IOC Report
la.bot.arm6.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/la.bot.arm6.elf
/tmp/la.bot.arm6.elf

URLs

Name
IP
Malicious
http:///wget.sh
unknown
http:///curl.sh
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
558b3b892000
page read and write
7f13bdf73000
page read and write
7f13bd88f000
page read and write
7f12b802b000
page execute read
7f13bd624000
page read and write
7ffdba062000
page read and write
558b38fb4000
page read and write
7f12b803b000
page read and write
7f12b8034000
page read and write
7f13b7fff000
page read and write
558b3afd2000
page read and write
7f13bdc00000
page read and write
7f13bdde1000
page read and write
7ffdba07f000
page execute read
7f13b8021000
page read and write
7f13bd2c2000
page read and write
558b3afbb000
page execute and read and write
7f13bca28000
page read and write
7f13bda1e000
page read and write
558b38d63000
page execute read
558b38fbd000
page read and write
7f13bdf2e000
page read and write
7f13bd8b2000
page read and write
7f13bd230000
page read and write
7f13bdf0a000
page read and write
There are 15 hidden memdumps, click here to show them.