IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/usr/lib/udisks2/udisksd
-
/usr/sbin/dumpe2fs
dumpe2fs -h /dev/dm-0

Domains

Name
IP
Malicious
enemybotnet.com
93.123.39.105
malicious

IPs

IP
Domain
Country
Malicious
93.123.39.105
enemybotnet.com
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
40f000
page execute read
7ffe78e2c000
page read and write
40f000
page execute read
1660000
page read and write
7ffe78fbe000
page execute read
510000
page read and write
513000
page read and write
510000
page read and write
1660000
page read and write
513000
page read and write
7ffe78e2c000
page read and write
7ffe78fbe000
page execute read
There are 2 hidden memdumps, click here to show them.