IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.167:77
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
93.123.85.167
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f040403b000
page execute read
malicious
7f040403b000
page execute read
malicious
7f050a740000
page read and write
7f050ad1c000
page read and write
7f050b04a000
page read and write
7f050a34c000
page read and write
7f050b026000
page read and write
7ffe2dff2000
page execute read
556356ffa000
page read and write
7f0504021000
page read and write
7f050a3de000
page read and write
7f050aefd000
page read and write
7f050aefd000
page read and write
556356fe3000
page execute and read and write
7f050a9ab000
page read and write
556356ffa000
page read and write
556354fe5000
page read and write
7f0503fff000
page read and write
7f050a3de000
page read and write
7f0503fff000
page read and write
7f050a9ce000
page read and write
7ffe2dedf000
page read and write
7f050b04a000
page read and write
7f0504021000
page read and write
7f050b08f000
page read and write
7f050ad1c000
page read and write
7f040404b000
page read and write
7f0404043000
page read and write
556354d8b000
page execute read
7f0509b44000
page read and write
556354fdc000
page read and write
7ffe2dff2000
page execute read
556358e47000
page read and write
556354fdc000
page read and write
7ffe2dedf000
page read and write
7f040404b000
page read and write
7f050a740000
page read and write
556356fe3000
page execute and read and write
556354fe5000
page read and write
7f0509b44000
page read and write
7f050a34c000
page read and write
556354d8b000
page execute read
7f050ab3a000
page read and write
7f050ab3a000
page read and write
7f050b08f000
page read and write
7f050b026000
page read and write
7f0404043000
page read and write
7f050a9ab000
page read and write
556358e47000
page read and write
7f050a9ce000
page read and write
There are 40 hidden memdumps, click here to show them.