IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.gWYdqRNfSr /tmp/tmp.zlfH7XbY54 /tmp/tmp.0IyubbBDRk
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.gWYdqRNfSr /tmp/tmp.zlfH7XbY54 /tmp/tmp.0IyubbBDRk
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

Domains

Name
IP
Malicious
75cents.libre
156.244.16.207
malicious

IPs

IP
Domain
Country
Malicious
156.244.16.207
75cents.libre
Seychelles
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
55e368258000
page read and write
7f2858024000
page execute read
7f2960f5c000
page read and write
7f2960980000
page read and write
55e368241000
page execute and read and write
7f285802c000
page read and write
7f2858033000
page read and write
7f295fd84000
page read and write
7f29612cf000
page read and write
55e366243000
page read and write
7fff100af000
page execute read
55e36623a000
page read and write
7f2960d7a000
page read and write
7f2958021000
page read and write
7f296113d000
page read and write
7f2961266000
page read and write
7f2957fff000
page read and write
7fff1002b000
page read and write
7f2960c0e000
page read and write
55e365fe9000
page execute read
7f296058c000
page read and write
7f296128a000
page read and write
7f2960beb000
page read and write
55e368683000
page read and write
7f296061e000
page read and write
There are 15 hidden memdumps, click here to show them.