IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown

Domains

Name
IP
Malicious
sandmen.geek
154.216.20.58
malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
41.157.30.63
unknown
South Africa
156.97.115.161
unknown
Chile
156.249.231.145
unknown
Seychelles
197.175.223.207
unknown
South Africa
41.117.228.130
unknown
South Africa
41.82.47.215
unknown
Senegal
197.248.19.137
unknown
Kenya
197.43.51.143
unknown
Egypt
156.148.61.225
unknown
Italy
41.248.235.169
unknown
Morocco
197.214.107.220
unknown
Nigeria
197.114.121.181
unknown
Algeria
197.219.152.187
unknown
Mozambique
41.152.179.67
unknown
Egypt
156.43.93.30
unknown
United Kingdom
156.241.105.210
unknown
Seychelles
41.116.238.229
unknown
South Africa
41.206.191.248
unknown
South Africa
156.17.237.238
unknown
Poland
41.42.142.158
unknown
Egypt
197.252.76.139
unknown
Sudan
156.228.228.21
unknown
Seychelles
156.3.253.127
unknown
United States
156.183.30.48
unknown
Egypt
156.209.86.3
unknown
Egypt
156.143.170.161
unknown
United States
41.76.191.241
unknown
Kenya
197.31.187.177
unknown
Tunisia
197.210.99.195
unknown
Nigeria
41.133.38.88
unknown
South Africa
197.33.36.97
unknown
Egypt
41.44.233.227
unknown
Egypt
41.188.184.86
unknown
Tanzania United Republic of
41.187.159.149
unknown
Egypt
156.56.101.216
unknown
United States
197.65.235.4
unknown
South Africa
41.102.150.112
unknown
Algeria
197.164.175.161
unknown
Egypt
41.149.186.128
unknown
South Africa
156.2.12.204
unknown
United States
41.117.228.166
unknown
South Africa
156.76.161.119
unknown
United States
41.73.250.188
unknown
Nigeria
156.251.245.87
unknown
Seychelles
197.184.139.221
unknown
South Africa
41.152.179.98
unknown
Egypt
156.56.101.221
unknown
United States
197.184.139.225
unknown
South Africa
41.45.223.174
unknown
Egypt
197.16.42.162
unknown
Tunisia
41.115.200.50
unknown
South Africa
156.132.248.3
unknown
United States
156.20.255.233
unknown
United States
197.75.183.115
unknown
South Africa
197.139.229.100
unknown
Kenya
156.7.184.124
unknown
United States
41.48.164.206
unknown
South Africa
41.41.152.212
unknown
Egypt
197.4.200.87
unknown
Tunisia
197.220.141.76
unknown
Lesotho
197.116.212.218
unknown
Algeria
156.61.32.155
unknown
United Kingdom
41.102.161.13
unknown
Algeria
156.202.232.5
unknown
Egypt
197.193.219.18
unknown
Egypt
41.186.122.70
unknown
Rwanda
41.35.57.74
unknown
Egypt
156.228.63.19
unknown
Seychelles
156.76.237.26
unknown
United States
156.15.146.100
unknown
United States
156.124.58.171
unknown
United States
197.233.177.229
unknown
Namibia
156.147.203.61
unknown
Korea Republic of
41.217.127.147
unknown
Nigeria
156.141.177.84
unknown
United States
41.227.43.51
unknown
Tunisia
41.96.73.37
unknown
Algeria
156.154.216.74
unknown
United States
156.215.129.210
unknown
Egypt
41.41.152.231
unknown
Egypt
197.212.239.125
unknown
Zambia
41.122.213.41
unknown
South Africa
41.217.127.141
unknown
Nigeria
41.77.181.176
unknown
Algeria
156.114.21.12
unknown
Netherlands
197.16.42.191
unknown
Tunisia
41.217.104.17
unknown
Nigeria
41.29.171.8
unknown
South Africa
156.214.15.144
unknown
Egypt
41.194.29.18
unknown
South Africa
197.214.51.247
unknown
Niger
197.139.229.133
unknown
Kenya
197.149.52.146
unknown
Madagascar
197.233.177.223
unknown
Namibia
197.37.72.187
unknown
Egypt
197.194.23.131
unknown
Egypt
197.108.18.99
unknown
South Africa
41.47.66.148
unknown
Egypt
156.112.63.245
unknown
United States
41.31.60.224
unknown
South Africa
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7f46a3d21000
