IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, with debug_info, not stripped
initial sample
malicious
/tmp/qemu-open.weZRGw (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f1478025000
page execute read
malicious
7f1478025000
page execute read
malicious
7f157d808000
page read and write
7f1578021000
page read and write
55db78c81000
page execute and read and write
7f1478036000
page read and write
7f157dca9000
page read and write
7f157dca1000
page read and write
55db76c83000
page read and write
55db78c98000
page read and write
55db79d37000
page read and write
7f157dcee000
page read and write
7f157d82d000
page read and write
55db76c83000
page read and write
7fff3f340000
page execute read
7f1578000000
page read and write
7f157dca1000
page read and write
7f1578021000
page read and write
7f157dca9000
page read and write
55db76c7a000
page read and write
7fff3f25a000
page read and write
7f147803c000
page read and write
7f157d446000
page read and write
7f1578000000
page read and write
7f157d1b7000
page read and write
7f157d82d000
page read and write
55db76a4c000
page execute read
7f157d1a9000
page read and write
55db78c81000
page execute and read and write
7f147803c000
page read and write
55db79d37000
page read and write
7fff3f340000
page execute read
7f157db78000
page read and write
7f1478036000
page read and write
7f157c9a6000
page read and write
7f157dcee000
page read and write
55db78c98000
page read and write
7f157db78000
page read and write
7f157d1a9000
page read and write
7f157d446000
page read and write
7f157c9a6000
page read and write
7fff3f25a000
page read and write
55db76c7a000
page read and write
7f157d1b7000
page read and write
55db76a4c000
page execute read
7f157d808000
page read and write
There are 36 hidden memdumps, click here to show them.