IOC Report
dlr.arm6.elf

loading gif

Files

File Path
Type
Category
Malicious
dlr.arm6.elf
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
initial sample
malicious
/tmp/byte
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
dropped
malicious

Processes

Path
Cmdline
Malicious
/tmp/dlr.arm6.elf
/tmp/dlr.arm6.elf
/usr/lib/systemd/systemd
-
/usr/lib/snapd/snap-failure
/usr/lib/snapd/snap-failure snapd
/usr/lib/snapd/snap-failure
-
/usr/bin/systemctl
systemctl stop snapd.socket
/usr/lib/snapd/snap-failure
-

IPs

IP
Domain
Country
Malicious
154.216.20.69
unknown
Seychelles

Memdumps

Base Address
Regiontype
Protect
Malicious
7f204e4f2000
page read and write
7f204e6d3000
page read and write
7f204dbb4000
page read and write
564dcaf1c000
page read and write
7f2048021000
page read and write
564dcaccb000
page execute read
7f204db22000
page read and write
7f204e865000
page read and write
7f204e820000
page read and write
564dccf3a000
page read and write
7f204e1a4000
page read and write
7f204e181000
page read and write
564dcd90d000
page read and write
7f204e310000
page read and write
7f1f48020000
page read and write
7f1f48018000
page execute read
7ffdf3e2d000
page execute read
7f204d31a000
page read and write
564dccf23000
page execute and read and write
7f204e7fc000
page read and write
7ffdf3e1d000
page read and write
7f204df16000
page read and write
564dcaf25000
page read and write
7f2047fff000
page read and write
There are 14 hidden memdumps, click here to show them.