IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.QUdWjiudxk /tmp/tmp.EmgGv0ygrp /tmp/tmp.x3ubNkrtf2
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.QUdWjiudxk /tmp/tmp.EmgGv0ygrp /tmp/tmp.x3ubNkrtf2
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

Domains

Name
IP
Malicious
imaverygoodbadboy.libre
154.205.144.234
malicious
nineteen.libre. [malformed]
unknown
malicious
75cents.libre. [malformed]
unknown
malicious
2joints.libre. [malformed]
unknown
malicious
r3racegame.indy
unknown
eighteen.pirate
unknown
kr2ddnsnet.dyn
unknown

IPs

IP
Domain
Country
Malicious
154.205.144.234
imaverygoodbadboy.libre
Seychelles
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom
161.97.219.84
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
7f17ac02b000
page read and write
5639708e8000
page read and write
7f18b3231000
page read and write
7f17ac023000
page execute read
7f18abfff000
page read and write
56396c69a000
page execute read
56396c8eb000
page read and write
7f18b28e2000
page read and write
7f18b2b70000
page read and write
7fffb8de5000
page execute read
7f18b309f000
page read and write
56396e909000
page read and write
7f18b1ce6000
page read and write
7f18b2cdc000
page read and write
56396e8f2000
page execute and read and write
7f17ac032000
page read and write
7f18b31ec000
page read and write
56396c8f4000
page read and write
7f18b2580000
page read and write
7f18b2b4d000
page read and write
7fffb8d8b000
page read and write
7f18b24ee000
page read and write
7f18b2ebe000
page read and write
7f18ac021000
page read and write
7f18b31c8000
page read and write
There are 15 hidden memdumps, click here to show them.