IOC Report
yakov.arm5.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.vKImhNH2RL /tmp/tmp.sGauTfuSqX /tmp/tmp.2IbEI6RwHG
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.vKImhNH2RL /tmp/tmp.sGauTfuSqX /tmp/tmp.2IbEI6RwHG
/tmp/yakov.arm5.elf
/tmp/yakov.arm5.elf

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f26e0023000
page execute read
malicious
55c0148f0000
page execute read
55c014b4a000
page read and write
7f27e4cfa000
page read and write
7ffd5e3c5000
page execute read
7f27e0021000
page read and write
7f27e505c000
page read and write
7f27e5638000
page read and write
55c014b41000
page read and write
7f26e003b000
page execute and read and write
7f27e5456000
page read and write
7ffd5e393000
page read and write
7f27e4c68000
page read and write
55c016b5f000
page read and write
7f26e003d000
page execute read
55c016b48000
page execute and read and write
7f27e5966000
page read and write
7f27e52c7000
page read and write
7f26e002b000
page read and write
7f27e5819000
page read and write
7f27dffff000
page read and write
7f27e5942000
page read and write
7f27e59ab000
page read and write
55c018ab9000
page read and write
7f27e52ea000
page read and write
7f27e4460000
page read and write
There are 16 hidden memdumps, click here to show them.