IOC Report
garm.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/garm.elf
/tmp/garm.elf
/tmp/garm.elf
-
/tmp/garm.elf
-
/tmp/garm.elf
-
/tmp/garm.elf
-
/tmp/garm.elf
-

URLs

Name
IP
Malicious
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown

Domains

Name
IP
Malicious
swimminginboats.geek
139.59.59.19
malicious
howyoudoinbby.dyn
138.197.7.36
malicious
therealniggas.parody
138.197.155.229
malicious
howyoudoinbby.dyn. [malformed]
unknown
malicious
swimminginboats.geek. [malformed]
unknown
malicious
therealniggas.parody. [malformed]
unknown
malicious
daisy.ubuntu.com
162.213.35.25
magicalmalware.pirate
157.245.110.224

IPs

IP
Domain
Country
Malicious
41.199.210.18
unknown
Egypt
malicious
41.172.232.54
unknown
South Africa
197.116.38.197
unknown
Algeria
197.206.163.99
unknown
Algeria
197.45.56.16
unknown
Egypt
41.121.55.93
unknown
South Africa
156.154.241.61
unknown
United States
197.20.132.143
unknown
Tunisia
197.251.50.112
unknown
Sudan
156.99.154.33
unknown
United States
197.237.231.9
unknown
Kenya
197.125.42.5
unknown
Egypt
197.191.9.255
unknown
Ghana
156.183.18.122
unknown
Egypt
197.58.66.145
unknown
Egypt
156.199.251.121
unknown
Egypt
197.41.205.2
unknown
Egypt
41.215.35.80
unknown
Kenya
41.244.252.219
unknown
Cameroon
156.124.11.108
unknown
United States
41.198.207.240
unknown
South Africa
156.241.153.121
unknown
Seychelles
156.149.192.225
unknown
New Zealand
156.171.83.11
unknown
Egypt
156.123.110.237
unknown
United States
156.177.147.113
unknown
Egypt
156.158.196.231
unknown
Tanzania United Republic of
41.242.248.210
unknown
South Africa
197.132.31.220
unknown
Egypt
197.47.0.119
unknown
Egypt
197.190.60.121
unknown
Ghana
156.215.141.83
unknown
Egypt
41.205.129.214
unknown
Namibia
197.57.40.36
unknown
Egypt
197.205.16.180
unknown
Algeria
41.102.150.126
unknown
Algeria
41.203.40.51
unknown
South Africa
41.76.191.245
unknown
Kenya
156.204.84.38
unknown
Egypt
197.140.232.135
unknown
Algeria
41.3.151.109
unknown
South Africa
41.169.49.255
unknown
South Africa
41.68.176.249
unknown
Egypt
41.3.198.153
unknown
South Africa
197.190.60.116
unknown
Ghana
41.140.45.215
unknown
Morocco
197.43.51.139
unknown
Egypt
41.247.23.176
unknown
South Africa
41.64.233.33
unknown
Egypt
197.43.98.193
unknown
Egypt
156.61.222.155
unknown
United Kingdom
41.122.162.176
unknown
South Africa
197.190.103.233
unknown
Ghana
41.102.161.78
unknown
Algeria
156.61.222.149
unknown
United Kingdom
197.243.212.169
unknown
Namibia
41.124.253.220
unknown
South Africa
156.252.248.242
unknown
Seychelles
41.239.14.43
unknown
Egypt
197.143.173.222
unknown
Algeria
156.208.152.83
unknown
Egypt
41.8.37.15
unknown
South Africa
41.255.246.74
unknown
Libyan Arab Jamahiriya
41.59.85.252
unknown
Tanzania United Republic of
41.213.138.6
unknown
Reunion
197.57.39.68
unknown
Egypt
197.89.97.98
unknown
South Africa
197.91.228.131
unknown
South Africa
156.165.149.222
unknown
Egypt
197.152.130.222
unknown
Tanzania United Republic of
156.93.180.101
unknown
United States
156.2.32.9
unknown
United States
156.31.48.92
unknown
Brunei Darussalam
41.44.132.63
unknown
Egypt
41.23.119.146
unknown
South Africa
197.78.128.241
unknown
South Africa
197.73.219.68
unknown
South Africa
41.121.55.51
unknown
South Africa
41.23.87.241
unknown
South Africa
41.239.14.11
unknown
Egypt
197.125.216.226
unknown
Egypt
197.132.199.65
