Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.ATtwu24ZWJ /tmp/tmp.NdgjzYv9SV /tmp/tmp.hAuNO4RoFi
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.ATtwu24ZWJ /tmp/tmp.NdgjzYv9SV /tmp/tmp.hAuNO4RoFi
|
||
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
|
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
|
||
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
|
-
|
||
/tmp/SecuriteInfo.com.ELF.Mirai-CVD.15130.25224.elf
|
-
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
iranistrash.libre
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
5.230.228.47
|
unknown
|
Germany
|
||
5.230.228.46
|
unknown
|
Germany
|
||
5.230.228.42
|
unknown
|
Germany
|
||
5.230.228.23
|
unknown
|
Germany
|
||
5.230.228.44
|
unknown
|
Germany
|
||
5.230.228.62
|
unknown
|
Germany
|
||
194.156.98.15
|
unknown
|
Russian Federation
|
||
5.230.122.81
|
unknown
|
Germany
|
||
5.230.122.80
|
unknown
|
Germany
|
||
172.217.192.127
|
unknown
|
United States
|
||
5.230.229.83
|
unknown
|
Germany
|
||
5.230.118.247
|
unknown
|
Germany
|
There are 2 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f88206c1000
|
page read and write
|
|||
564d3c479000
|
page read and write
|
|||
7f8718035000
|
page read and write
|
|||
7f88200e5000
|
page read and write
|
|||
7f8817fff000
|
page read and write
|
|||
7f88208a2000
|
page read and write
|
|||
7f8820a34000
|
page read and write
|
|||
564d387d6000
|
page execute read
|
|||
7f88209cb000
|
page read and write
|
|||
564d3aa2e000
|
page execute and read and write
|
|||
7f8820350000
|
page read and write
|
|||
7f8818021000
|
page read and write
|
|||
7f88209ef000
|
page read and write
|
|||
7ffe624c4000
|
page read and write
|
|||
564d3aa45000
|
page read and write
|
|||
564d38a30000
|
page read and write
|
|||
7f881fd83000
|
page read and write
|
|||
7ffe625f8000
|
page execute read
|
|||
7f881fcf1000
|
page read and write
|
|||
7f881f4e9000
|
page read and write
|
|||
7f8820373000
|
page read and write
|
|||
7f88204df000
|
page read and write
|
|||
7f871802d000
|
page execute read
|
|||
564d38a27000
|
page read and write
|
|||
7f871803c000
|
page read and write
|
There are 15 hidden memdumps, click here to show them.