IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.ebcXKyBTgg /tmp/tmp.xjlTqoAop4 /tmp/tmp.ftbB2Q94Ra
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.ebcXKyBTgg /tmp/tmp.xjlTqoAop4 /tmp/tmp.ftbB2Q94Ra

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fe888028000
page execute read
malicious
7fe98fcea000
page read and write
56471c2dc000
page execute read
7fe888031000
page read and write
7fe990366000
page read and write
7fe98ee60000
page read and write
7fe98f6fa000
page read and write
7fe987fff000
page read and write
7fe990038000
page read and write
7fe990342000
page read and write
7fe98f668000
page read and write
7fffb9d90000
page read and write
7fe98fcc7000
page read and write
7fe9903ab000
page read and write
56471c52d000
page read and write
7fe98fe56000
page read and write
7fe988021000
page read and write
56471fe55000
page read and write
7fe990219000
page read and write
56471e54b000
page read and write
7fffb9dfc000
page execute read
7fe88803b000
page read and write
56471e534000
page execute and read and write
56471c536000
page read and write
7fe98fa5c000
page read and write
There are 15 hidden memdumps, click here to show them.