IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit LSB shared object, ARM, EABI5 version 1 (GNU/Linux), statically linked, stripped
initial sample
malicious
/var/spool/cron/crontabs/tmp.JjIApe
ASCII text
dropped
malicious
/sys/devices/system/node/node0/hugepages/hugepages-1048576kB/nr_hugepages
very short file (no magic)
dropped
/sys/devices/system/node/node0/hugepages/hugepages-2048kB/nr_hugepages
ASCII text, with no line terminators
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/bin/sh
sh -c "command -v crontab >/dev/null 2>&1"
/tmp/na.elf
-
/bin/sh
sh -c "crontab -r >/dev/null 2>&1; echo \"@reboot /tmp/na.elf\" | crontab -"
/bin/sh
-
/usr/bin/crontab
crontab -r
/bin/sh
-
/bin/sh
-
/usr/bin/crontab
crontab -
/tmp/na.elf
-
/bin/sh
sh -c "command -v php >/dev/null 2>&1"
/tmp/na.elf
-
/bin/sh
sh -c "command -v nginx >/dev/null 2>&1"
/tmp/na.elf
-
/bin/sh
sh -c "which apache2"
/bin/sh
-
/usr/bin/which
which apache2
/tmp/na.elf
-
/bin/sh
sh -c "which httpd"
/bin/sh
-
/usr/bin/which
which httpd
/tmp/na.elf
-
/tmp/na.elf
-
/bin/sh
sh -c "iptables -I INPUT -p tcp --dport 35793 -j ACCEPT >/dev/null 2>&1"
/bin/sh
-
/usr/sbin/iptables
iptables -I INPUT -p tcp --dport 35793 -j ACCEPT
There are 18 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious
https://gcc.gnu.org/bugs/):
unknown
https://xmrig.com/wizard
unknown
https://xmrig.com/wizard%s
unknown

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3b2bead000
page execute read
malicious
7f3b331ff000
page read and write
7f3b326e0000
page read and write
55f4774ab000
page read and write
55f475496000
page read and write
7f3b32e3c000
page read and write
7f3b2bb76000
page read and write
7f3b2b375000
page read and write
7f3b32cad000
page read and write
7f3b3264e000
page read and write
7f3b3334c000
page read and write
7f3b2b367000
page read and write
7f3b2c021000
page read and write
7f3b32a42000
page read and write
7f3b3301e000
page read and write
7f3b33328000
page read and write
55f47929a000
page read and write
7f3b31e46000
page read and write
55f47548d000
page read and write
55f477494000
page execute and read and write
7ffceedf5000
page execute read
7f3b2beda000
page read and write
7f3b2b36f000
page read and write
7f3b33391000
page read and write
7f3b32cd0000
page read and write
55f47523c000
page execute read
7ffceec2d000
page read and write
There are 17 hidden memdumps, click here to show them.