IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.IemHT51aKE /tmp/tmp.ovgany5aq2 /tmp/tmp.NIDgLiYqT8
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.IemHT51aKE /tmp/tmp.ovgany5aq2 /tmp/tmp.NIDgLiYqT8
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

Domains

Name
IP
Malicious
iranistrash.libre
unknown
malicious

IPs

IP
Domain
Country
Malicious
5.230.122.82
unknown
Germany
109.202.202.202
unknown
Switzerland
172.217.192.127
unknown
United States
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fff859b1000
page execute read
7fc1b4021000
page read and write
7fc0b402d000
page execute read
7fc1ba62e000
page read and write
7fc1bad12000
page read and write
7fc1ba99f000
page read and write
563444562000
page read and write
7fc0b403a000
page read and write
7fc0b4035000
page read and write
7fc1ba3c3000
page read and write
56344819b000
page read and write
7fc1b3fff000
page read and write
7fc1ba651000
page read and write
56344456b000
page read and write
7fc1b97c7000
page read and write
563446569000
page execute and read and write
563446580000
page read and write
563444311000
page execute read
7fc1bab80000
page read and write
7fff85915000
page read and write
7fc1ba061000
page read and write
7fc1ba7bd000
page read and write
7fc1baccd000
page read and write
7fc1b9fcf000
page read and write
7fc1baca9000
page read and write
There are 15 hidden memdumps, click here to show them.