IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.DqSTHg5SOE /tmp/tmp.FUxV3jxmUC /tmp/tmp.HwIRvgXqI4
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.DqSTHg5SOE /tmp/tmp.FUxV3jxmUC /tmp/tmp.HwIRvgXqI4
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
http://%d.%d.%d.%d/la.bot.%s
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24
eighteen.pirate
38.60.249.66

IPs

IP
Domain
Country
Malicious
194.123.89.250
unknown
Germany
102.253.185.176
unknown
South Africa
119.246.189.102
unknown
Hong Kong
141.174.45.236
unknown
United States
59.234.226.122
unknown
China
68.61.146.234
unknown
United States
51.245.16.211
unknown
United States
242.166.31.243
unknown
Reserved
67.73.174.73
unknown
United States
60.75.41.13
unknown
Japan
206.127.49.170
unknown
United States
101.175.179.161
unknown
Australia
123.107.238.97
unknown
Japan
188.240.15.151
unknown
Netherlands
255.195.132.64
unknown
Reserved
77.30.231.91
unknown
Saudi Arabia
245.217.232.245
unknown
Reserved
17.91.35.78
unknown
United States
76.197.175.251
unknown
United States
128.146.245.186
unknown
United States
13.168.83.27
unknown
United States
22.143.223.83
unknown
United States
126.165.146.199
unknown
Japan
66.126.55.128
unknown
United States
1.148.236.60
unknown
Australia
190.23.141.175
unknown
Paraguay
216.36.68.246
unknown
United States
100.134.166.241
unknown
United States
111.89.177.200
unknown
Japan
128.53.179.232
unknown
Japan
92.69.253.196
unknown
Netherlands
55.81.32.128
unknown
United States
58.162.85.192
unknown
Australia
93.28.219.173
unknown
France
130.41.156.159
unknown
United States
215.252.29.138
unknown
United States
174.177.52.218
unknown
United States
203.11.144.209
unknown
Australia
30.144.88.219
unknown
United States
11.241.81.32
unknown
United States
248.129.199.142
unknown
Reserved
157.71.232.80
unknown
Japan
90.174.75.187
unknown
Spain
24.212.148.54
unknown
Canada
86.179.156.33
unknown
United Kingdom
87.152.228.68
unknown
Germany
106.97.89.15
unknown
Korea Republic of
109.21.105.124
unknown
France
201.221.52.236
unknown
Uruguay
205.222.113.72
unknown
United States
187.234.29.99
unknown
Mexico
30.209.89.192
unknown
United States
115.129.152.10
unknown
Australia
191.85.197.155
unknown
Argentina
223.66.245.144
unknown
China
61.180.197.113
unknown
China
16.252.73.195
unknown
United States
30.163.216.101
unknown
United States
169.4.207.215
unknown
United States
197.55.34.211
unknown
Egypt
205.141.136.19
unknown
United States
200.75.126.238
unknown
Venezuela
193.42.153.76
unknown
Poland
196.121.69.199
unknown
Morocco
139.141.205.4
unknown
Kuwait
181.16.252.5
unknown
Argentina
206.46.125.251
unknown
United States
49.105.53.197
unknown
Japan
243.250.83.118
unknown
Reserved
166.116.73.165
unknown
United States
123.58.228.51
unknown
China
255.193.153.114
unknown
Reserved
154.44.229.197
unknown
United States
179.122.106.86
unknown
Brazil
253.160.189.57
unknown
Reserved
200.244.158.165
unknown
Brazil
246.44.175.50
unknown
Reserved
107.84.237.238
unknown
United States
33.191.239.232
unknown
United States
75.116.237.232
unknown
United States
216.249.40.137
unknown
Bermuda
32.217.12.10
unknown
United States
45.159.66.169
unknown
Italy
72.143.32.14
unknown
Canada
135.195.178.41
unknown
United States
190.174.130.14
unknown
Argentina
4.38.93.3
unknown
United States
45.154.143.52
unknown
Poland
1.102.42.10
unknown
Korea Republic of
25.248.176.207
unknown
United Kingdom
81.255.48.64
unknown
France
53.120.38.43
unknown
Germany
205.143.2.99
unknown
United States
130.199.219.122
unknown
United States
56.100.72.207
unknown
United States
76.119.142.186
unknown
United States
87.247.119.51
unknown
Lithuania
107.244.47.7
unknown
United States
216.184.218.89
unknown
United States
59.54.215.107
unknown
China
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7fc14f6a5000
page read and write
7fc148021000
page read and write
562edb087000
page read and write
7fc14f1e4000
page read and write
7fc058033000
page read and write
7fc14f658000
page read and write
7fc14edfd000
page read and write
7fc148000000
page read and write
7fc14f52f000
page read and write
7fc14f660000
page read and write
7fc14eb60000
page read and write
7fc14e35d000
page read and write
7ffc7e0e5000
page read and write
562ede781000
page read and write
7fc05802a000
page read and write
562edb08f000
page read and write
7fc14eb6e000
page read and write
562edd0a3000
page read and write
7ffc7e148000
page execute read
562edd08d000
page execute and read and write
7fc058013000
page execute read
7fc14f1bf000
page read and write
562edae04000
page execute read
There are 13 hidden memdumps, click here to show them.