IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/usr/lib/systemd/systemd
-
/usr/lib/snapd/snap-failure
/usr/lib/snapd/snap-failure snapd
/usr/lib/snapd/snap-failure
-
/usr/bin/systemctl
systemctl stop snapd.socket
/usr/lib/snapd/snap-failure
-

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
38.60.249.66
unknown
United States
malicious
116.203.104.203
unknown
Germany

Memdumps

Base Address
Regiontype
Protect
Malicious
7effd86d2000
page read and write
7efee000e000
page execute read
5585cdb90000
page execute read
7effd8435000
page read and write
7effd8f7a000
page read and write
5585d1089000
page read and write
7effd8e04000
page read and write
7efee001f000
page read and write
5585cde1b000
page read and write
7effd8443000
page read and write
7effd8ab9000
page read and write
7effd8a94000
page read and write
5585cfe2f000
page read and write
7effd0000000
page read and write
5585cfe19000
page execute and read and write
7effd7c32000
page read and write
7effd0021000
page read and write
7fffe29f3000
page execute read
5585cde13000
page read and write
7fffe29c9000
page read and write
7efee0026000
page read and write
7effd8f35000
page read and write
7effd8f2d000
page read and write
There are 13 hidden memdumps, click here to show them.