IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious
http://%s:%d/bin.sh;chmod
unknown
http://ipinfo.io/ip
unknown
http://%s:%d/Mozi.a;chmod
unknown
http://%s:%d/Mozi.m;/tmp/Mozi.m
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://%s:%d/bin.sh
unknown
http://purenetworks.com/HNAP1/
unknown
http://%s:%d/Mozi.m;
unknown
http://%s:%d/Mozi.m;$
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://HTTP/1.1
unknown
http://%s:%d/Mozi.a;sh$
unknown
http://127.0.0.1
unknown
http://baidu.com/%s/%s/%d/%s/%s/%s/%s)
unknown
http://schemas.xmlsoap.org/soap/envelope//
unknown
http://%s:%d/Mozi.m
unknown
http://127.0.0.1sendcmd
unknown
There are 8 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffca8e37000
page read and write
5602db2d7000
page execute read
7faef8777000
page read and write
7faef8103000
page read and write
5602dd7b3000
page read and write
7faeef7ff000
page read and write
5602dd567000
page execute and read and write
7faef0021000
page read and write
7fae704c3000
page read and write
7faef8754000
page read and write
7faef80f5000
page read and write
7faef8794000
page read and write
7faef0000000
page read and write
5602db55f000
page read and write
7faef78ed000
page read and write
5602dd57e000
page read and write
5602db569000
page read and write
7faef8ac5000
page read and write
7faef8e1c000
page read and write
7ffca8fb6000
page execute read
7faef8dcf000
page read and write
7fae70422000
page execute read
7faef8ca6000
page read and write
7faef8dd7000
page read and write
7faef83b3000
page read and write
There are 15 hidden memdumps, click here to show them.