IOC Report
na.elf

loading gifFilesProcessesURLsDomainsIPsMemdumps32101032Label

Files

File Path
Type
Category
Malicious
Download
na.elf
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
initial sample
malicious
/etc/CommId
ASCII text, with no line terminators
dropped
malicious
/usr/sbin/uplugplay
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
dropped
malicious
/memfd:snapd-env-generator (deleted)
ASCII text
dropped
/usr/lib/systemd/system/uplugplay.service
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/bin/sh
sh -c "pgrep na.elf"
/bin/sh
-
/usr/bin/pgrep
pgrep na.elf
/tmp/na.elf
-
/bin/sh
sh -c "pidof na.elf"
/bin/sh
-
/usr/bin/pidof
pidof na.elf
/tmp/na.elf
-
/bin/sh
sh -c "pgrep uplugplay"
/bin/sh
-
/usr/bin/pgrep
pgrep uplugplay
/tmp/na.elf
-
/bin/sh
sh -c "pidof uplugplay"
/bin/sh
-
/usr/bin/pidof
pidof uplugplay
/tmp/na.elf
-
/bin/sh
sh -c "pgrep upnpsetup"
/bin/sh
-
/usr/bin/pgrep
pgrep upnpsetup
/tmp/na.elf
-
/bin/sh
sh -c "pidof upnpsetup"
/bin/sh
-
/usr/bin/pidof
pidof upnpsetup
/tmp/na.elf
-
/bin/sh
sh -c "systemctl daemon-reload"
/bin/sh
-
/usr/bin/systemctl
systemctl daemon-reload
/tmp/na.elf
-
/bin/sh
sh -c "systemctl enable uplugplay.service"
/bin/sh
-
/usr/bin/systemctl
systemctl enable uplugplay.service
/tmp/na.elf
-
/bin/sh
sh -c "systemctl start uplugplay.service"
/bin/sh
-
/usr/bin/systemctl
systemctl start uplugplay.service
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/systemd
-
/usr/sbin/uplugplay
/usr/sbin/uplugplay
/usr/sbin/uplugplay
-
/usr/sbin/uplugplay
-
/bin/sh
sh -c "/usr/sbin/uplugplay -Dcomsvc"
/bin/sh
-
/usr/sbin/uplugplay
/usr/sbin/uplugplay -Dcomsvc
/usr/sbin/uplugplay
-
/bin/sh
sh -c hostnamectl
/bin/sh
-
/usr/bin/hostnamectl
hostnamectl
/usr/sbin/uplugplay
-
/bin/sh
sh -c hostnamectl
/bin/sh
-
/usr/bin/hostnamectl
hostnamectl
/usr/sbin/uplugplay
-
/bin/sh
sh -c "dmidecode --type baseboard"
/bin/sh
-
/usr/sbin/dmidecode
dmidecode --type baseboard
/usr/sbin/uplugplay
-
/bin/sh
sh -c uptime
/bin/sh
-
/usr/bin/uptime
uptime
/usr/sbin/uplugplay
-
/bin/sh
sh -c dmidecode
/bin/sh
-
/usr/sbin/dmidecode
dmidecode
/usr/sbin/uplugplay
-
/bin/sh
sh -c "uname -a"
/bin/sh
-
/usr/bin/uname
uname -a
/usr/sbin/uplugplay
-
/bin/sh
sh -c uptime
/bin/sh
-
/usr/bin/uptime
uptime
/usr/sbin/uplugplay
-
/bin/sh
sh -c "uname -a"
/bin/sh
-
/usr/bin/uname
uname -a
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-hostnamed
/lib/systemd/systemd-hostnamed
There are 72 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://152.36.128.18/cgi-bin/p.cgi?add=aW5mbyB7DQp2NC4wMlZfVW5peDY0DQpnYWxhc3NpYQ0KDQoyeCBJbnRlbChSKSBYZW9uKFIpIFNpbHZlciA0MjEwIENQVSBAIDIuMjBHSHoNCjMwNjQyOTYga0INCnZtd2FyZQ0KDQoNCg0KVWJ1bnR1ICYgMjAuMDQuMiBMVFMgKEZvY2FsIEZvc3NhKSAgJiBidWxsc2V5ZS9zaWQgJiANCg0KL3Vzci9zYmluLw0KIyBkbWlkZWNvZGUgMy4yfDE3NDM2NDAwOTcNCg0KfQ0K&i=OW94QYZJX86RU66K&h=galassia&enckey=ukgueiGmTCfARUqEWqEj8HJ+4lXqLv1NSijS+BVeZmIBwfQIK8u5nppAL+fT0dXxE0v7rbs+hfJ94jZCKPC1jSQX0YnGk3/6QcgtQNN3cSztTV7kPYwyZYPS3qBQTpfl9TH6cgxwwzd/ZoChwjnq+5ZiWVtENjo7sCFeC3ORlqU=
152.36.128.18
malicious
http://152.36.128.18/cgi-bin/p.cgi?r=15&i=OW94QYZJX86RU66K
152.36.128.18
malicious
http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.oni
unknown
http://upx.sf.net
unknown
http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
unknown
http://xinaccfea.org/cgi-bin/p.cgi?r=0&auth=hash&i=OW94QYZJX86RU66K&enckey=ukgueiGmTCfARUqEWqEj8HJ-4lXqLv1NSijS-BVeZmIBwfQIK8u5nppAL-fT0dXxE0v7rbs-hfJ94jZCKPC1jSQX0YnGk3/6QcgtQNN3cSztTV7kPYwyZYPS3qBQTpfl9TH6cgxwwzd/ZoChwjnq-5ZiWVtENjo7sCFeC3ORlqU_
85.214.228.140
https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
unknown
http://152.36.128.18/cgi-bin/p.cgi
unknown
http://dummy.zero/cgi-bin/prometei.cgi
unknown
http://xinchaoaccfea.net/cgi-bin/p.cgi?r=0&auth=hash&i=OW94QYZJX86RU66K&enckey=ukgueiGmTCfARUqEWqEj8HJ-4lXqLv1NSijS-BVeZmIBwfQIK8u5nppAL-fT0dXxE0v7rbs-hfJ94jZCKPC1jSQX0YnGk3/6QcgtQNN3cSztTV7kPYwyZYPS3qBQTpfl9TH6cgxwwzd/ZoChwjnq-5ZiWVtENjo7sCFeC3ORlqU_
34.229.166.50
http://152.36.128
unknown
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
xinchaoaccfea.net
34.229.166.50
xinaccfea.org
85.214.228.140
xinchaoaccfea.com
unknown

IPs

IP
Domain
Country
Malicious
152.36.128.18
unknown
United States
malicious
34.229.166.50
xinchaoaccfea.net
United States
85.214.228.140
xinaccfea.org
Germany
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
34e9000
page read and write
7ffd507af000
page execute read
7f0c30021000
page read and write
7f0c35003000
page read and write
1575000
page read and write
4f9000
page execute read
7ffd507a1000
page read and write
7f0c37808000
page read and write
7f0c36005000
page read and write
7f0c35804000
page read and write
7f0c36806000
page read and write
7f0c30000000
page read and write
7f0c38009000
page read and write
7f0c37007000
page read and write
7f0c3880a000
page read and write
7f0c2effe000
page read and write
7f0c2f7ff000
page read and write
7f0c34802000
page read and write
There are 8 hidden memdumps, click here to show them.