Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/botnet.sh4.elf
|
/tmp/botnet.sh4.elf
|
||
/tmp/botnet.sh4.elf
|
-
|
||
/bin/sh
|
sh -c "rm -rf bin/busybox && mkdir bin; >bin/busybox && mv /tmp/botnet.sh4.elf bin/busybox; chmod 777 bin/busybox"
|
||
/bin/sh
|
-
|
||
/usr/bin/rm
|
rm -rf bin/busybox
|
||
/bin/sh
|
-
|
||
/usr/bin/mkdir
|
mkdir bin
|
||
/bin/sh
|
-
|
||
/usr/bin/mv
|
mv /tmp/botnet.sh4.elf bin/busybox
|
||
/bin/sh
|
-
|
||
/usr/bin/chmod
|
chmod 777 bin/busybox
|
||
/tmp/botnet.sh4.elf
|
-
|
||
/tmp/botnet.sh4.elf
|
-
|
There are 3 hidden processes, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
88.212.208.57
|
unknown
|
Russian Federation
|
||
107.244.110.159
|
unknown
|
United States
|
||
78.31.168.26
|
unknown
|
Germany
|
||
96.212.50.92
|
unknown
|
United States
|
||
125.248.115.171
|
unknown
|
Korea Republic of
|
||
216.203.121.111
|
unknown
|
United States
|
||
76.11.253.168
|
unknown
|
United States
|
||
138.112.32.73
|
unknown
|
United States
|
||
81.147.140.12
|
unknown
|
United Kingdom
|
||
203.76.27.221
|
unknown
|
Australia
|
||
9.250.155.36
|
unknown
|
United States
|
||
35.146.139.255
|
unknown
|
United States
|
||
80.222.97.49
|
unknown
|
Finland
|
||
120.78.240.209
|
unknown
|
China
|
||
146.147.76.79
|
unknown
|
United States
|
||
41.9.191.230
|
unknown
|
South Africa
|
||
128.252.8.151
|
unknown
|
United States
|
||
37.218.181.144
|
unknown
|
Kyrgyzstan
|
||
203.6.121.113
|
unknown
|
Australia
|
||
100.236.185.83
|
unknown
|
United States
|
||
192.161.76.10
|
unknown
|
United States
|
||
17.249.203.182
|
unknown
|
United States
|
||
177.45.17.160
|
unknown
|
Brazil
|
||
121.180.78.95
|
unknown
|
Korea Republic of
|
||
148.53.4.45
|
unknown
|
United States
|
||
46.127.188.23
|
unknown
|
Switzerland
|
||
218.194.100.1
|
unknown
|
China
|
||
70.218.66.129
|
unknown
|
United States
|
||
8.65.78.248
|
unknown
|
United States
|
||
147.34.23.135
|
unknown
|
United States
|
||
65.3.68.55
|
unknown
|
United States
|
||
150.109.191.87
|
unknown
|
Singapore
|
||
70.125.95.206
|
unknown
|
United States
|
||
43.137.36.124
|
unknown
|
Japan
|
||
105.66.179.121
|
unknown
|
Morocco
|
||
169.247.137.101
|
unknown
|
United States
|
||
72.51.253.243
|
unknown
|
United States
|
||
83.211.189.87
|
unknown
|
Italy
|
||
212.249.205.55
|
unknown
|
Switzerland
|
||
47.183.199.104
|
unknown
|
United States
|
||
143.233.109.92
|
unknown
|
Greece
|
||
94.227.159.196
|
unknown
|
Belgium
|
||
182.178.198.247
|
unknown
|
Pakistan
|
||
49.43.26.113
|
unknown
|
India
|
||
135.87.62.170
|
unknown
|
United States
|
||
36.177.52.222
|
unknown
|
China
|
||
152.180.4.6
|
unknown
|
United States
|
||
117.45.233.9
|
unknown
|
China
|
||
78.212.249.212
|
unknown
|
France
|
||
144.212.243.251
|
unknown
|
United States
|
||
113.72.119.63
|
unknown
|
China
|
||
86.15.7.191
|
unknown
|
United Kingdom
|
||
162.145.242.81
|
unknown
|
Australia
|
||
61.210.62.100
|
unknown
|
Japan
|
||
77.203.28.40
|
unknown
|
France
|
