Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/na.elf
|
/tmp/na.elf
|
||
/tmp/na.elf
|
-
|
||
/tmp/na.elf
|
-
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
ru.coziest.lol
|
38.60.198.180
|
||
f.codingdrunk.cc
|
38.54.57.248
|
||
2joints.libre
|
156.244.7.75
|
||
r3racegame.indy
|
154.223.21.228
|
||
kr3ddnsnet1.indy
|
154.223.21.228
|
||
kr2ddnsnet.dyn
|
154.90.62.142
|
||
subcarrace.indy
|
154.223.21.228
|
||
nineteen.libre. [malformed]
|
unknown
|
||
imaverygoodbadboy.libre. [malformed]
|
unknown
|
||
fortyfivehundred.dyn. [malformed]
|
unknown
|
||
2joints.libre. [malformed]
|
unknown
|
||
eighteen.pirate
|
unknown
|
||
kr2ddnsnet.dyn. [malformed]
|
unknown
|
||
eighteen.pirate. [malformed]
|
unknown
|
||
r3racegame.indy. [malformed]
|
unknown
|
||
krddnsnet.dyn. [malformed]
|
unknown
|
||
21savage.dyn. [malformed]
|
unknown
|
||
ru.coziest.lol. [malformed]
|
unknown
|
||
daisy.ubuntu.com
|
162.213.35.25
|
There are 9 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
38.54.57.248
|
f.codingdrunk.cc
|
United States
|
||
154.90.62.142
|
kr2ddnsnet.dyn
|
Seychelles
|
||
156.244.7.75
|
2joints.libre
|
Seychelles
|
||
154.223.21.228
|
r3racegame.indy
|
Seychelles
|
||
38.60.198.180
|
ru.coziest.lol
|
United States
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7ffcb15f9000
|
page read and write
|
|||
559cafadf000
|
page read and write
|
|||
7fa93b8bc000
|
page read and write
|
|||
7fa93bc80000
|
page read and write
|
|||
559cb1af4000
|
page read and write
|
|||
7fa934000000
|
page read and write
|
|||
559cb273e000
|
page read and write
|
|||
7fa93c325000
|
page read and write
|
|||
7fa934021000
|
page read and write
|
|||
7fa93c2d8000
|
page read and write
|
|||
7fa93bfce000
|
page read and write
|
|||
7fa93bc5d000
|
page read and write
|
|||
7fa93adf6000
|
page read and write
|
|||
7fa93c1af000
|
page read and write
|
|||
559cb1add000
|
page execute and read and write
|
|||
7fa8b4458000
|
page read and write
|
|||
7fa93b5fe000
|
page read and write
|
|||
7fa93bc9d000
|
page read and write
|
|||
7fa8b4410000
|
page execute read
|
|||
7ffcb1600000
|
page execute read
|
|||
7fa93b60c000
|
page read and write
|
|||
7fa8b4451000
|
page read and write
|
|||
559cafad5000
|
page read and write
|
|||
7fa93c2e0000
|
page read and write
|
|||
559caf84d000
|
page execute read
|
There are 15 hidden memdumps, click here to show them.