IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.QQuhjvfmRR /tmp/tmp.4ta8QmZA8k /tmp/tmp.bZC4RaebMV
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.QQuhjvfmRR /tmp/tmp.4ta8QmZA8k /tmp/tmp.bZC4RaebMV
/tmp/na.elf
/tmp/na.elf

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f6ffc43e000
page read and write
7f6ef4026000
page read and write
7f6ff4021000
page read and write
7f6ffc990000
page read and write
7f6ffc461000
page read and write
55fa344dd000
page read and write
7f6ffcab9000
page read and write
7f6ff3fff000
page read and write
7f6ffbe71000
page read and write
7ffe61edb000
page read and write
55fa344e6000
page read and write
7f6ffcadd000
page read and write
7f6ffcb22000
page read and write
7f6ffbddf000
page read and write
7f6ef401d000
page execute read
55fa364e5000
page execute and read and write
7f6ffc1d3000
page read and write
55fa37678000
page read and write
55fa364fb000
page read and write
7ffe61f98000
page execute read
7f6ffc5cd000
page read and write
55fa3428c000
page execute read
7f6ffb5d7000
page read and write
7f6ffc7af000
page read and write
There are 14 hidden memdumps, click here to show them.