IOC Report
boatnet.spc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.spc.elf
/tmp/boatnet.spc.elf

URLs

Name
IP
Malicious
http://5.181.159.16/wget.sh;
unknown
http://5.181.159.16/idk/home.arm7;chmod
unknown
http://5.181.159.16/w.sh;
unknown
http://5.181.159.16/c.sh;
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://5.181.159.16/idk/home.mips
unknown
http://5.181.159.16/idk/home.mips;
unknown
http://5.181.159.16/idk/home.x86
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown

IPs

IP
Domain
Country
Malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f80d402b000
page execute read
malicious
7f81dc1fb000
page read and write
7f81d4000000
page read and write
5625e7ab9000
page execute and read and write
7ffecbfee000
page execute read
7f80d403b000
page read and write
7f81d4021000
page read and write
7f81db75b000
page read and write
7f81dca56000
page read and write
7f81dc92d000
page read and write
5625e5884000
page execute read
7ffecbeaa000
page read and write
7f81dca5e000
page read and write
5625e5ab2000
page read and write
5625e9ac0000
page read and write
7f81dbf5e000
page read and write
7f80d403c000
page read and write
5625e7ad0000
page read and write
5625e5abb000
page read and write
7f81dcaa3000
page read and write
7f81dc5e2000
page read and write
7f81dc5bd000
page read and write
7f81dbf6c000
page read and write
There are 13 hidden memdumps, click here to show them.