IOC Report
na.elf

loading gifFilesProcessesURLsDomainsIPsMemdumps32101032Label

Files

File Path
Type
Category
Malicious
Download
na.elf
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
initial sample
malicious
/etc/CommId
ASCII text, with no line terminators
dropped
malicious
/usr/sbin/uplugplay
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
dropped
malicious
/memfd:snapd-env-generator (deleted)
ASCII text
dropped
/usr/lib/systemd/system/uplugplay.service
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/bin/sh
sh -c "pgrep na.elf"
/bin/sh
-
/usr/bin/pgrep
pgrep na.elf
/tmp/na.elf
-
/bin/sh
sh -c "pidof na.elf"
/bin/sh
-
/usr/bin/pidof
pidof na.elf
/tmp/na.elf
-
/bin/sh
sh -c "pgrep uplugplay"
/bin/sh
-
/usr/bin/pgrep
pgrep uplugplay
/tmp/na.elf
-
/bin/sh
sh -c "pidof uplugplay"
/bin/sh
-
/usr/bin/pidof
pidof uplugplay
/tmp/na.elf
-
/bin/sh
sh -c "pgrep upnpsetup"
/bin/sh
-
/usr/bin/pgrep
pgrep upnpsetup
/tmp/na.elf
-
/bin/sh
sh -c "pidof upnpsetup"
/bin/sh
-
/usr/bin/pidof
pidof upnpsetup
/tmp/na.elf
-
/bin/sh
sh -c "systemctl daemon-reload"
/bin/sh
-
/usr/bin/systemctl
systemctl daemon-reload
/tmp/na.elf
-
/bin/sh
sh -c "systemctl enable uplugplay.service"
/bin/sh
-
/usr/bin/systemctl
systemctl enable uplugplay.service
/tmp/na.elf
-
/bin/sh
sh -c "systemctl start uplugplay.service"
/bin/sh
-
/usr/bin/systemctl
systemctl start uplugplay.service
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/systemd
-
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/system-environment-generators/snapd-env-generator
/usr/lib/systemd/systemd
-
/usr/sbin/uplugplay
/usr/sbin/uplugplay
/usr/sbin/uplugplay
-
/usr/sbin/uplugplay
-
/bin/sh
sh -c "/usr/sbin/uplugplay -Dcomsvc"
/bin/sh
-
/usr/sbin/uplugplay
/usr/sbin/uplugplay -Dcomsvc
/usr/sbin/uplugplay
-
/bin/sh
sh -c hostnamectl
/bin/sh
-
/usr/bin/hostnamectl
hostnamectl
/usr/sbin/uplugplay
-
/bin/sh
sh -c hostnamectl
/bin/sh
-
/usr/bin/hostnamectl
hostnamectl
/usr/sbin/uplugplay
-
/bin/sh
sh -c "dmidecode --type baseboard"
/bin/sh
-
/usr/sbin/dmidecode
dmidecode --type baseboard
/usr/sbin/uplugplay
-
/bin/sh
sh -c uptime
/bin/sh
-
/usr/bin/uptime
uptime
/usr/sbin/uplugplay
-
/bin/sh
sh -c "uname -a"
/bin/sh
-
/usr/bin/uname
uname -a
/usr/sbin/uplugplay
-
/bin/sh
sh -c "dmidecode --type baseboard"
/bin/sh
-
/usr/sbin/dmidecode
dmidecode --type baseboard
/usr/sbin/uplugplay
-
/bin/sh
sh -c "dmidecode --type baseboard"
/bin/sh
-
/usr/sbin/dmidecode
dmidecode --type baseboard
/usr/sbin/uplugplay
-
/bin/sh
sh -c "dmidecode --type baseboard"
/bin/sh
-
/usr/sbin/dmidecode
dmidecode --type baseboard
