IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
initial sample
malicious
/tmp/qemu-open.sjtPX8 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.167:77
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.167
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f4f4c42a000
page execute read
malicious
7f4f4c42a000
page execute read
malicious
7f4fd4348000
page read and write
7f4fcc000000
page read and write
55935e1d8000
page execute and read and write
7f4fd41d2000
page read and write
7f4fd3621000
page read and write
7f4fd3ca3000
page read and write
7f4fd3cc0000
page read and write
7f4fd3ff1000
page read and write
7fff7b8e3000
page read and write
55935c1d0000
page read and write
7f4fcc000000
page read and write
7f4fd38df000
page read and write
7f4f4c43c000
page read and write
7f4fd4303000
page read and write
7f4fd362f000
page read and write
7fff7b9b1000
page execute read
7f4fd3cc0000
page read and write
7f4fd42fb000
page read and write
7f4fd3ff1000
page read and write
7f4f4c43c000
page read and write
7f4f4c444000
page read and write
7f4fd41d2000
page read and write
7f4fd4303000
page read and write
55935e1d8000
page execute and read and write
7f4fd3c80000
page read and write
7f4fd362f000
page read and write
55935e1ef000
page read and write
7f4fd38df000
page read and write
55935c1da000
page read and write
7f4fd4348000
page read and write
7fff7b8e3000
page read and write
7f4fd3c80000
page read and write
7f4fcc021000
page read and write
55935c1da000
page read and write
7f4fd2e19000
page read and write
7f4fcc021000
page read and write
7fff7b9b1000
page execute read
7f4fd2e19000
page read and write
55935f844000
page read and write
7f4fd3621000
page read and write
7f4f4c444000
page read and write
55935bf48000
page execute read
55935e1ef000
page read and write
55935c1d0000
page read and write
55935f844000
page read and write
7f4fd42fb000
page read and write
55935bf48000
page execute read
7f4fd3ca3000
page read and write
There are 40 hidden memdumps, click here to show them.