IOC Report
cARM.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.aNyespp82r /tmp/tmp.IQcjuF3Dk3 /tmp/tmp.0bY9obFiN4
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.aNyespp82r /tmp/tmp.IQcjuF3Dk3 /tmp/tmp.0bY9obFiN4
/tmp/cARM.elf
/tmp/cARM.elf
/tmp/cARM.elf
-
/usr/bin/bash
bash -c "apt -y install curl && apt -y install hping3 && apt -y install screen\n"
/usr/bin/bash
-
/usr/bin/apt
apt -y install curl

URLs

Name
IP
Malicious
http://51.81.121.129/cARM
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
45.148.10.176
unknown
Italy
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f9a8e766000
page read and write
7f9a47e06000
page read and write
7f9a59f87000
page read and write
7ffd7caab000
page read and write
7f9a79f87000
page read and write
c000400000
page read and write
692000
page read and write
7f9a47df5000
page read and write
7f9a8e687000
page read and write
66e000
page read and write
7f9a49e06000
page read and write
51c000
page execute read
7f9a8e20d000
page read and write
7ffd7cbe0000
page execute read
7f9a8be37000
page read and write
7f9a47cf5000
page read and write
There are 6 hidden memdumps, click here to show them.