IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.b4IsJmMT26 /tmp/tmp.oYMsvJQLLd /tmp/tmp.IUZdjxDpIw
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.b4IsJmMT26 /tmp/tmp.oYMsvJQLLd /tmp/tmp.IUZdjxDpIw
/tmp/na.elf
/tmp/na.elf

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
564fe78d5000
page read and write
7f871db73000
page read and write
7f871d583000
page read and write
7f871e234000
page read and write
7f8717fff000
page read and write
564fe98d3000
page execute and read and write
564fe767b000
page execute read
7f871db50000
page read and write
7f871d4f1000
page read and write
7f871e1ef000
page read and write
564feb29b000
page read and write
564fe78cc000
page read and write
7f871dec1000
page read and write
7ffc86b99000
page read and write
7f8718021000
page read and write
7f871e1cb000
page read and write
7f871cce9000
page read and write
7f871d8e5000
page read and write
7ffc86bce000
page execute read
7f8618033000
page execute read
7f871e0a2000
page read and write
564fe98ea000
page read and write
7f871dcdf000
page read and write
There are 13 hidden memdumps, click here to show them.