IOC Report
Satan.sh4.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/Satan.sh4.elf
/tmp/Satan.sh4.elf
/tmp/Satan.sh4.elf
-
/tmp/Satan.sh4.elf
-
/tmp/Satan.sh4.elf
-
/tmp/Satan.sh4.elf
-
/tmp/Satan.sh4.elf
-

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
193.84.71.119
unknown
Poland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f67f8504000
page read and write
7f6770428000
page read and write
7f6770427000
page read and write
7f67f7eb3000
page read and write
7f67f76a2000
page read and write
7f67f0000000
page read and write
7ffd37100000
page read and write
563f9eca0000
page execute and read and write
563f9f3ef000
page read and write
7f67f0021000
page read and write
7ffd37100000
page read and write
7f67f7ea5000
page read and write
7f67f0000000
page read and write
7f67f8874000
page read and write
7f67f0021000
page read and write
563f9ecb7000
page read and write
7f67f89a5000
page read and write
7ffd37159000
page execute read
7f6770414000
page execute read
7f67f8504000
page read and write
7f67f89ea000
page read and write
7f67f8529000
page read and write
7f6770425000
page read and write
563f9cca2000
page read and write
563f9eca0000
page execute and read and write
7f67f8874000
page read and write
7ffd37100000
page read and write
563f9ecb7000
page read and write
7f6770427000
page read and write
7f67f0000000
page read and write
563f9ecb7000
page read and write
563f9f416000
page read and write
7f67f89ea000
page read and write
563f9eca0000
page execute and read and write
7f67f7ea5000
page read and write
7f67f89a5000
page read and write
7f67f8529000
page read and write
563f9cca2000
page read and write
7f67f76a2000
page read and write
7f67f8142000
page read and write
7f6770414000
page execute read
7f67f8504000
page read and write
7f6770428000
page read and write
7f67f8874000
page read and write
7f67f0021000
page read and write
563f9ca84000
page execute read
7f67f7ea5000
page read and write
563f9ca84000
page execute read
7f67f89a5000
page read and write
7f67f899d000
page read and write
7f67f89ea000
page read and write
7f67f0000000
page read and write
7f67f899d000
page read and write
7f67f8504000
page read and write
7f67f7ea5000
page read and write
7f67f76a2000
page read and write
7f67f8529000
page read and write
7f67f7eb3000
page read and write
7f67f899d000
page read and write
563f9ecb7000
page read and write
7ffd37159000
page execute read
7f67f0021000
page read and write
7f6770425000
page read and write
563f9cca2000
page read and write
563f9ca84000
page execute read
7ffd37100000
page read and write
563f9cc9a000
page read and write
7f67f8529000
page read and write
7f67f8142000
page read and write
7f6770414000
page execute read
563f9cc9a000
page read and write
7f67f899d000
page read and write
563f9eca0000
page execute and read and write
7f67f8874000
page read and write
7f67f7eb3000
page read and write
563f9f3ef000
page read and write
563f9cca2000
page read and write
7f67f8142000
page read and write
7f6770425000
page read and write
7f67f89ea000
page read and write
7f6770414000
page execute read
7f67f7eb3000
page read and write
563f9cc9a000
page read and write
563f9ca84000
page execute read
7f67f76a2000
page read and write
7f6770425000
page read and write
7f67f8142000
page read and write
7ffd37159000
page execute read
7f67f89a5000
page read and write
563f9cc9a000
page read and write
563f9f416000
page read and write
7ffd37159000
page execute read
There are 82 hidden memdumps, click here to show them.