp.NmodxJrXEu /tmp/tmp.LzhMMjFD4I
/tmp/SecuriteInfo.com.ELF.Agent-BQZ.16715.24370.elf
/tmp/SecuriteInfo.com.ELF.Agent-BQZ.16715.24370.elf

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fde74108000
page execute read
55933c9f0000
page read and write
7ffe2b297000
page read and write
7fdefb3af000
page read and write
7fdefc899000
page read and write
7fdef4000000
page read and write
55933c9d9000
page execute and read and write
7fdefc891000
page read and write
7fdefc239000
page read and write
7fdefc256000
page read and write
7fdef4021000
page read and write
7ffe2b3de000
page execute read
55933a9d1000
page read and write
7fdefc216000
page read and write
7fdefc587000
page read and write
55933a749000
page execute read
7fdefbe75000
page read and write
7fdefc8de000
page read and write
55933cfb1000
page read and write
7fdefbbc5000
page read and write
7fdefc768000
page read and write
55933a9db000
page read and write
7fdefbbb7000
page read and write
There are 13 hidden memdumps, click here to show them.