Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/na.elf
|
/tmp/na.elf
|
||
/tmp/na.elf
|
-
|
||
/tmp/na.elf
|
-
|
||
/tmp/na.elf
|
-
|
||
/bin/sh
|
sh -c "ps -A -o pid,cmd --no-headers"
|
||
/bin/sh
|
-
|
||
/usr/bin/ps
|
ps -A -o pid,cmd --no-headers
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://upx.sf.net
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
daisy.ubuntu.com
|
162.213.35.25
|
||
cnc.merisprivate.net
|
194.120.230.54
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
194.120.230.54
|
cnc.merisprivate.net
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
805c000
|
page execute read
|
|||
805c000
|
page execute read
|
|||
805c000
|
page execute read
|
|||
8a98000
|
page read and write
|
|||
8a98000
|
page read and write
|
|||
805f000
|
page read and write
|
|||
c02000
|
page execute read
|
|||
8ab1000
|
page read and write
|
|||
f7f3b000
|
page execute read
|
|||
ffcee000
|
page read and write
|
|||
c02000
|
page execute read
|
|||
ffcee000
|
page read and write
|
|||
c02000
|
page execute read
|
|||
f7f3b000
|
page execute read
|
|||
805f000
|
page read and write
|
|||
ffcee000
|
page read and write
|
|||
805f000
|
page read and write
|
|||
8a98000
|
page read and write
|
|||
f7f3b000
|
page execute read
|
There are 9 hidden memdumps, click here to show them.