IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/qemu-open.927MZh (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.SWnrHj3yFd /tmp/tmp.9Vj0sQu7JP /tmp/tmp.E4aqgWdPdk
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.SWnrHj3yFd /tmp/tmp.9Vj0sQu7JP /tmp/tmp.E4aqgWdPdk
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.167:77
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

IPs

IP
Domain
Country
Malicious
93.123.85.167
unknown
Bulgaria
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7890036000
page execute read
malicious
7f7890036000
page execute read
malicious
7f7995b17000
page read and write
55c0cbbfb000
page read and write
7ffe8075a000
page read and write
7f7996328000
page read and write
55c0c9884000
page read and write
55c0cb899000
page read and write
7f799699e000
page read and write
7f79965b7000
page read and write
7f7996e12000
page read and write
7f7890050000
page read and write
7f7996e1a000
page read and write
7f79965b7000
page read and write
7ffe80799000
page execute read
7f7990000000
page read and write
7ffe80799000
page execute read
7f7890048000
page read and write
7f7996979000
page read and write
55c0cb882000
page execute and read and write
7f7990021000
page read and write
55c0c964d000
page execute read
7f7996328000
page read and write
55c0c9884000
page read and write
7f7996ce9000
page read and write
7f7996e5f000
page read and write
55c0c964d000
page execute read
7f7996e12000
page read and write
7f7996e5f000
page read and write
55c0c987b000
page read and write
7f7995b17000
page read and write
7f7890048000
page read and write
7f7990021000
page read and write
55c0cb882000
page execute and read and write
7ffe8075a000
page read and write
7f799631a000
page read and write
7f7996ce9000
page read and write
55c0cbbfb000
page read and write
55c0cb899000
page read and write
7f7990000000
page read and write
7f7996e1a000
page read and write
7f799699e000
page read and write
7f7890050000
page read and write
55c0c987b000
page read and write
7f7996979000
page read and write
7f799631a000
page read and write
There are 36 hidden memdumps, click here to show them.