Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
na.elf
|
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped
|
initial sample
|
||
/tmp/qemu-open.SqQQIe (deleted)
|
ASCII text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/na.elf
|
/tmp/na.elf
|
||
/tmp/na.elf
|
-
|
||
/tmp/na.elf
|
-
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
93.123.85.205:7777
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
daisy.ubuntu.com
|
162.213.35.25
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
93.123.85.205
|
unknown
|
Bulgaria
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f7644013000
|
page execute read
|
|||
7f7644013000
|
page execute read
|
|||
556bd6fc4000
|
page execute and read and write
|
|||
7ffdd1245000
|
page read and write
|
|||
7f7739ce8000
|
page read and write
|
|||
7f7644029000
|
page read and write
|
|||
7f7644029000
|
page read and write
|
|||
7f7739485000
|
page read and write
|
|||
7f7739bb7000
|
page read and write
|
|||
7f7739ce0000
|
page read and write
|
|||
7f7734000000
|
page read and write
|
|||
7f7739d2d000
|
page read and write
|
|||
7f77391f6000
|
page read and write
|
|||
7f7739847000
|
page read and write
|
|||
556bd4fc6000
|
page read and write
|
|||
7f773986c000
|
page read and write
|
|||
556bd4fbe000
|
page read and write
|
|||
556bd4d3b000
|
page execute read
|
|||
7f7644023000
|
page read and write
|
|||
7f77391e8000
|
page read and write
|
|||
7f773986c000
|
page read and write
|
|||
556bd4fc6000
|
page read and write
|
|||
556bd4d3b000
|
page execute read
|
|||
556bd6fda000
|
page read and write
|
|||
7f77389e5000
|
page read and write
|
|||
7f7644023000
|
page read and write
|
|||
7f7734021000
|
page read and write
|
|||
7f7739bb7000
|
page read and write
|
|||
556bd6fc4000
|
page execute and read and write
|
|||
7f7739d2d000
|
page read and write
|
|||
7f77391e8000
|
page read and write
|
|||
7ffdd12cd000
|
page execute read
|
|||
7f77391f6000
|
page read and write
|
|||
7f7739847000
|
page read and write
|
|||
556bd7670000
|
page read and write
|
|||
7ffdd12cd000
|
page execute read
|
|||
7f7734000000
|
page read and write
|
|||
7f7739ce8000
|
page read and write
|
|||
7ffdd1245000
|
page read and write
|
|||
7f7739ce0000
|
page read and write
|
|||
556bd6fda000
|
page read and write
|
|||
556bd4fbe000
|
page read and write
|
|||
7f77389e5000
|
page read and write
|
|||
7f7739485000
|
page read and write
|
|||
556bd7670000
|
page read and write
|
|||
7f7734021000
|
page read and write
|
There are 36 hidden memdumps, click here to show them.