IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0

Domains

Name
IP
Malicious
enemybotnet.com
93.123.39.105
malicious

IPs

IP
Domain
Country
Malicious
93.123.39.105
enemybotnet.com
Bulgaria
malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f18b35e1000
page read and write
7f18b3b33000
page read and write
7f18ac021000
page read and write
7f18b3952000
page read and write
7f18b3770000
page read and write
7f18b35e1000
page read and write
7f18b3014000
page read and write
7f18b2f82000
page read and write
557e1d38f000
page read and write
7ffdf3bf9000
page execute read
7f18b3014000
page read and write
7f18b3604000
page read and write
7f18b3376000
page read and write
7f17ac027000
page execute read
557e1f396000
page execute and read and write
7f17ac032000
page read and write
7f17ac02f000
page read and write
7f18b3952000
page read and write
557e1d398000
page read and write
7f18b277a000
page read and write
7f18b277a000
page read and write
7f18b3604000
page read and write
7f18b3770000
page read and write
7f17ac027000
page execute read
7f17ac032000
page read and write
7f18b3c80000
page read and write
7f18b3c80000
page read and write
7f18abfff000
page read and write
557e1f3ad000
page read and write
7f18ac021000
page read and write
7f17ac02f000
page read and write
7f18b2f82000
page read and write
7f18b3376000
page read and write
557e1d13e000
page execute read
7f18b3cc5000
page read and write
7f18abfff000
page read and write
557e1f3ad000
page read and write
7ffdf3bf5000
page read and write
7f18b3b33000
page read and write
7ffdf3bf5000
page read and write
7f18b3c5c000
page read and write
7f18b3cc5000
page read and write
7f18b3c5c000
page read and write
557e1f7ac000
page read and write
557e1d38f000
page read and write
557e1d398000
page read and write
7ffdf3bf9000
page execute read
557e1d13e000
page execute read
557e1f396000
page execute and read and write
557e1f7ac000
page read and write
There are 40 hidden memdumps, click here to show them.