IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.fEIzVkmMNE /tmp/tmp.DGnFjVnjf1 /tmp/tmp.NdOzBep5uQ
/usr/bin/dash
-
/usr/bin/rm
rm -f /tmp/tmp.fEIzVkmMNE /tmp/tmp.DGnFjVnjf1 /tmp/tmp.NdOzBep5uQ
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f03f802c000
page execute read
malicious
7f03f802c000
page execute read
malicious
7f03f803a000
page read and write
7f04feb83000
page read and write
55d985bc6000
page read and write
7f04feee5000
page read and write
55d983097000
page read and write
7f04feee5000
page read and write
55d9830a0000
page read and write
7f04ff6a2000
page read and write
7f03f8034000
page read and write
7f03f8034000
page read and write
55d982e46000
page execute read
7f04ff834000
page read and write
7f04f8021000
page read and write
55d9850b5000
page read and write
7fffe96b9000
page read and write
55d982e46000
page execute read
7f04ff2df000
page read and write
7fffe96b9000
page read and write
7fffe9726000
page execute read
55d9830a0000
page read and write
7f04ff2df000
page read and write
7f04f7fff000
page read and write
7f04ff834000
page read and write
55d985bc6000
page read and write
7f04ff4c1000
page read and write
7f04ff4c1000
page read and write
7f04ff6a2000
page read and write
7f04ff7ef000
page read and write
7f03f803a000
page read and write
7f04ff7cb000
page read and write
7f04fe2e9000
page read and write
7f04ff7ef000
page read and write
7f04ff7cb000
page read and write
55d98509e000
page execute and read and write
55d98509e000
page execute and read and write
7f04fe2e9000
page read and write
7f04ff150000
page read and write
7f04feaf1000
page read and write
55d9850b5000
page read and write
7f04ff173000
page read and write
7fffe9726000
page execute read
7f04feaf1000
page read and write
7f04ff150000
page read and write
7f04f7fff000
page read and write
7f04ff173000
page read and write
55d983097000
page read and write
7f04feb83000
page read and write
7f04f8021000
page read and write
There are 40 hidden memdumps, click here to show them.