Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
na.elf
|
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
|
initial sample
|
||
/tmp/qemu-open.MnLeFo (deleted)
|
ASCII text
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/na.elf
|
/tmp/na.elf
|
||
/tmp/na.elf
|
-
|
||
/tmp/na.elf
|
-
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
93.123.85.205:7777
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
daisy.ubuntu.com
|
162.213.35.25
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
93.123.85.205
|
unknown
|
Bulgaria
|
||
185.125.190.26
|
unknown
|
United Kingdom
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f68a8418000
|
page execute read
|
|||
7f68a8418000
|
page execute read
|
|||
7f692fdc7000
|
page read and write
|
|||
559e104de000
|
page read and write
|
|||
7f692fdc7000
|
page read and write
|
|||
559e12c15000
|
page read and write
|
|||
559e124dc000
|
page execute and read and write
|
|||
7f692fc9e000
|
page read and write
|
|||
7f692fc9e000
|
page read and write
|
|||
7f68a8458000
|
page read and write
|
|||
7f692f74c000
|
page read and write
|
|||
7f692f0ed000
|
page read and write
|
|||
559e1024c000
|
page execute read
|
|||
7f692f0fb000
|
page read and write
|
|||
7f6928021000
|
page read and write
|
|||
7ffdd1b17000
|
page read and write
|
|||
559e104d4000
|
page read and write
|
|||
7f68a845e000
|
page read and write
|
|||
7f692e8e5000
|
page read and write
|
|||
7f692f74c000
|
page read and write
|
|||
7f692fdcf000
|
page read and write
|
|||
559e124f3000
|
page read and write
|
|||
7f692f0fb000
|
page read and write
|
|||
7f692fe14000
|
page read and write
|
|||
7f692f76f000
|
page read and write
|
|||
7f6928000000
|
page read and write
|
|||
7f692fdcf000
|
page read and write
|
|||
7f68a8458000
|
page read and write
|
|||
7f692f78c000
|
page read and write
|
|||
559e124dc000
|
page execute and read and write
|
|||
559e104de000
|
page read and write
|
|||
7f692fabd000
|
page read and write
|
|||
7f6928021000
|
page read and write
|
|||
7f692f3ab000
|
page read and write
|
|||
7f692e8e5000
|
page read and write
|
|||
7f692f76f000
|
page read and write
|
|||
7f692fe14000
|
page read and write
|
|||
7f692f0ed000
|
page read and write
|
|||
7ffdd1b91000
|
page execute read
|
|||
7f692f78c000
|
page read and write
|
|||
7f68a845e000
|
page read and write
|
|||
7f692f3ab000
|
page read and write
|
|||
559e1024c000
|
page execute read
|
|||
559e12c15000
|
page read and write
|
|||
7ffdd1b17000
|
page read and write
|
|||
7f692fabd000
|
page read and write
|
|||
559e124f3000
|
page read and write
|
|||
7ffdd1b91000
|
page execute read
|
|||
559e104d4000
|
page read and write
|
|||
7f6928000000
|
page read and write
|
There are 40 hidden memdumps, click here to show them.