IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.G4gqbMAAF5 /tmp/tmp.A9Q0SM8G6H /tmp/tmp.drh5UKVaiC
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.G4gqbMAAF5 /tmp/tmp.A9Q0SM8G6H /tmp/tmp.drh5UKVaiC
/tmp/na.elf
/tmp/na.elf

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f33d73e5000
page read and write
7f33d755b000
page read and write
7f3350115000
page execute read
7f33d6ed3000
page read and write
55970f307000
page read and write
7ffdb875a000
page execute read
55970b297000
page read and write
55970d29f000
page execute and read and write
55970b00f000
page execute read
55970b2a1000
page read and write
7f33d750e000
page read and write
7f33d0000000
page read and write
7f33d6eb6000
page read and write
7f33d6e93000
page read and write
7f33d6834000
page read and write
7f33d6af2000
page read and write
7f33d6842000
page read and write
55970d2b6000
page read and write
7f33d602c000
page read and write
7ffdb8622000
page read and write
7f33d0021000
page read and write
7f33d7204000
page read and write
7f33d7516000
page read and write
There are 13 hidden memdumps, click here to show them.