IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.DGA79cPZXZ /tmp/tmp.ssuri6dQxf /tmp/tmp.nHD3hupuB3
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.DGA79cPZXZ /tmp/tmp.ssuri6dQxf /tmp/tmp.nHD3hupuB3

Domains

Name
IP
Malicious
iranistrash.libre
unknown
malicious

IPs

IP
Domain
Country
Malicious
34.249.145.219
unknown
United States
5.230.229.84
unknown
Germany
109.202.202.202
unknown
Switzerland
172.217.192.127
unknown
United States
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f60c4457000
page read and write
5599f2aa2000
page read and write
7f614bf7e000
page read and write
7f614c5cf000
page read and write
7f614b768000
page read and write
7f6144000000
page read and write
7f614cc97000
page read and write
5599f57ed000
page read and write
5599f2a98000
page read and write
7f614c940000
page read and write
7ffd3f5c5000
page execute read
7f614cc52000
page read and write
7f614bf70000
page read and write
5599f4ab7000
page read and write
7f614cc4a000
page read and write
5599f4aa0000
page execute and read and write
7f6144021000
page read and write
7f614c22e000
page read and write
7f614cb21000
page read and write
7f614c5f2000
page read and write
5599f2810000
page execute read
7f60c4456000
page read and write
7ffd3f5a5000
page read and write
7f614c60f000
page read and write
7f60c4415000
page execute read
There are 15 hidden memdumps, click here to show them.