IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/run/systemd/resolve/stub-resolv.conf
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
154.213.187.206
unknown
Seychelles

Memdumps

Base Address
Regiontype
Protect
Malicious
7f8e68030000
page execute read
malicious
7f8e68030000
page execute read
malicious
7f8f6fe89000
page read and write
7f8f68021000
page read and write
7ffc577cb000
page read and write
7f8e6803e000
page read and write
7f8f6ffb2000
page read and write
55eec1c4c000
page read and write
7f8f7001b000
page read and write
7f8e6803e000
page read and write
7f8f6f2d8000
page read and write
55eebf1d9000
page read and write
55eebef7f000
page execute read
7f8f6f6cc000
page read and write
7f8f6f36a000
page read and write
7f8f6fca8000
page read and write
7f8f6ffd6000
page read and write
55eebef7f000
page execute read
7ffc577cb000
page read and write
7f8f6f937000
page read and write
7f8f67fff000
page read and write
55eec11ee000
page read and write
55eebf1d0000
page read and write
7f8f6fe89000
page read and write
7f8f6f6cc000
page read and write
7f8f6fac6000
page read and write
7f8f6f937000
page read and write
7f8f6f95a000
page read and write
7f8f7001b000
page read and write
7f8f68021000
page read and write
7f8e68038000
page read and write
7f8f6fac6000
page read and write
7f8f6ead0000
page read and write
7f8f6fca8000
page read and write
7f8e68038000
page read and write
55eebf1d9000
page read and write
7f8f6f2d8000
page read and write
7f8f6ffd6000
page read and write
7f8f6f95a000
page read and write
7f8f6ffb2000
page read and write
7ffc577d4000
page execute read
7ffc577d4000
page execute read
7f8f67fff000
page read and write
55eebf1d0000
page read and write
7f8f6f36a000
page read and write
55eec11d7000
page execute and read and write
7f8f6ead0000
page read and write
55eec11d7000
page execute and read and write
55eec1c4c000
page read and write
55eec11ee000
page read and write
There are 40 hidden memdumps, click here to show them.