IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.woJkVAa1Z6 /tmp/tmp.PjOycGhfr2 /tmp/tmp.tNpryRPH7p
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.woJkVAa1Z6 /tmp/tmp.PjOycGhfr2 /tmp/tmp.tNpryRPH7p
/tmp/na.elf
/tmp/na.elf

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3bdcda8000
page read and write
7f3bdcd63000
page read and write
7f3bdcc16000
page read and write
7f3bd4021000
page read and write
7f3bdc0f7000
page read and write
7f3bdc6c4000
page read and write
7f3bdb85d000
page read and write
7f3bdca35000
page read and write
556efaa26000
page execute read
7f3bdc459000
page read and write
7f3bdcd3f000
page read and write
7f3bdc065000
page read and write
556efac77000
page read and write
556efcc95000
page read and write
7ffe1cb23000
page read and write
556efe82c000
page read and write
7f3ad413e000
page read and write
7f3ad4144000
page read and write
7f3ad412d000
page execute read
556efac80000
page read and write
7f3bdc6e7000
page read and write
556efcc7f000
page execute and read and write
7ffe1cbaa000
page execute read
7f3bdc853000
page read and write
There are 14 hidden memdumps, click here to show them.