IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7efca8029000
page execute read
malicious
7efca8029000
page execute read
malicious
5654ac8c7000
page read and write
7ffc4310e000
page read and write
7efdae1f0000
page read and write
7efda8021000
page read and write
7efdadec2000
page read and write
5654ac8be000
page read and write
7efda8021000
page read and write
7efda7fff000
page read and write
7efdad4f2000
page read and write
7efdadb51000
page read and write
7efdae0a3000
page read and write
7efdadec2000
page read and write
5654ae8c5000
page execute and read and write
7efdadb74000
page read and write
7efdad584000
page read and write
7efdae235000
page read and write
7efdad8e6000
page read and write
5654ac66d000
page execute read
5654ae8dc000
page read and write
7efdadce0000
page read and write
7efca8032000
page read and write
5654ac66d000
page execute read
7efdae0a3000
page read and write
5654af78e000
page read and write
7efdaccea000
page read and write
7efdae235000
page read and write
7ffc431c9000
page execute read
7efdadb74000
page read and write
5654ae8c5000
page execute and read and write
7efdae1f0000
page read and write
7ffc431c9000
page execute read
7efda7fff000
page read and write
5654ae8dc000
page read and write
7ffc4310e000
page read and write
5654af78e000
page read and write
7efdadb51000
page read and write
7efdad8e6000
page read and write
7efca8038000
page read and write
5654ac8c7000
page read and write
7efca8038000
page read and write
7efdad584000
page read and write
7efdad4f2000
page read and write
7efdadce0000
page read and write
7efdae1cc000
page read and write
7efca8032000
page read and write
7efdae1cc000
page read and write
7efdaccea000
page read and write
5654ac8be000
page read and write
There are 40 hidden memdumps, click here to show them.