IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
5.42.98.74:4258
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
5.42.98.74
unknown
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f5ccc02e000
page execute read
malicious
7f5ccc02e000
page execute read
malicious
7f5dd2cd3000
page read and write
7f5dcc021000
page read and write
7f5dd1e49000
page read and write
7f5dd26e3000
page read and write
7f5dd2651000
page read and write
56343007e000
page read and write
7f5dd2e3f000
page read and write
56342e069000
page read and write
7f5dd2cd3000
page read and write
7f5dd3202000
page read and write
563430067000
page execute and read and write
7f5ccc036000
page read and write
56343007e000
page read and write
7ffd740db000
page read and write
56342de0f000
page execute read
7ffd740e0000
page execute read
56342e060000
page read and write
7f5dd332b000
page read and write
7f5dd2a45000
page read and write
7ffd740db000
page read and write
7f5dd3202000
page read and write
56342e060000
page read and write
563431e55000
page read and write
7f5dd2cb0000
page read and write
7ffd740e0000
page execute read
7f5dd2a45000
page read and write
7f5dd334f000
page read and write
563431e55000
page read and write
7f5dd1e49000
page read and write
7f5dd3394000
page read and write
7f5dd3394000
page read and write
7f5dd334f000
page read and write
7f5dd2cb0000
page read and write
563430067000
page execute and read and write
7f5dcbfff000
page read and write
7f5dd2e3f000
page read and write
56342e069000
page read and write
7f5dd3021000
page read and write
7f5ccc036000
page read and write
7f5dd332b000
page read and write
7f5dcc021000
page read and write
7f5ccc03e000
page read and write
7f5dd26e3000
page read and write
7f5ccc03e000
page read and write
7f5dd3021000
page read and write
7f5dd2651000
page read and write
56342de0f000
page execute read
7f5dcbfff000
page read and write
There are 40 hidden memdumps, click here to show them.