IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
5.42.98.74:4258
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
5.42.98.74
unknown
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f24d002e000
page execute read
malicious
7f24d002e000
page execute read
malicious
5581771c6000
page read and write
558174f57000
page execute read
7f25d5040000
page read and write
7f25d5592000
page read and write
5581782e9000
page read and write
7f25d56bb000
page read and write
7ffef5b5e000
page execute read
7f24d0036000
page read and write
7f25d49e1000
page read and write
7f25d4dd5000
page read and write
7f25d41d9000
page read and write
7f24d0036000
page read and write
5581751a8000
page read and write
558174f57000
page execute read
7f25d4dd5000
page read and write
7f25d56bb000
page read and write
7f25d5040000
page read and write
7ffef5b2a000
page read and write
7f25d5063000
page read and write
5581771c6000
page read and write
7f25d53b1000
page read and write
5581751b1000
page read and write
7f24d003e000
page read and write
7f25d0021000
page read and write
7f25d51cf000
page read and write
5581751b1000
page read and write
7f25d5724000
page read and write
7f25d56df000
page read and write
7f25d41d9000
page read and write
5581751a8000
page read and write
7f25d4a73000
page read and write
5581782e9000
page read and write
7f25d49e1000
page read and write
7f25d56df000
page read and write
7f25d5724000
page read and write
7f25cffff000
page read and write
7f25d0021000
page read and write
7f24d003e000
page read and write
7f25d53b1000
page read and write
7ffef5b2a000
page read and write
5581771af000
page execute and read and write
5581771af000
page execute and read and write
7f25d5063000
page read and write
7ffef5b5e000
page execute read
7f25d5592000
page read and write
7f25cffff000
page read and write
7f25d4a73000
page read and write
7f25d51cf000
page read and write
There are 40 hidden memdumps, click here to show them.