IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.167:77
malicious
http://www.baidu.com/search/spider.html)
unknown
http://www.billybobbot.com/crawler/)
unknown
http://fast.no/support/crawler.asp)
unknown
http://feedback.redkolibri.com/
unknown
http://www.baidu.com/search/spider.htm)
unknown

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.167
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
8063000
page execute read
malicious
8063000
page execute read
malicious
9401000
page read and write
fffa3000
page read and write
fffa3000
page read and write
9401000
page read and write
8064000
page read and write
8064000
page read and write
f7fe4000
page execute read
806b000
page read and write
f7fe4000
page execute read
806b000
page read and write
There are 2 hidden memdumps, click here to show them.