/usr/sbin/uplugplay
-
/bin/sh
sh -c "dmidecode --type baseboard"
/bin/sh
-
/usr/sbin/dmidecode
dmidecode --type baseboard
/usr/sbin/uplugplay
-
/bin/sh
sh -c "dmidecode --type baseboard"
/bin/sh
-
/usr/sbin/dmidecode
dmidecode --type baseboard
/usr/sbin/uplugplay
-
/bin/sh
sh -c dmidecode
/bin/sh
-
/usr/sbin/dmidecode
dmidecode
/usr/sbin/uplugplay
-
/bin/sh
sh -c uptime
/bin/sh
-
/usr/bin/uptime
uptime
/usr/sbin/uplugplay
-
/bin/sh
sh -c "uname -a"
/bin/sh
-
/usr/bin/uname
uname -a
/usr/lib/systemd/systemd
-
/lib/systemd/systemd-hostnamed
/lib/systemd/systemd-hostnamed
There are 92 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://152.36.128.18/cgi-bin/p.cgi?r=13&i=INE7RDXF3QIF20S8
152.36.128.18
malicious
http://152.36.128.18/cgi-bin/p.cgihttp://dummy.zero/cgi-bin/prometei.cgihttps://gb7ni5rgeexdcncj.oni
unknown
http://upx.sf.net
unknown
http://xinchaoagcfea.net/cgi-bin/p.cgi?r=0&auth=hash&i=INE7RDXF3QIF20S8&enckey=H8qpMGGfMcq73nQ8VRrkyLiMiXyBiKKD0IaKx3Farw3LKq/QZS33KsPTqzeEFCQgX458IfapasDSIJxVG2EWX39m3LHkpOBD3h12YCAEISJzQIHsfk5PPrAxxFqHDqOYAtj0U9100aFmgNY7R2eaKV8bLOFK7b34L9Tzs5v3ZFY_
13.213.51.196
http://mkhkjxgchtfgu7uhofxzgoawntfzrkdccymveektqgpxrpjb72oq.b32.i2p/cgi-bin/prometei.cgi
unknown
https://gb7ni5rgeexdcncj.onion/cgi-bin/prometei.cgi
unknown
http://xinagcfea.org/cgi-bin/p.cgi?r=0&auth=hash&i=INE7RDXF3QIF20S8&enckey=H8qpMGGfMcq73nQ8VRrkyLiMiXyBiKKD0IaKx3Farw3LKq/QZS33KsPTqzeEFCQgX458IfapasDSIJxVG2EWX39m3LHkpOBD3h12YCAEISJzQIHsfk5PPrAxxFqHDqOYAtj0U9100aFmgNY7R2eaKV8bLOFK7b34L9Tzs5v3ZFY_
85.214.228.140
http://152.36.128.18/cgi-bin/p.cgi
unknown
http://dummy.zero/cgi-bin/prometei.cgi
unknown
http://152.36.128
unknown

Domains

Name
IP
Malicious
xinchaoagcfea.net
13.213.51.196
xinagcfea.org
85.214.228.140
xinchaoagcfea.com
unknown

IPs

IP
Domain
Country
Malicious
152.36.128.18
unknown
United States
malicious
85.214.228.140
xinagcfea.org
Germany
13.213.51.196
xinchaoagcfea.net
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
Download
2f23000
page read and write
1575000
page read and write
7ffcef92a000
page execute read
7ff7c67fd000
page read and write
7ff7c4ffa000
page read and write
7ff7c8021000
page read and write
7ff7ce693000
page read and write
7ff7cde92000
page read and write
4f9000
page execute read
7ff7c6ffe000
page read and write
7ff7cd691000
page read and write
7ff7cee94000
page read and write
7ff7c77ff000
page read and write
7ff7c5ffc000
page read and write
7ffcef902000
page read and write
7ff7c57fb000
page read and write
7ff7c8000000
page read and write
7ff7cce90000
page read and write
There are 8 hidden memdumps, click here to show them.