IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.tZjZy5SILM /tmp/tmp.JTu1nCT417 /tmp/tmp.9lBcOe8jxo
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.tZjZy5SILM /tmp/tmp.JTu1nCT417 /tmp/tmp.9lBcOe8jxo
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
http://%d.%d.%d.%d/la.bot.%s
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7f25e0419000
page execute read
malicious
7f266589c000
page read and write
55dec9876000
page read and write
7f2664ceb000
page read and write
7f26644e3000
page read and write
7f266536d000
page read and write
55dec7857000
page read and write
7f26656bb000
page read and write
7f26659cd000
page read and write
7f2665a12000
page read and write
7f266534a000
page read and write
7f25e0469000
page read and write
7f2660021000
page read and write
7f2660000000
page read and write
7ffcbf9ed000
page read and write
55dec75cf000
page execute read
55dec985f000
page execute and read and write
7f2664cf9000
page read and write
7ffcbf9fc000
page execute read
7f26659c5000
page read and write
7f25e0460000
page read and write
7f2664fa9000
page read and write
55dec9ded000
page read and write
7f266538a000
page read and write
55dec7861000
page read and write
There are 15 hidden memdumps, click here to show them.