unknown
Egypt
197.149.159.201
unknown
unknown
197.125.216.222
unknown
Egypt
197.248.91.247
unknown
Kenya
197.96.124.58
unknown
South Africa
197.146.254.225
unknown
Morocco
197.30.88.178
unknown
Tunisia
41.148.201.142
unknown
South Africa
197.109.183.61
unknown
South Africa
156.8.250.161
unknown
South Africa
197.51.4.236
unknown
Egypt
156.231.211.142
unknown
Seychelles
156.103.193.168
unknown
United States
156.215.116.49
unknown
Egypt
156.68.234.139
unknown
United States
197.152.227.95
unknown
Tanzania United Republic of
41.158.217.51
unknown
Gabon
197.43.98.133
unknown
Egypt
156.147.46.180
unknown
Korea Republic of
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7f38b8029000
page execute read
malicious
7f38b8029000
page execute read
malicious
7f38b8029000
page execute read
malicious
556fe7ecd000
page read and write
7f39bdb5d000
page read and write
7f39b8021000
page read and write
7ffdba19e000
page execute read
7f38b8039000
page read and write
7f39bdebf000
page read and write
556fe9ee2000
page read and write
7f39be14d000
page read and write
7f39be2b9000
page read and write
556fe9ee2000
page read and write
556fe7c73000
page execute read
7f39be49b000
page read and write
7f39bdebf000
page read and write
7f38b8037000
page read and write
7f39be12a000
page read and write
7f39bd2c3000
page read and write
7f39bdebf000
page read and write
7f39be12a000
page read and write
7f39be67c000
page read and write
556fe7ec4000
page read and write
7f39be7c9000
page read and write
7f38b8037000
page read and write
556fe9ecb000
page execute and read and write
7f39be80e000
page read and write
7f39bdb5d000
page read and write
7f39be12a000
page read and write
556fea4f7000
page read and write
7f39be2b9000
page read and write
7f39be67c000
page read and write
7ffdba189000
page read and write
556fe9ecb000
page execute and read and write
556fe7c73000
page execute read
7f39be80e000
page read and write
7f39bd2c3000
page read and write
556fea4f7000
page read and write
7f39b7fff000
page read and write
7f39bdacb000
page read and write
7ffdba189000
page read and write
7f39bdb5d000
page read and write
556fe9ecb000
page execute and read and write
556fe7c73000
page execute read
7ffdba19e000
page execute read
7f39be7a5000
page read and write
7f39b7fff000
page read and write
556fe9ee2000
page read and write
556fe7ecd000
page read and write
556fe7ec4000
page read and write
7f38b8039000
page read and write
7f39be7c9000
page read and write
7f39bd2c3000
page read and write
7f39be49b000
page read and write
7f39be7a5000
page read and write
7f39be80e000
page read and write
7f38b8031000
page read and write
556fea4f7000
page read and write
7f39be7c9000
page read and write
7f38b8031000
page read and write
7f39b8021000
page read and write
7f39be67c000
page read and write
7f39be14d000
page read and write
7f39b7fff000
page read and write
7f39b8021000
page read and write
7f39be14d000
page read and write
7ffdba19e000
page execute read
7ffdba189000
page read and write
556fe7ec4000
page read and write
7f39be7a5000
page read and write
7f39bdacb000
page read and write
7f39be2b9000
page read and write
556fe7ecd000
page read and write
7f39bdacb000
page read and write
7f38b8037000
page read and write
7f39be49b000
page read and write
7f38b8031000
page read and write
There are 67 hidden memdumps, click here to show them.