IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.167:77
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
93.123.85.167
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7d3403b000
page execute read
malicious
7f7d3403b000
page execute read
malicious
7f7e38c3f000
page read and write
7f7e3929e000
page read and write
7f7e39982000
page read and write
7f7d3404b000
page read and write
7f7e397f0000
page read and write
7ffd029ff000
page execute read
7f7e33fff000
page read and write
7f7e39982000
page read and write
7f7e392c1000
page read and write
7f7d34043000
page read and write
7f7e39033000
page read and write
7f7e38437000
page read and write
7f7e3929e000
page read and write
7f7e3942d000
page read and write
7f7e3960f000
page read and write
55e25a730000
page execute read
55e25d921000
page read and write
55e25a981000
page read and write
7f7e38437000
page read and write
7f7e39919000
page read and write
55e25a98a000
page read and write
7f7e33fff000
page read and write
7ffd029ff000
page execute read
55e25c99f000
page read and write
55e25c988000
page execute and read and write
7f7e34021000
page read and write
7f7d34043000
page read and write
7f7e38cd1000
page read and write
55e25a981000
page read and write
7f7e392c1000
page read and write
55e25d921000
page read and write
7f7e39919000
page read and write
7ffd029dd000
page read and write
7f7e3960f000
page read and write
7f7e3993d000
page read and write
7f7e3993d000
page read and write
7f7e39033000
page read and write
7f7e3942d000
page read and write
7f7d3404b000
page read and write
7ffd029dd000
page read and write
7f7e397f0000
page read and write
7f7e34021000
page read and write
7f7e38c3f000
page read and write
7f7e38cd1000
page read and write
55e25a730000
page execute read
55e25a98a000
page read and write
55e25c988000
page execute and read and write
55e25c99f000
page read and write
There are 40 hidden memdumps, click here to show them.