IOC Report
botnet.sh4.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/botnet.sh4.elf
/tmp/botnet.sh4.elf
/tmp/botnet.sh4.elf
-
/bin/sh
sh -c "rm -rf bin/busybox && mkdir bin; >bin/busybox && mv /tmp/botnet.sh4.elf bin/busybox; chmod 777 bin/busybox"
/bin/sh
-
/usr/bin/rm
rm -rf bin/busybox
/bin/sh
-
/usr/bin/mkdir
mkdir bin
/bin/sh
-
/usr/bin/mv
mv /tmp/botnet.sh4.elf bin/busybox
/bin/sh
-
/usr/bin/chmod
chmod 777 bin/busybox
/tmp/botnet.sh4.elf
-
/tmp/botnet.sh4.elf
-
There are 3 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
88.212.208.57
unknown
Russian Federation
107.244.110.159
unknown
United States
78.31.168.26
unknown
Germany
96.212.50.92
unknown
United States
125.248.115.171
unknown
Korea Republic of
216.203.121.111
unknown
United States
76.11.253.168
unknown
United States
138.112.32.73
unknown
United States
81.147.140.12
unknown
United Kingdom
203.76.27.221
unknown
Australia
9.250.155.36
unknown
United States
35.146.139.255
unknown
United States
80.222.97.49
unknown
Finland
120.78.240.209
unknown
China
146.147.76.79
unknown
United States
41.9.191.230
unknown
South Africa
128.252.8.151
unknown
United States
37.218.181.144
unknown
Kyrgyzstan
203.6.121.113
unknown
Australia
100.236.185.83
unknown
United States
192.161.76.10
unknown
United States
17.249.203.182
unknown
United States
177.45.17.160
unknown
Brazil
121.180.78.95
unknown
Korea Republic of
148.53.4.45
unknown
United States
46.127.188.23
unknown
Switzerland
218.194.100.1
unknown
China
70.218.66.129
unknown
United States
8.65.78.248
unknown
United States
147.34.23.135
unknown
United States
65.3.68.55
unknown
United States
150.109.191.87
unknown
Singapore
70.125.95.206
unknown
United States
43.137.36.124
unknown
Japan
105.66.179.121
unknown
Morocco
169.247.137.101
unknown
United States
72.51.253.243
unknown
United States
83.211.189.87
unknown
Italy
212.249.205.55
unknown
Switzerland
47.183.199.104
unknown
United States
143.233.109.92
unknown
Greece
94.227.159.196
unknown
Belgium
182.178.198.247
unknown
Pakistan
49.43.26.113
unknown
India
135.87.62.170
unknown
United States
36.177.52.222
unknown
China
152.180.4.6
unknown
United States
117.45.233.9
unknown
China
78.212.249.212
unknown
France
144.212.243.251
unknown
United States
113.72.119.63
unknown
China
86.15.7.191
unknown
United Kingdom
162.145.242.81
unknown
Australia
61.210.62.100
unknown
Japan
77.203.28.40
unknown
France
153.44.231.212
unknown
Norway
23.170.62.188
unknown
Reserved
210.108.185.174
unknown
Korea Republic of
115.208.213.246
unknown
China
92.159.155.179
unknown
France
65.127.249.20
unknown
United States
114.120.232.137
unknown
Indonesia
86.56.41.165
unknown
Germany
115.107.75.34
unknown
China
46.113.39.90
unknown
Poland
114.40.69.255
unknown
Taiwan; Republic of China (ROC)
198.14.9.4
unknown
United States
62.51.3.70
unknown
European Union
42.187.28.137
unknown
China
124.204.19.119
unknown
China
168.66.250.31
unknown
United States
37.207.231.62
unknown
Italy
72.190.162.43
unknown
United States
196.187.126.96
unknown
Tunisia
209.75.197.148
unknown
United States
200.33.215.38
unknown
Mexico
147.84.49.161
unknown
Spain
79.73.45.127
unknown
United Kingdom
95.214.117.146
unknown
Russian Federation
149.230.227.41
unknown
Germany
152.234.121.128
unknown
Brazil
204.141.81.232
unknown
United States
78.73.118.13
unknown
Sweden
220.104.50.227
unknown
Japan
112.25.71.133
unknown
China
194.195.203.143
unknown
Germany
132.121.181.11
unknown
United States
96.147.8.202
unknown
United States
223.196.163.149
unknown
India
164.149.28.40
unknown
South Africa
51.146.187.19
unknown
United Kingdom
32.32.129.176
unknown
United States
110.19.71.215
unknown
China
189.115.120.20
unknown
Brazil
208.123.248.244
unknown
United States
17.162.2.22
unknown
United States
95.85.236.154
unknown
Czech Republic
84.189.216.125
unknown
Germany
102.54.126.221
unknown
Morocco
46.21.243.5
unknown
Russian Federation
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffb70412000
page execute read
malicious
7ffbf0021000
page read and write
7ffbf6788000
page read and write
7ffd9dae9000
page read and write
55f8fbeb3000
page execute and read and write
7ffbf63a1000
page read and write
7ffbf6bfc000
page read and write
55f8fc8df000
page read and write
55f8f9c97000
page execute read
7ffbf6ad3000
page read and write
7ffbf5901000
page read and write
7ffbf6112000
page read and write
7ffbf6104000
page read and write
7ffbf6763000
page read and write
55f8f9ead000
page read and write
55f8fbeca000
page read and write
7ffbf0000000
page read and write
7ffb70422000
page read and write
7ffd9db78000
page execute read
7ffbf6c49000
page read and write
55f8f9eb5000
page read and write
7ffbf6c04000
page read and write
7ffb70425000
page read and write
There are 13 hidden memdumps, click here to show them.