page execute read
malicious
7f46a3d21000
page execute read
malicious
7f46a3d21000
page execute read
malicious
7f46a3d21000
page execute read
malicious
7f47a5279000
page read and write
7f47a5255000
page read and write
7f47a457b000
page read and write
7f47a3d73000
page read and write
7ffd9d25b000
page execute read
7f47a3cf1000
page read and write
7f47a4f4b000
page read and write
558afd813000
page read and write
7ffd9d25b000
page execute read
7f47a4f4b000
page read and write
7f47a496f000
page read and write
7f47a4d69000
page read and write
7f47a3cf1000
page read and write
7f47a4d69000
page read and write
7f47a4bda000
page read and write
7f47a457b000
page read and write
7f47a4bda000
page read and write
7f46a3d29000
page read and write
7f47a3cf1000
page read and write
7f47a457b000
page read and write
558aff811000
page execute and read and write
7f47a460d000
page read and write
7f47a52be000
page read and write
7f47a460d000
page read and write
7f47a3cf1000
page read and write
558afd80a000
page read and write
558afd813000
page read and write
7f469c021000
page read and write
7f47a3d73000
page read and write
558aff828000
page read and write
7f469c021000
page read and write
7f469c021000
page read and write
558aff828000
page read and write
7f47a5255000
page read and write
7f47a5279000
page read and write
558afd813000
page read and write
7f47a5279000
page read and write
7f46a3d29000
page read and write
7f47a460d000
page read and write
7f47a457b000
page read and write
558aff828000
page read and write
7f46a3d31000
page read and write
7f46a3d31000
page read and write
7f47a4d69000
page read and write
7f47a4bfd000
page read and write
558aff828000
page read and write
7f47a52be000
page read and write
7f47a5279000
page read and write
7f47a4f4b000
page read and write
7f46a3d29000
page read and write
558afd5b9000
page execute read
7f47a512c000
page read and write
558aff811000
page execute and read and write
558affa05000
page read and write
558affa05000
page read and write
7ffd9d25b000
page execute read
7f47a4bfd000
page read and write
558afd5b9000
page execute read
558aff811000
page execute and read and write
558afd5b9000
page execute read
7f47a512c000
page read and write
7ffd9d219000
page read and write
7f47a3d73000
page read and write
7f46a3d32000
page read and write
558affa05000
page read and write
558aff811000
page execute and read and write
7f47a512c000
page read and write
7f47a52be000
page read and write
558afd80a000
page read and write
7ffd9d219000
page read and write
7f47a512c000
page read and write
7f47a4bfd000
page read and write
558afd5b9000
page execute read
7ffd9d219000
page read and write
7f47a496f000
page read and write
7f47a460d000
page read and write
7f47a3d73000
page read and write
7f46a3d31000
page read and write
7f47a4f4b000
page read and write
7f47a4d69000
page read and write
558afd80a000
page read and write
558afd813000
page read and write
7f47a496f000
page read and write
558affa05000
page read and write
7ffd9d25b000
page execute read
7f47a5255000
page read and write
7f47a52be000
page read and write
7f47a4bfd000
page read and write
7f47a4bda000
page read and write
7f46a3d29000
page read and write
558afd80a000
page read and write
7f47a5255000
page read and write
7f46a3d31000
page read and write
7f469c021000
page read and write
7f47a4bda000
page read and write
7f47a496f000
page read and write
7ffd9d219000
page read and write
There are 91 hidden memdumps, click here to show them.