IOC Report
5lg7zd.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/5lg7zd.elf
/tmp/5lg7zd.elf
/tmp/5lg7zd.elf
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --dport 61234 -j DROP

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious
http://crl.certigna.fr/certignarootca.crl
unknown
http://crl.xrampsecurity.com/XGCA.crl
unknown
http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl0
unknown
http://crl.securetrust.com/SGCA.crl/etc/ssl/certs/Sonera_Class_2_Root_CA.pem/etc/ssl/certs/Sonera_Cl
unknown
http://crl.securetrust.com/SGCA.crlStaat
unknown
http://crl.securetrust.com/SGCA.crl
unknown
http://www.accv.es/legislacion_c.htm0U
unknown
https://wwww.certigna.fr/autorites/0m
unknown
http://crl.certigna.fr/certignarootca.crlhttp://crl.dhimyotis.com/certignarootca.crl(c)
unknown
http://ocsp.accv.es0
unknown
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0B1
unknown
http://crl.dhimyotis.com/certignarootca.crl0
unknown
http://www.firmaprofesional.com/cps0
unknown
http://crl.securetrust.com/STCA.crl/etc/ssl/certs/Secure_Global_CA.pem/etc/ssl/certs/Secure_Global_C
unknown
http://repository.swisssign.com/0
unknown
http://crl.securetrust.com/SGCA.crl0
unknown
https://ocsp.quovadisoffshore.com
unknown
http://crl.certigna.fr/certignarootca.crlhttp://crl.dhimyotis.com/certignarootca.crl/etc/ssl/certs/C
unknown
http://crl.securetrust.com/STCA.crl0
unknown
https://ocsp.quovadisoffshore.comSSL.com
unknown
http://crl.xrampsecurity.com/XGCA.crl/etc/ssl/certs/ca-certificates.crt/etc/ssl/certs/ca-certificate
unknown
https://13::1ip6-localhostip6-loopbackhttps://vnc.wtffe00::ff00::ip6-localnet13
unknown
https://ocsp.quovadisoffshore.com/etc/ssl/certs/QuoVadis_Root_CA_1_G3.pem/etc/ssl/certs/QuoVadis_Roo
unknown
https://www.catcert.net/verarrel
unknown
http://crl.securetrust.com/STCA.crl
unknown
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
unknown
http://www.quovadisglobal.com/cps0
unknown
https://vnc.wtf
unknown
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
unknown
https://vnc.wtf/api/client
188.114.97.3
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0
unknown
http://crl.xrampsecurity.com/XGCA.crl0
unknown
https://www.catcert.net/verarrel05
unknown
http://crl.certigna.fr/certignarootca.crl01
unknown
http://www.quovadis.bm0
unknown
http://crl.dhimyotis.com/certignarootca.crl
unknown
http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl
unknown
http://ocsp.accv.es
unknown
http://www.accv.es00
unknown
https://ocsp.quovadisoffshore.com0
unknown
http://www.cert.fnmt.es/dpcs/0
unknown
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0;1
unknown
http://policy.camerfirma.com0
unknown
There are 34 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
vnc.wtf
188.114.97.3

IPs

IP
Domain
Country
Malicious
188.114.97.3
vnc.wtf
European Union
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7efc0d181000
page read and write
7efc21881000
page read and write
7efc21407000
page read and write
7ffe673de000
page execute read
7efc1f031000
page read and write
7ffe6737d000
page read and write
612000
page execute read
86d000
page read and write
c000800000
page read and write
7efc21960000
page read and write
7efbfd000000
page read and write
There are 1 hidden memdumps, click here to show them.