IOC Report
boatnet.arm6.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.arm6.elf
/tmp/boatnet.arm6.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.4evUn5HxYP /tmp/tmp.YlGktNSe7E /tmp/tmp.NKlNdcWPWd
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.4evUn5HxYP /tmp/tmp.YlGktNSe7E /tmp/tmp.NKlNdcWPWd

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f725c027000
page execute read
malicious
7f73612bc000
page read and write
7f736160a000
page read and write
558a92b20000
page execute and read and write
7f73617eb000
page read and write
7f7360432000
page read and write
7f7361299000
page read and write
7f736102e000
page read and write
7f725c032000
page read and write
7ffc7074e000
page execute read
7f7361914000
page read and write
7f7360c3a000
page read and write
7f736197d000
page read and write
558a94603000
page read and write
7f735bfff000
page read and write
558a92b37000
page read and write
7f7361938000
page read and write
7f7360ccc000
page read and write
558a908c8000
page execute read
7ffc70679000
page read and write
558a90b22000
page read and write
558a90b19000
page read and write
7f735c021000
page read and write
7f7361428000
page read and write
There are 14 hidden memdumps, click here to show them.