IOC Report
arm.b.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.MBi4uDqKfa /tmp/tmp.iz63md9wLs /tmp/tmp.cAMoGgC5Xb
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.MBi4uDqKfa /tmp/tmp.iz63md9wLs /tmp/tmp.cAMoGgC5Xb
/tmp/arm.b.elf
/tmp/arm.b.elf
/tmp/arm.b.elf
-

IPs

IP
Domain
Country
Malicious
154.213.187.68
unknown
Seychelles
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f9c49766000
page read and write
7f9b44024000
page execute read
7f9c490a5000
page read and write
55f390bce000
page execute read
7f9c495d4000
page read and write
55f390e28000
page read and write
55f390e28000
page read and write
7f9b44024000
page execute read
7f9c49721000
page read and write
7f9c49721000
page read and write
7f9c493f3000
page read and write
7f9b44030000
page read and write
7f9c4821b000
page read and write
55f3933fd000
page read and write
7f9b4402d000
page read and write
7f9c48a23000
page read and write
7f9c49082000
page read and write
7ffe1d676000
page read and write
55f390e1f000
page read and write
55f392e3d000
page read and write
7f9c49211000
page read and write
7f9c48e17000
page read and write
7f9c48a23000
page read and write
55f3933fd000
page read and write
7f9c496fd000
page read and write
7f9c49766000
page read and write
7f9b44030000
page read and write
7f9c49211000
page read and write
7f9c493f3000
page read and write
7ffe1d676000
page read and write
55f392e3d000
page read and write
55f390e1f000
page read and write
7f9c496fd000
page read and write
7f9c43fff000
page read and write
7f9c48e17000
page read and write
55f390bce000
page execute read
55f392e26000
page execute and read and write
7f9c49082000
page read and write
7ffe1d6cc000
page execute read
7f9c490a5000
page read and write
7f9c4821b000
page read and write
7ffe1d6cc000
page execute read
7f9b4402d000
page read and write
7f9c48ab5000
page read and write
7f9c44021000
page read and write
7f9c44021000
page read and write
7f9c495d4000
page read and write
7f9c48ab5000
page read and write
7f9c43fff000
page read and write
55f392e26000
page execute and read and write
There are 40 hidden memdumps, click here to show them.