IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7fa844028000
page execute read
malicious
7fa844028000
page execute read
malicious
7ffc09284000
page read and write
7fa94b168000
page read and write
7fa94a4b7000
page read and write
7fa94a4b7000
page read and write
5559907b9000
page read and write
7fa94afd6000
page read and write
7fa94aaa7000
page read and write
7fa94b123000
page read and write
7fa94a425000
page read and write
7fa94b123000
page read and write
7fa943fff000
page read and write
7fa949c1d000
page read and write
7fa949c1d000
page read and write
7fa94b168000
page read and write
7fa94aaa7000
page read and write
7fa844031000
page read and write
7fa94adf5000
page read and write
7fa94ac13000
page read and write
7fa94a819000
page read and write
7ffc09284000
page read and write
7fa943fff000
page read and write
55598e3bd000
page read and write
55598e16c000
page execute read
5559903c4000
page execute and read and write
7fa94aa84000
page read and write
7fa94adf5000
page read and write
7fa844031000
page read and write
7fa94a425000
page read and write
7fa844037000
page read and write
7fa944021000
page read and write
7fa94afd6000
page read and write
7fa94a819000
page read and write
5559903db000
page read and write
7fa94aa84000
page read and write
7fa944021000
page read and write
5559907b9000
page read and write
7ffc09342000
page execute read
55598e3c6000
page read and write
55598e3c6000
page read and write
55598e16c000
page execute read
7fa94ac13000
page read and write
5559903db000
page read and write
7ffc09342000
page execute read
7fa94b0ff000
page read and write
7fa844037000
page read and write
7fa94b0ff000
page read and write
5559903c4000
page execute and read and write
55598e3bd000
page read and write
There are 40 hidden memdumps, click here to show them.