IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.SqQQIe (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7644013000
page execute read
malicious
7f7644013000
page execute read
malicious
556bd6fc4000
page execute and read and write
7ffdd1245000
page read and write
7f7739ce8000
page read and write
7f7644029000
page read and write
7f7644029000
page read and write
7f7739485000
page read and write
7f7739bb7000
page read and write
7f7739ce0000
page read and write
7f7734000000
page read and write
7f7739d2d000
page read and write
7f77391f6000
page read and write
7f7739847000
page read and write
556bd4fc6000
page read and write
7f773986c000
page read and write
556bd4fbe000
page read and write
556bd4d3b000
page execute read
7f7644023000
page read and write
7f77391e8000
page read and write
7f773986c000
page read and write
556bd4fc6000
page read and write
556bd4d3b000
page execute read
556bd6fda000
page read and write
7f77389e5000
page read and write
7f7644023000
page read and write
7f7734021000
page read and write
7f7739bb7000
page read and write
556bd6fc4000
page execute and read and write
7f7739d2d000
page read and write
7f77391e8000
page read and write
7ffdd12cd000
page execute read
7f77391f6000
page read and write
7f7739847000
page read and write
556bd7670000
page read and write
7ffdd12cd000
page execute read
7f7734000000
page read and write
7f7739ce8000
page read and write
7ffdd1245000
page read and write
7f7739ce0000
page read and write
556bd6fda000
page read and write
556bd4fbe000
page read and write
7f77389e5000
page read and write
7f7739485000
page read and write
556bd7670000
page read and write
7f7734021000
page read and write
There are 36 hidden memdumps, click here to show them.