IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7fc9a002f000
page execute read
malicious
7fc9a002f000
page execute read
malicious
55e35d214000
page execute read
7fcaa5f0d000
page read and write
7fcaa5f76000
page read and write
7fcaa0021000
page read and write
7fcaa5233000
page read and write
7fcaa5de4000
page read and write
7fcaa5627000
page read and write
7fcaa5627000
page read and write
55e35f483000
page read and write
7fffb9162000
page read and write
7fcaa5a21000
page read and write
7fc9a0037000
page read and write
55e35d465000
page read and write
55e35d214000
page execute read
7fcaa0021000
page read and write
7fcaa5c03000
page read and write
7fcaa4a2b000
page read and write
55e35f46c000
page execute and read and write
7fffb9162000
page read and write
7fcaa5892000
page read and write
7fffb91be000
page execute read
7fcaa5f0d000
page read and write
7fcaa5de4000
page read and write
7fcaa52c5000
page read and write
7fcaa5233000
page read and write
55e35d46e000
page read and write
7fcaa5f31000
page read and write
55e3604e2000
page read and write
7fc9a003f000
page read and write
7fcaa5f76000
page read and write
7fca9ffff000
page read and write
55e35d46e000
page read and write
7fcaa5892000
page read and write
55e35d465000
page read and write
55e35f483000
page read and write
7fc9a003f000
page read and write
7fcaa5c03000
page read and write
7fcaa58b5000
page read and write
7fcaa52c5000
page read and write
7fcaa5f31000
page read and write
7fc9a0037000
page read and write
55e35f46c000
page execute and read and write
55e3604e2000
page read and write
7fffb91be000
page execute read
7fcaa5a21000
page read and write
7fcaa58b5000
page read and write
7fca9ffff000
page read and write
7fcaa4a2b000
page read and write
There are 40 hidden memdumps, click here to show them.