IOC Report
WiT9fhQAMr.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/WiT9fhQAMr.elf
/tmp/WiT9fhQAMr.elf
/tmp/WiT9fhQAMr.elf
-
/tmp/WiT9fhQAMr.elf
-
/tmp/WiT9fhQAMr.elf
-

Domains

Name
IP
Malicious
drumev.eu
93.123.85.140

IPs

IP
Domain
Country
Malicious
93.123.85.140
drumev.eu
Bulgaria

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffea98fa000
page read and write
7ffea99c8000
page execute read
7ffea98fa000
page read and write
610000
page read and write
60e000
page read and write
e28000
page read and write
40c000
page execute read
60e000
page read and write
610000
page read and write
610000
page read and write
e28000
page read and write
7ffea99c8000
page execute read
60e000
page read and write
7ffea98fa000
page read and write
e28000
page read and write
40c000
page execute read
40c000
page execute read
7ffea99c8000
page execute read
There are 8 hidden memdumps, click here to show them.