IOC Report
main_arm5.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.PFgdWwxIAG /tmp/tmp.ztji1lVemX /tmp/tmp.Q7hSgNOfBy
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.PFgdWwxIAG /tmp/tmp.ztji1lVemX /tmp/tmp.Q7hSgNOfBy
/tmp/main_arm5.elf
/tmp/main_arm5.elf

Memdumps

Base Address
Regiontype
Protect
Malicious
7ff88bfb1000
page execute read
malicious
7ffe644fc000
page read and write
7ff991549000
page read and write
7ff99084b000
page read and write
5617e6564000
page execute and read and write
7ff99158e000
page read and write
7ff9908dd000
page read and write
5617e657b000
page read and write
7ff98c021000
page read and write
5617e455d000
page read and write
7ff991525000
page read and write
7ff990c3f000
page read and write
7ff88bfbe000
page read and write
7ff98bf7e000
page read and write
7ff88bfc4000
page read and write
7ffe645c1000
page execute read
7ff9913fc000
page read and write
7ff991039000
page read and write
5617e6885000
page read and write
7ff990eaa000
page read and write
5617e4566000
page read and write
7ff990ecd000
page read and write
5617e430c000
page execute read
7ff99121b000
page read and write
7ff98c000000
page read and write
There are 15 hidden memdumps, click here to show them.