IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.ye3Xt3 (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.167:77
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
93.123.85.167
unknown
Bulgaria
malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7058022000
page execute read
malicious
7f7058022000
page execute read
malicious
7f714eff0000
page read and write
7f714f853000
page read and write
7f714e550000
page read and write
55655bce1000
page read and write
7f714f722000
page read and write
7f7058039000
page execute and read and write
7f714f3d7000
page read and write
55655bce1000
page read and write
556559ccd000
page read and write
7f7148000000
page read and write
7f714f84b000
page read and write
7f714ed53000
page read and write
556559a42000
page execute read
7f714f3b2000
page read and write
7f705803a000
page read and write
556559cc5000
page read and write
556559cc5000
page read and write
7ffd67b70000
page execute read
556559a42000
page execute read
7f714f898000
page read and write
7f714f722000
page read and write
7f714eff0000
page read and write
7f714e550000
page read and write
55655c5bf000
page read and write
7f714f84b000
page read and write
7ffd67ab3000
page read and write
7f7148000000
page read and write
7ffd67ab3000
page read and write
7f7148021000
page read and write
55655bccb000
page execute and read and write
7f7148021000
page read and write
55655bccb000
page execute and read and write
556559ccd000
page read and write
7ffd67b70000
page execute read
7f7058032000
page execute and read and write
55655c5bf000
page read and write
7f7058039000
page execute and read and write
7f7058032000
page execute and read and write
7f714f853000
page read and write
7f705803a000
page read and write
7f714f3b2000
page read and write
7f714f3d7000
page read and write
7f714ed61000
page read and write
7f714f898000
page read and write
7f714ed61000
page read and write
7f714ed53000
page read and write
There are 38 hidden memdumps, click here to show them.