IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.MnLeFo (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f68a8418000
page execute read
malicious
7f68a8418000
page execute read
malicious
7f692fdc7000
page read and write
559e104de000
page read and write
7f692fdc7000
page read and write
559e12c15000
page read and write
559e124dc000
page execute and read and write
7f692fc9e000
page read and write
7f692fc9e000
page read and write
7f68a8458000
page read and write
7f692f74c000
page read and write
7f692f0ed000
page read and write
559e1024c000
page execute read
7f692f0fb000
page read and write
7f6928021000
page read and write
7ffdd1b17000
page read and write
559e104d4000
page read and write
7f68a845e000
page read and write
7f692e8e5000
page read and write
7f692f74c000
page read and write
7f692fdcf000
page read and write
559e124f3000
page read and write
7f692f0fb000
page read and write
7f692fe14000
page read and write
7f692f76f000
page read and write
7f6928000000
page read and write
7f692fdcf000
page read and write
7f68a8458000
page read and write
7f692f78c000
page read and write
559e124dc000
page execute and read and write
559e104de000
page read and write
7f692fabd000
page read and write
7f6928021000
page read and write
7f692f3ab000
page read and write
7f692e8e5000
page read and write
7f692f76f000
page read and write
7f692fe14000
page read and write
7f692f0ed000
page read and write
7ffdd1b91000
page execute read
7f692f78c000
page read and write
7f68a845e000
page read and write
7f692f3ab000
page read and write
559e1024c000
page execute read
559e12c15000
page read and write
7ffdd1b17000
page read and write
7f692fabd000
page read and write
559e124f3000
page read and write
7ffdd1b91000
page execute read
559e104d4000
page read and write
7f6928000000
page read and write
There are 40 hidden memdumps, click here to show them.