IOC Report
17CiAkKMyC.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.czFjcWPh1i /tmp/tmp.ElHTL6aAuP /tmp/tmp.rpE6mXwnI3
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.czFjcWPh1i /tmp/tmp.ElHTL6aAuP /tmp/tmp.rpE6mXwnI3

URLs

Name
IP
Malicious
http://185.196.10.215/bins/x86
unknown
http://185.196.10.215/bins/mips;
unknown
http://185.196.10.215/atp%20-O%20-%3E%20/tmp/kh;sh%20/tmp/kh%27$
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://185.196.10.215/bins/mips
unknown
http://purenetworks.com/HNAP1/
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
185.125.190.26
unknown
United Kingdom