IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/bin/sh
sh -c "ps -A -o pid,cmd --no-headers"
/bin/sh
-
/usr/bin/ps
ps -A -o pid,cmd --no-headers

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25
cnc.merisprivate.net
194.120.230.54

IPs

IP
Domain
Country
Malicious
194.120.230.54
cnc.merisprivate.net
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
805c000
page execute read
malicious
805c000
page execute read
malicious
805c000
page execute read
malicious
8a98000
page read and write
8a98000
page read and write
805f000
page read and write
c02000
page execute read
8ab1000
page read and write
f7f3b000
page execute read
ffcee000
page read and write
c02000
page execute read
ffcee000
page read and write
c02000
page execute read
f7f3b000
page execute read
805f000
page read and write
ffcee000
page read and write
805f000
page read and write
8a98000
page read and write
f7f3b000
page execute read
There are 9 hidden memdumps, click here to show them.