IOC Report
SecuriteInfo.com.Trojan.Linux.GenericKD.24576.12596.14920.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Ze5FXhQGmx /tmp/tmp.zyEcEV5Ve8 /tmp/tmp.ePWjI8w4A6
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Ze5FXhQGmx /tmp/tmp.zyEcEV5Ve8 /tmp/tmp.ePWjI8w4A6
/tmp/SecuriteInfo.com.Trojan.Linux.GenericKD.24576.12596.14920.elf
/tmp/SecuriteInfo.com.Trojan.Linux.GenericKD.24576.12596.14920.elf

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffffc8fd000
page read and write
55d12080d000
page read and write
7ffffc9d5000
page execute read
55d120a31000
page read and write
55d11e7f8000
page read and write
7fbf69a05000
page read and write
7fbf693a6000
page read and write
7fbf68b9e000
page read and write
7fbf6a088000
page read and write
7fbf69f57000
page read and write
7fbf64021000
page read and write
7fbf69a28000
page read and write
55d11e7ed000
page read and write
5f2000
page read and write
7fbf6a0cd000
page read and write
4000801000
page read and write
31f000
page execute read
55d11e563000
page execute read
7fbf69664000
page read and write
7fbf693b4000
page read and write
7fbf69a45000
page read and write
7fbf69d76000
page read and write
5b2000
page read and write
55d1207f6000
page execute and read and write
7fbf6a080000
page read and write
There are 15 hidden memdumps, click here to show them.