IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious
http://%s:%d/Mozi.a;sh$
unknown
http://%s:%d/Mozi.a;chmod
unknown
http://%s:%d/Mozi.m;/tmp/Mozi.m
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://schemas.xmlsoap.org/soap/envelope//
unknown
http://%s:%d/Mozi.m
unknown
http://purenetworks.com/HNAP1/
unknown
http://%s:%d/Mozi.m;
unknown
http://%s:%d/Mozi.m;$
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

Memdumps

Base Address
Regiontype
Protect
Malicious
55575dfbc000
page execute and read and write
7f8c28389000
page read and write
7f8c29561000
page read and write
55575dfd3000
page read and write
7f8c29742000
page read and write
7f8c29230000
page read and write
7f8c29873000
page read and write
7f8ba44c3000
page read and write
55575bfbe000
page read and write
55575bd2c000
page execute read
7ffe8bcb5000
page read and write
7f8c237ff000
page read and write
55575bfb4000
page read and write
7f8c24000000
page read and write
7f8c28b91000
page read and write
7f8c2986b000
page read and write
7f8c28b9f000
page read and write
7f8c28e4f000
page read and write
7f8c24021000
page read and write
55575fa1a000
page read and write
7f8ba4422000
page execute read
7f8c298b8000
page read and write
7f8c291f0000
page read and write
7f8c29213000
page read and write
7ffe8bda2000
page execute read
There are 15 hidden memdumps, click here to show them.