IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Lk1rOt9EZh /tmp/tmp.ZpPoJCqDUT /tmp/tmp.kXy2ydxulA
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.Lk1rOt9EZh /tmp/tmp.ZpPoJCqDUT /tmp/tmp.kXy2ydxulA
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
5.42.98.74:4258
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

IPs

IP
Domain
Country
Malicious
5.42.98.74
unknown
Russian Federation
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f657002e000
page execute read
malicious
7f657002e000
page execute read
malicious
558f73e13000
page execute read
7f657003e000
page read and write
7f6675dd9000
page read and write
7f6677192000
page read and write
7f6675dd9000
page read and write
7f6676c40000
page read and write
7f66769d5000
page read and write
7f66772df000
page read and write
7f666ffff000
page read and write
7f6670021000
page read and write
7ffd67dbc000
page execute read
558f76811000
page read and write
7f6570036000
page read and write
558f74064000
page read and write
7f6676c63000
page read and write
7ffd67dbc000
page execute read
7f6677324000
page read and write
7f6676fb1000
page read and write
558f76082000
page read and write
7f66769d5000
page read and write
7f6676fb1000
page read and write
558f76811000
page read and write
7ffd67c4b000
page read and write
7f6676c63000
page read and write
7f6676673000
page read and write
7f66765e1000
page read and write
7f6677192000
page read and write
7f6677324000
page read and write
558f74064000
page read and write
7f666ffff000
page read and write
558f7406d000
page read and write
7f657003e000
page read and write
7f6676c40000
page read and write
7f6670021000
page read and write
7f6676dcf000
page read and write
558f7406d000
page read and write
7ffd67c4b000
page read and write
558f76082000
page read and write
7f66772bb000
page read and write
7f6676673000
page read and write
7f6570036000
page read and write
7f66765e1000
page read and write
7f66772df000
page read and write
7f6676dcf000
page read and write
558f73e13000
page execute read
558f7606b000
page execute and read and write
558f7606b000
page execute and read and write
7f66772bb000
page read and write
There are 40 hidden memdumps, click here to show them.