IOC Report
SecuriteInfo.com.Linux.Siggen.9999.29850.12766.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.63Oryc2QkA /tmp/tmp.pzcsQIkaj1 /tmp/tmp.lNL7x3qj92
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.63Oryc2QkA /tmp/tmp.pzcsQIkaj1 /tmp/tmp.lNL7x3qj92
/tmp/SecuriteInfo.com.Linux.Siggen.9999.29850.12766.elf
/tmp/SecuriteInfo.com.Linux.Siggen.9999.29850.12766.elf

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

Memdumps

Base Address
Regiontype
Protect
Malicious
7fc620028000
page execute read
malicious
55afc4204000
page execute and read and write
7ffe187e0000
page execute read
7fc71ffff000
page read and write
7fc7276cc000
page read and write
7fc726dc2000
page read and write
7fc727050000
page read and write
55afc21fd000
page read and write
55afc4d48000
page read and write
7fc727711000
page read and write
7fc62003a000
page read and write
55afc421b000
page read and write
7fc72757f000
page read and write
7fc726a60000
page read and write
7fc7276a8000
page read and write
55afc2206000
page read and write
7fc72702d000
page read and write
55afc1fac000
page execute read
7fc720021000
page read and write
7fc7261c6000
page read and write
7ffe187a6000
page read and write
7fc7271bc000
page read and write
7fc72739e000
page read and write
7fc7269ce000
page read and write
There are 14 hidden memdumps, click here to show them.