IOC Report
wheiuwa4.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.LixYaMEdc6 /tmp/tmp.ch7km2Tn7N /tmp/tmp.UhXrX0YvVx
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.LixYaMEdc6 /tmp/tmp.ch7km2Tn7N /tmp/tmp.UhXrX0YvVx
/tmp/wheiuwa4.elf
/tmp/wheiuwa4.elf

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f046a7cf000
page read and write
7ffcced03000
page execute read
7f036403a000
page execute read
55649deca000
page read and write
55649bf53000
page read and write
7f0364047000
page read and write
7f036404b000
page read and write
7f0469945000
page read and write
556499f35000
page read and write
7f046acfe000
page read and write
7f0464021000
page read and write
7f046ae27000
page read and write
556499f3e000
page read and write
7f046a93b000
page read and write
55649bf3d000
page execute and read and write
7f046ab1d000
page read and write
7ffccec31000
page read and write
556499ce4000
page execute read
7f046a541000
page read and write
7f046a14d000
page read and write
7f046a1df000
page read and write
7f046ae90000
page read and write
7f046ae4b000
page read and write
7f046a7ac000
page read and write
There are 14 hidden memdumps, click here to show them.