IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/proc/self/exe
/proc/self/exe
/proc/self/exe
-
/usr/bin/whoami
whoami
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.hsFND1riiL /tmp/tmp.h3IQgAEO96 /tmp/tmp.5cGkCVw7uC
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.hsFND1riiL /tmp/tmp.h3IQgAEO96 /tmp/tmp.5cGkCVw7uC

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
121.41.18.122
unknown
China
malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f65fe7bc000
page read and write
1034000
page read and write
7ffe62319000
page read and write
7f65d9600000
page read and write
7f65fe83d000
page read and write
7f65fe91c000
page read and write
7f65fe09c000
page read and write
7f65d9800000
page read and write
7ffe623f1000
page execute read
b22000
page execute read
7f65fbcc6000
page read and write
7f65d989c000
page read and write
7f65e9e16000
page read and write
c000400000
page read and write
There are 4 hidden memdumps, click here to show them.