IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/qemu-open.JgkToj (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
5.42.98.74:4258
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
5.42.98.74
unknown
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3f90029000
page execute read
malicious
7f3f90029000
page execute read
malicious
7f4095276000
page read and write
7f4095ad9000
page read and write
7f4095ad9000
page read and write
7f40959a8000
page read and write
556511589000
page execute and read and write
7f4095b1e000
page read and write
7f4095638000
page read and write
55650f58b000
page read and write
7f4094fd9000
page read and write
7f4090021000
page read and write
7fffb2950000
page execute read
7f3f90042000
page read and write
556511883000
page read and write
55650f354000
page execute read
7f4095b1e000
page read and write
7fffb2860000
page read and write
556511589000
page execute and read and write
7f40959a8000
page read and write
7f3f9003a000
page read and write
7f4090000000
page read and write
7f4095ad1000
page read and write
5565115a0000
page read and write
7f4095ad1000
page read and write
5565115a0000
page read and write
7f4094fe7000
page read and write
7f4090000000
page read and write
7f4090021000
page read and write
55650f58b000
page read and write
55650f582000
page read and write
7f40947d6000
page read and write
55650f354000
page execute read
7f409565d000
page read and write
7f4094fd9000
page read and write
7f3f9003a000
page read and write
7fffb2950000
page execute read
7f40947d6000
page read and write
7f4094fe7000
page read and write
7f3f90042000
page read and write
7f4095638000
page read and write
7fffb2860000
page read and write
55650f582000
page read and write
7f409565d000
page read and write
7f4095276000
page read and write
556511883000
page read and write
There are 36 hidden memdumps, click here to show them.