IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/proc/self/exe
/proc/self/exe
/proc/self/exe
-
/usr/bin/whoami
whoami

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25
ssh.updategoogle.cc
103.212.49.88

IPs

IP
Domain
Country
Malicious
185.125.190.26
unknown
United Kingdom
103.212.49.88
ssh.updategoogle.cc
China

Memdumps

Base Address
Regiontype
Protect
Malicious
f7f5c000
page execute read
8bcd000
page read and write
ef556000
page read and write
ffebd000
page read and write
a000000
page read and write
f7f58000
page read and write
8742000
page execute read