IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/usr/bin/dash
-
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.4LbTawigsP /tmp/tmp.bf6cxzIhf6 /tmp/tmp.e6elOtG3HL

Domains

Name
IP
Malicious
eighteen.pirate
38.60.249.66
malicious
nineteen.libre. [malformed]
unknown
malicious
2joints.libre. [malformed]
unknown
malicious

IPs

IP
Domain
Country
Malicious
38.60.249.66
eighteen.pirate
United States
malicious
34.249.145.219
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f002baf9000
page read and write
7f002b47e000
page read and write
55b4a6175000
page execute and read and write
7f002b4a1000
page read and write
55b4a3ee5000
page execute read
7effa4453000
page read and write
7effa445a000
page read and write
7f002bb46000
page read and write
55b4a618c000
page read and write
7f002b4be000
page read and write
7fff3e535000
page execute read
7f002b7ef000
page read and write
7fff3e51c000
page read and write
55b4a78fb000
page read and write
7f002ae2d000
page read and write
55b4a416d000
page read and write
7f002ae1f000
page read and write
55b4a4177000
page read and write
7f002bb01000
page read and write
7f0024021000
page read and write
7f002b0dd000
page read and write
7f002b9d0000
page read and write
7f002a617000
page read and write
7f0024000000
page read and write
7effa4412000
page execute read
There are 15 hidden memdumps, click here to show them.