IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/usr/lib/systemd/systemd
-
/usr/lib/snapd/snap-failure
/usr/lib/snapd/snap-failure snapd
/usr/lib/snapd/snap-failure
-
/usr/bin/systemctl
systemctl stop snapd.socket
/usr/lib/snapd/snap-failure
-

Domains

Name
IP
Malicious
nineteen.libre
38.60.249.66
malicious
r3racegame.indy
154.223.21.228
malicious
eighteen.pirate
38.60.249.66
malicious
kr3ddnsnet1.indy
154.223.21.228
malicious
kr2ddnsnet.dyn
154.90.62.142
malicious
imaverygoodbadboy.libre
154.205.144.234
malicious
subcarrace.indy
154.223.21.228
malicious
nineteen.libre. [malformed]
unknown
malicious
imaverygoodbadboy.libre. [malformed]
unknown
malicious
fortyfivehundred.dyn. [malformed]
unknown
malicious
kr3ddnsnet1.indy. [malformed]
unknown
malicious
75cents.libre. [malformed]
unknown
malicious
2joints.libre. [malformed]
unknown
malicious
kr2ddnsnet.dyn. [malformed]
unknown
malicious
r3racegame.indy. [malformed]
unknown
malicious
fortyfivehundred.dyn
unknown
malicious
krddnsnet.dyn. [malformed]
unknown
malicious
21savage.dyn. [malformed]
unknown
malicious
daisy.ubuntu.com
162.213.35.24
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
154.205.144.234
imaverygoodbadboy.libre
Seychelles
malicious
154.90.62.142
kr2ddnsnet.dyn
Seychelles
malicious
154.223.21.228
r3racegame.indy
Seychelles
malicious
38.60.249.66
nineteen.libre
United States
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7fe318031000
page read and write
7fe41e777000
page read and write
7fe417fff000
page read and write
7fe41eca6000
page read and write
55c98f11e000
page execute read
7fe41e4e9000
page read and write
7ffc4ce37000
page read and write
7fe41d8ed000
page read and write
7fe41e187000
page read and write
7fe318029000
page execute read
7fe41edcf000
page read and write
7fe41ee38000
page read and write
55c99138d000
page read and write
7fe41e0f5000
page read and write
7fe31803a000
page read and write
55c98f378000
page read and write
55c992500000
page read and write
7fe41eac5000
page read and write
7fe41edf3000
page read and write
7fe41e8e3000
page read and write
7fe418021000
page read and write
7ffc4ced4000
page execute read
55c991376000
page execute and read and write
55c98f36f000
page read and write
7fe41e754000
page read and write
There are 15 hidden memdumps, click here to show them.