IOC Report
cayo.i486.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.gwY62oDfHc /tmp/tmp.eq3MmwQRU8 /tmp/tmp.4pNKbmBgxQ
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.gwY62oDfHc
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.gwY62oDfHc
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.gwY62oDfHc /tmp/tmp.eq3MmwQRU8 /tmp/tmp.4pNKbmBgxQ
/tmp/cayo.i486.elf
/tmp/cayo.i486.elf
/tmp/cayo.i486.elf
-
/tmp/cayo.i486.elf
-
/tmp/cayo.i486.elf
-
There are 14 hidden processes, click here to show them.

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
207.244.199.83
unknown
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
805b000
page execute read
malicious
805b000
page execute read
malicious
805b000
page execute read
malicious
f7f36000
page execute read
ffc10000
page read and write
8063000
page read and write
f7f36000
page execute read
9454000
page read and write
9454000
page read and write
8063000
page read and write
805c000
page read and write
ffc10000
page read and write
9454000
page read and write
8063000
page read and write
ffc10000
page read and write
805c000
page read and write
f7f36000
page execute read
805c000
page read and write
There are 8 hidden memdumps, click here to show them.