IOC Report
spc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/spc.elf
/tmp/spc.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.UkvbpLCbEf /tmp/tmp.sMwP72AK1y /tmp/tmp.A0rpXYDhiz
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.UkvbpLCbEf /tmp/tmp.sMwP72AK1y /tmp/tmp.A0rpXYDhiz

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f13d7d56000
page read and write
7fffe7f26000
page execute read
7f13d725e000
page read and write
7fffe7e0d000
page read and write
5586ccb4d000
page read and write
7f13d74fb000
page read and write
7f13d0000000
page read and write
7f12d001e000
page execute read
7f12d0023000
page read and write
5586ceb6b000
page read and write
5586cc91f000
page execute read
5586cf497000
page read and write
7f13d7da3000
page read and write
5586ccb56000
page read and write
7f13d7c2d000
page read and write
7f13d7d5e000
page read and write
7f13d726c000
page read and write
7f12d001f000
page read and write
7f13d6a5b000
page read and write
7f13d78bd000
page read and write
5586ceb54000
page execute and read and write
7f13d0021000
page read and write
7f13d78e2000
page read and write
There are 13 hidden memdumps, click here to show them.