IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.chHrPe (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.qDdxYAxe4C /tmp/tmp.LdQDusjWTd /tmp/tmp.2ap7FCsLs5
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.qDdxYAxe4C /tmp/tmp.LdQDusjWTd /tmp/tmp.2ap7FCsLs5
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
5.42.98.74:4258
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

IPs

IP
Domain
Country
Malicious
5.42.98.74
unknown
Russian Federation
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f678841a000
page execute read
malicious
7f678841a000
page execute read
malicious
55e5a932d000
page read and write
7ffe335cc000
page read and write
7f6808021000
page read and write
7f680e8b6000
page read and write
55e5ab7f7000
page read and write
7f680ef15000
page read and write
55e5a909b000
page execute read
7f680f467000
page read and write
7f680f5dd000
page read and write
55e5a932d000
page read and write
55e5ab342000
page read and write
55e5ab342000
page read and write
7f680f590000
page read and write
7f680eb74000
page read and write
55e5ab32b000
page execute and read and write
7f6808021000
page read and write
7f6788433000
page read and write
55e5a909b000
page execute read
7f680ef55000
page read and write
7f680ef38000
page read and write
7f6808000000
page read and write
7ffe335d2000
page execute read
7ffe335d2000
page execute read
7f680f5dd000
page read and write
7f680e8c4000
page read and write
7f680f590000
page read and write
7f680f598000
page read and write
7f678842b000
page read and write
7f6808000000
page read and write
7f680ef38000
page read and write
7f680e8b6000
page read and write
7f680f286000
page read and write
7f680ef15000
page read and write
55e5ab7f7000
page read and write
7f680e0ae000
page read and write
7f680e0ae000
page read and write
7f680f467000
page read and write
55e5ab32b000
page execute and read and write
7f680e8c4000
page read and write
55e5a9323000
page read and write
7f678842b000
page read and write
7f680ef55000
page read and write
7ffe335cc000
page read and write
7f6788433000
page read and write
7f680eb74000
page read and write
7f680f598000
page read and write
55e5a9323000
page read and write
7f680f286000
page read and write
There are 40 hidden memdumps, click here to show them.