IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
5.42.98.74:4258
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
5.42.98.74
unknown
Russian Federation
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f9d8002a000
page execute read
malicious
7f9d8002a000
page execute read
malicious
7f9e84c60000
page read and write
7f9d80039000
page read and write
7f9e80021000
page read and write
7f9e858a8000
page read and write
7f9e85911000
page read and write
7ffc57394000
page read and write
7f9e84bce000
page read and write
55ee9acd4000
page read and write
7f9d80033000
page read and write
7f9e8577f000
page read and write
7f9e84fc2000
page read and write
7f9e8522d000
page read and write
55ee9ccd2000
page execute and read and write
55ee9accb000
page read and write
55ee9aa7a000
page execute read
7f9e843c6000
page read and write
7f9e853bc000
page read and write
7f9e8559e000
page read and write
7f9e85250000
page read and write
55ee9ccd2000
page execute and read and write
55ee9eb51000
page read and write
7f9e85911000
page read and write
7f9e858cc000
page read and write
55ee9accb000
page read and write
7f9e8522d000
page read and write
7f9e858cc000
page read and write
7ffc573d3000
page execute read
7f9e84bce000
page read and write
55ee9acd4000
page read and write
7f9d80033000
page read and write
7f9e84fc2000
page read and write
7f9d80039000
page read and write
7f9e84c60000
page read and write
7f9e8559e000
page read and write
7ffc57394000
page read and write
7f9e80021000
page read and write
7f9e8577f000
page read and write
7f9e843c6000
page read and write
7f9e7ffff000
page read and write
7f9e85250000
page read and write
7ffc573d3000
page execute read
7f9e858a8000
page read and write
55ee9cce9000
page read and write
55ee9eb51000
page read and write
7f9e7ffff000
page read and write
55ee9aa7a000
page execute read
7f9e853bc000
page read and write
55ee9cce9000
page read and write
There are 40 hidden memdumps, click here to show them.