IOC Report
HB2h7DKsXn.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.kez7MmyFty /tmp/tmp.9HED5QhUTD /tmp/tmp.RYTmACJWEm
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.kez7MmyFty /tmp/tmp.9HED5QhUTD /tmp/tmp.RYTmACJWEm
/tmp/HB2h7DKsXn.elf
/tmp/HB2h7DKsXn.elf
/tmp/HB2h7DKsXn.elf
-
/tmp/HB2h7DKsXn.elf
-

Domains

Name
IP
Malicious
download.vmfare.com
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
80f9000
page read and write
ffc37000
page read and write
80b3000
page execute read
f7f47000
page execute read
931c000
page read and write
80f9000
page read and write
ffc37000
page read and write
80b8000
page read and write
931c000
page read and write
f7f47000
page execute read
80b3000
page execute read
80b8000
page read and write
There are 2 hidden memdumps, click here to show them.