IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/run/systemd/resolve/stub-resolv.conf
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
154.213.187.206
unknown
Seychelles

Memdumps

Base Address
Regiontype
Protect
Malicious
7f5cf4030000
page execute read
malicious
7f5cf4030000
page execute read
malicious
7f5df4021000
page read and write
7f5dfb4a7000
page read and write
56050c968000
page read and write
56050e966000
page execute and read and write
7f5dfabc1000
page read and write
7f5df3fff000
page read and write
56050c95f000
page read and write
7f5dfa7cd000
page read and write
56050c968000
page read and write
56050e97d000
page read and write
7f5dfb510000
page read and write
7f5df3fff000
page read and write
7f5cf403f000
page read and write
7fff1fcb8000
page execute read
7f5cf4039000
page read and write
7f5df4021000
page read and write
7f5dfb19d000
page read and write
7f5dfb4cb000
page read and write
7f5dfae2c000
page read and write
56050e966000
page execute and read and write
7f5dfa85f000
page read and write
7f5dfb4a7000
page read and write
7fff1fc15000
page read and write
7f5cf4039000
page read and write
56050c70e000
page execute read
56050f79f000
page read and write
7f5dfae4f000
page read and write
7f5dfabc1000
page read and write
56050c70e000
page execute read
7f5dfae4f000
page read and write
56050f79f000
page read and write
7f5dfb37e000
page read and write
7f5dfb37e000
page read and write
7f5dfa7cd000
page read and write
7f5cf403f000
page read and write
7f5dfb19d000
page read and write
7f5dfafbb000
page read and write
7f5dfb510000
page read and write
7f5dfae2c000
page read and write
56050c95f000
page read and write
7f5df9fc5000
page read and write
7f5df9fc5000
page read and write
56050e97d000
page read and write
7f5dfb4cb000
page read and write
7fff1fc15000
page read and write
7f5dfa85f000
page read and write
7fff1fcb8000
page execute read
7f5dfafbb000
page read and write
There are 40 hidden memdumps, click here to show them.