Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.aNyespp82r /tmp/tmp.IQcjuF3Dk3 /tmp/tmp.0bY9obFiN4
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.aNyespp82r /tmp/tmp.IQcjuF3Dk3 /tmp/tmp.0bY9obFiN4
|
||
/tmp/cARM.elf
|
/tmp/cARM.elf
|
||
/tmp/cARM.elf
|
-
|
||
/usr/bin/bash
|
bash -c "apt -y install curl && apt -y install hping3 && apt -y install screen\n"
|
||
/usr/bin/bash
|
-
|
||
/usr/bin/apt
|
apt -y install curl
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://51.81.121.129/cARM
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
109.202.202.202
|
unknown
|
Switzerland
|
||
91.189.91.43
|
unknown
|
United Kingdom
|
||
45.148.10.176
|
unknown
|
Italy
|
||
91.189.91.42
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f9a8e766000
|
page read and write
|
|||
7f9a47e06000
|
page read and write
|
|||
7f9a59f87000
|
page read and write
|
|||
7ffd7caab000
|
page read and write
|
|||
7f9a79f87000
|
page read and write
|
|||
c000400000
|
page read and write
|
|||
692000
|
page read and write
|
|||
7f9a47df5000
|
page read and write
|
|||
7f9a8e687000
|
page read and write
|
|||
66e000
|
page read and write
|
|||
7f9a49e06000
|
page read and write
|
|||
51c000
|
page execute read
|
|||
7f9a8e20d000
|
page read and write
|
|||
7ffd7cbe0000
|
page execute read
|
|||
7f9a8be37000
|
page read and write
|
|||
7f9a47cf5000
|
page read and write
|
There are 6 hidden memdumps, click here to show them.