||
153.44.231.212
|
unknown
|
Norway
|
||
23.170.62.188
|
unknown
|
Reserved
|
||
210.108.185.174
|
unknown
|
Korea Republic of
|
||
115.208.213.246
|
unknown
|
China
|
||
92.159.155.179
|
unknown
|
France
|
||
65.127.249.20
|
unknown
|
United States
|
||
114.120.232.137
|
unknown
|
Indonesia
|
||
86.56.41.165
|
unknown
|
Germany
|
||
115.107.75.34
|
unknown
|
China
|
||
46.113.39.90
|
unknown
|
Poland
|
||
114.40.69.255
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
198.14.9.4
|
unknown
|
United States
|
||
62.51.3.70
|
unknown
|
European Union
|
||
42.187.28.137
|
unknown
|
China
|
||
124.204.19.119
|
unknown
|
China
|
||
168.66.250.31
|
unknown
|
United States
|
||
37.207.231.62
|
unknown
|
Italy
|
||
72.190.162.43
|
unknown
|
United States
|
||
196.187.126.96
|
unknown
|
Tunisia
|
||
209.75.197.148
|
unknown
|
United States
|
||
200.33.215.38
|
unknown
|
Mexico
|
||
147.84.49.161
|
unknown
|
Spain
|
||
79.73.45.127
|
unknown
|
United Kingdom
|
||
95.214.117.146
|
unknown
|
Russian Federation
|
||
149.230.227.41
|
unknown
|
Germany
|
||
152.234.121.128
|
unknown
|
Brazil
|
||
204.141.81.232
|
unknown
|
United States
|
||
78.73.118.13
|
unknown
|
Sweden
|
||
220.104.50.227
|
unknown
|
Japan
|
||
112.25.71.133
|
unknown
|
China
|
||
194.195.203.143
|
unknown
|
Germany
|
||
132.121.181.11
|
unknown
|
United States
|
||
96.147.8.202
|
unknown
|
United States
|
||
223.196.163.149
|
unknown
|
India
|
||
164.149.28.40
|
unknown
|
South Africa
|
||
51.146.187.19
|
unknown
|
United Kingdom
|
||
32.32.129.176
|
unknown
|
United States
|
||
110.19.71.215
|
unknown
|
China
|
||
189.115.120.20
|
unknown
|
Brazil
|
||
208.123.248.244
|
unknown
|
United States
|
||
17.162.2.22
|
unknown
|
United States
|
||
95.85.236.154
|
unknown
|
Czech Republic
|
||
84.189.216.125
|
unknown
|
Germany
|
||
102.54.126.221
|
unknown
|
Morocco
|
||
46.21.243.5
|
unknown
|
Russian Federation
|
There are 90 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7ffb70412000
|
page execute read
|
|||
7ffbf0021000
|
page read and write
|
|||
7ffbf6788000
|
page read and write
|
|||
7ffd9dae9000
|
page read and write
|
|||
55f8fbeb3000
|
page execute and read and write
|
|||
7ffbf63a1000
|
page read and write
|
|||
7ffbf6bfc000
|
page read and write
|
|||
55f8fc8df000
|
page read and write
|
|||
55f8f9c97000
|
page execute read
|
|||
7ffbf6ad3000
|
page read and write
|
|||
7ffbf5901000
|
page read and write
|
|||
7ffbf6112000
|
page read and write
|
|||
7ffbf6104000
|
page read and write
|
|||
7ffbf6763000
|
page read and write
|
|||
55f8f9ead000
|
page read and write
|
|||
55f8fbeca000
|
page read and write
|
|||
7ffbf0000000
|
page read and write
|
|||
7ffb70422000
|
page read and write
|
|||
7ffd9db78000
|
page execute read
|
|||
7ffbf6c49000
|
page read and write
|
|||
55f8f9eb5000
|
page read and write
|
|||
7ffbf6c04000
|
page read and write
|
|||
7ffb70425000
|
page read and write
|
There are 13 hidden memdumps, click here to show them.