IOC Report
.i.elf

loading gif

Files

File Path
Type
Category
Malicious
.i.elf
ELF 32-bit LSB executable, ARM, EABI5 version 1 (GNU/Linux), statically linked, no section header
initial sample
malicious
/tmp/qemu-open.2H0wOg (deleted)
data
dropped

Processes

Path
Cmdline
Malicious
/tmp/.i.elf
/tmp/.i.elf
/tmp/.i.elf
-
/tmp/.i.elf
-
/bin/sh
/bin/sh -c "iptables -A INPUT -p tcp --destination-port 23 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 23 -j DROP
/tmp/.i.elf
-
/bin/sh
/bin/sh -c "iptables -A INPUT -p tcp --destination-port 7547 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 7547 -j DROP
/tmp/.i.elf
-
/bin/sh
/bin/sh -c "iptables -A INPUT -p tcp --destination-port 5555 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 5555 -j DROP
/tmp/.i.elf
-
/bin/sh
/bin/sh -c "iptables -A INPUT -p tcp --destination-port 5358 -j DROP"
/bin/sh
-
/usr/sbin/iptables
iptables -A INPUT -p tcp --destination-port 5358 -j DROP
/tmp/.i.elf
-
/bin/sh
/bin/sh -c "iptables -D INPUT -j CWMP_CR"
/bin/sh
-
/usr/sbin/iptables
iptables -D INPUT -j CWMP_CR
/tmp/.i.elf
-
/bin/sh
/bin/sh -c "iptables -X CWMP_CR"
/bin/sh
-
/usr/sbin/iptables
iptables -X CWMP_CR
/tmp/.i.elf
-
/bin/sh
/bin/sh -c "iptables -I INPUT -p udp --dport 27986 -j ACCEPT"
/bin/sh
-
/usr/sbin/iptables
iptables -I INPUT -p udp --dport 27986 -j ACCEPT
There are 20 hidden processes, click here to show them.

Domains

Name
IP
Malicious
router.bittorrent.com
unknown
router.utorrent.com
unknown

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fde00953000
page read and write
55e983a11000
page read and write
7fddfc021000
page read and write
7ffd8675c000
page read and write
55e981505000
page read and write
7fde017dd000
page read and write
55e9814fc000
page read and write
7fde01e59000
page read and write
7fde01949000
page read and write
7fde0115b000
page read and write
7fdcfc062000
page read and write
7ffd867aa000
page execute read
7fde017ba000
page read and write
7fde011ed000
page read and write
7fddfbfff000
page read and write
55e9812ab000
page execute read
55e98351a000
page read and write
7fdcfc080000
page execute and read and write
7fdcfc049000
page execute read
55e983503000
page execute and read and write
7fde01e35000
page read and write
7fde01d0c000
page read and write
7fde01e9e000
page read and write
7fde0154f000
page read and write
7fde01b2b000
page read and write
There are 15 hidden memdumps, click here to show them.