IOC Report
ppc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/ppc.elf
/tmp/ppc.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.3LJXLBJDpY /tmp/tmp.hxt2XFYAzN /tmp/tmp.54hUUxWXmv
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.3LJXLBJDpY /tmp/tmp.hxt2XFYAzN /tmp/tmp.54hUUxWXmv

IPs

IP
Domain
Country
Malicious
54.217.10.153
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7223f90000
page execute read
malicious
55eba4fe3000
page execute and read and write
7f73191ed000
page read and write
55eba2fe5000
page read and write
7f7318abb000
page read and write
7ffe681be000
page execute read
55eba2d5a000
page execute read
7f7223f93000
page execute and read and write
7f7223f94000
page read and write
7f7314000000
page read and write
7f731882c000
page read and write
7ffe681af000
page read and write
55eba6bb1000
page read and write
7f731881e000
page read and write
55eba4ff9000
page read and write
7f7318ea2000
page read and write
55eba2fdd000
page read and write
7f7223f91000
page execute and read and write
7f7318e7d000
page read and write
7f731931e000
page read and write
7f7319316000
page read and write
7f7319363000
page read and write
7f7314021000
page read and write
There are 13 hidden memdumps, click here to show them.