IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.7vP5t8 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
5.42.98.74:4258
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
5.42.98.74
unknown
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f84cc015000
page execute read
malicious
7f84cc015000
page execute read
malicious
560271ee2000
page read and write
7f85bc000000
page read and write
7f85c3d40000
page read and write
7f84cc02d000
page execute and read and write
560271eea000
page read and write
7f85bc021000
page read and write
7f85c4bc7000
page read and write
7f85c4543000
page read and write
7f85c4f12000
page read and write
7f85c3d40000
page read and write
7f85c5043000
page read and write
7f85c5088000
page read and write
7f84cc026000
page execute and read and write
7f84cc026000
page execute and read and write
7f85c5088000
page read and write
560271eea000
page read and write
560273efe000
page read and write
7f85bc000000
page read and write
7f85c503b000
page read and write
560271c5f000
page execute read
7f84cc02d000
page execute and read and write
560273efe000
page read and write
7f85c47e0000
page read and write
7f84cc02e000
page read and write
7f85c4543000
page read and write
7f85c4ba2000
page read and write
7f85c4ba2000
page read and write
560273ee8000
page execute and read and write
7ffda68ec000
page read and write
7ffda69ac000
page execute read
7f85c4bc7000
page read and write
7f85bc021000
page read and write
7ffda69ac000
page execute read
7f85c4551000
page read and write
7f85c4f12000
page read and write
560271c5f000
page execute read
7f85c5043000
page read and write
560271ee2000
page read and write
56027433d000
page read and write
7f85c503b000
page read and write
56027433d000
page read and write
7f85c4551000
page read and write
7f85c47e0000
page read and write
7ffda68ec000
page read and write
7f84cc02e000
page read and write
560273ee8000
page execute and read and write
There are 38 hidden memdumps, click here to show them.