IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.167:77
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
93.123.85.167
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7fba3c420000
page execute read
malicious
7fba3c420000
page execute read
malicious
7fbac3675000
page read and write
7fbac4115000
page read and write
55cd59dfb000
page read and write
7fbac4978000
page read and write
7ffc017e9000
page execute read
7fba3c438000
page read and write
7ffc017e9000
page execute read
55cd57108000
page read and write
7fbac4847000
page read and write
7fbac3e78000
page read and write
55cd57110000
page read and write
7fbac3675000
page read and write
7fbabc021000
page read and write
55cd56ef2000
page execute read
55cd59dfb000
page read and write
7fbac49bd000
page read and write
55cd59125000
page read and write
55cd56ef2000
page execute read
7fbabc000000
page read and write
7fbac4115000
page read and write
7fbac3e86000
page read and write
55cd5910e000
page execute and read and write
7ffc0178c000
page read and write
55cd59125000
page read and write
7fba3c438000
page read and write
55cd57108000
page read and write
7fbac4970000
page read and write
7fba3c430000
page read and write
7fbac44fc000
page read and write
7fbac49bd000
page read and write
7fbac44fc000
page read and write
7fba3c430000
page read and write
7fbac44d7000
page read and write
7fbac3e78000
page read and write
7fbac3e86000
page read and write
55cd5910e000
page execute and read and write
7fbabc021000
page read and write
7fbac4847000
page read and write
7fbac44d7000
page read and write
7ffc0178c000
page read and write
55cd57110000
page read and write
7fbac4978000
page read and write
7fbac4970000
page read and write
7fbabc000000
page read and write
There are 36 hidden memdumps, click here to show them.