IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

Domains

Name
IP
Malicious
ru.coziest.lol
38.60.198.180
malicious
f.codingdrunk.cc
38.54.57.248
malicious
2joints.libre
156.244.7.75
malicious
r3racegame.indy
154.223.21.228
malicious
kr3ddnsnet1.indy
154.223.21.228
malicious
kr2ddnsnet.dyn
154.90.62.142
malicious
subcarrace.indy
154.223.21.228
malicious
nineteen.libre. [malformed]
unknown
malicious
imaverygoodbadboy.libre. [malformed]
unknown
malicious
fortyfivehundred.dyn. [malformed]
unknown
malicious
2joints.libre. [malformed]
unknown
malicious
eighteen.pirate
unknown
malicious
kr2ddnsnet.dyn. [malformed]
unknown
malicious
eighteen.pirate. [malformed]
unknown
malicious
r3racegame.indy. [malformed]
unknown
malicious
krddnsnet.dyn. [malformed]
unknown
malicious
21savage.dyn. [malformed]
unknown
malicious
ru.coziest.lol. [malformed]
unknown
malicious
daisy.ubuntu.com
162.213.35.25
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
38.54.57.248
f.codingdrunk.cc
United States
malicious
154.90.62.142
kr2ddnsnet.dyn
Seychelles
malicious
156.244.7.75
2joints.libre
Seychelles
malicious
154.223.21.228
r3racegame.indy
Seychelles
malicious
38.60.198.180
ru.coziest.lol
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7ffcb15f9000
page read and write
559cafadf000
page read and write
7fa93b8bc000
page read and write
7fa93bc80000
page read and write
559cb1af4000
page read and write
7fa934000000
page read and write
559cb273e000
page read and write
7fa93c325000
page read and write
7fa934021000
page read and write
7fa93c2d8000
page read and write
7fa93bfce000
page read and write
7fa93bc5d000
page read and write
7fa93adf6000
page read and write
7fa93c1af000
page read and write
559cb1add000
page execute and read and write
7fa8b4458000
page read and write
7fa93b5fe000
page read and write
7fa93bc9d000
page read and write
7fa8b4410000
page execute read
7ffcb1600000
page execute read
7fa93b60c000
page read and write
7fa8b4451000
page read and write
559cafad5000
page read and write
7fa93c2e0000
page read and write
559caf84d000
page execute read
There are 15 hidden memdumps, click here to show them.