IOC Report
SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.ATtwu24ZWJ /tmp/tmp.NdgjzYv9SV /tmp/tmp.hAuNO4RoFi
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.ATtwu24ZWJ /tmp/tmp.NdgjzYv9SV /tmp/tmp.hAuNO4RoFi
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
-
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
-

Domains

Name
IP
Malicious
iranistrash.libre
unknown
malicious

IPs

IP
Domain
Country
Malicious
5.230.228.47
unknown
Germany
malicious
5.230.228.46
unknown
Germany
malicious
5.230.228.42
unknown
Germany
malicious
5.230.228.23
unknown
Germany
malicious
5.230.228.44
unknown
Germany
malicious
5.230.228.62
unknown
Germany
malicious
194.156.98.15
unknown
Russian Federation
malicious
5.230.122.81
unknown
Germany
5.230.122.80
unknown
Germany
172.217.192.127
unknown
United States
5.230.229.83
unknown
Germany
5.230.118.247
unknown
Germany
There are 2 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7f88206c1000
page read and write
564d3c479000
page read and write
7f8718035000
page read and write
7f88200e5000
page read and write
7f8817fff000
page read and write
7f88208a2000
page read and write
7f8820a34000
page read and write
564d387d6000
page execute read
7f88209cb000
page read and write
564d3aa2e000
page execute and read and write
7f8820350000
page read and write
7f8818021000
page read and write
7f88209ef000
page read and write
7ffe624c4000
page read and write
564d3aa45000
page read and write
564d38a30000
page read and write
7f881fd83000
page read and write
7ffe625f8000
page execute read
7f881fcf1000
page read and write
7f881f4e9000
page read and write
7f8820373000
page read and write
7f88204df000
page read and write
7f871802d000
page execute read
564d38a27000
page read and write
7f871803c000
page read and write
There are 15 hidden memdumps, click here to show them.