IOC Report
wget.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/wget.elf
/tmp/wget.elf
/tmp/wget.elf
-
/tmp/wget.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.UMd1K2tj9b /tmp/tmp.7lqeN2d1oT /tmp/tmp.kYNUeneDCE
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.UMd1K2tj9b /tmp/tmp.7lqeN2d1oT /tmp/tmp.kYNUeneDCE

URLs

Name
IP
Malicious
160.22.160.59:4444
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

IPs

IP
Domain
Country
Malicious
160.22.160.59
unknown
unknown
malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
8063000
page execute read
malicious
8063000
page execute read
malicious
8c3e000
page read and write
ffc9d000
page read and write
8064000
page read and write
806b000
page read and write
f7fc4000
page execute read
f7fc4000
page execute read
8064000
page read and write
8c3e000
page read and write
806b000
page read and write
ffc9d000
page read and write
There are 2 hidden memdumps, click here to show them.