IOC Report
na.elf

loading gif

Files

File Path
Type
Category
Malicious
na.elf
ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, not stripped
initial sample
malicious
/tmp/qemu-open.zUGkuH (deleted)
ASCII text
dropped

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-

URLs

Name
IP
Malicious
93.123.85.205:7777
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
93.123.85.205
unknown
Bulgaria
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7e04014000
page execute read
malicious
7f7e04014000
page execute read
malicious
7ffcf4046000
page read and write
7f7e8b240000
page read and write
7f7e04016000
page read and write
7f7e8c588000
page read and write
7f7e84000000
page read and write
7f7e84021000
page read and write
558664875000
page execute read
7f7e8ba43000
page read and write
7f7e8c0a2000
page read and write
7f7e8ba51000
page read and write
7f7e8bce0000
page read and write
558666b44000
page read and write
7f7e8c0c7000
page read and write
558664aa7000
page read and write
7f7e8c53b000
page read and write
5586680bc000
page read and write
7f7e8c543000
page read and write
7f7e84021000
page read and write
7ffcf40f8000
page execute read
7ffcf40f8000
page execute read
7f7e8c0a2000
page read and write
5586680bc000
page read and write
558666aad000
page execute and read and write
558664aa7000
page read and write
7f7e8bce0000
page read and write
7f7e8c588000
page read and write
7f7e8ba51000
page read and write
558664aaf000
page read and write
7f7e84000000
page read and write
7f7e8c412000
page read and write
7f7e8b240000
page read and write
7f7e8c0c7000
page read and write
558664aaf000
page read and write
7f7e8c412000
page read and write
7f7e04016000
page read and write
7f7e8c53b000
page read and write
7f7e8c543000
page read and write
558666aad000
page execute and read and write
7f7e0401c000
page read and write
558666b44000
page read and write
558664875000
page execute read
7f7e8ba43000
page read and write
7f7e0401c000
page read and write
7ffcf4046000
page read and write
There are 36 hidden memdumps, click here to show them.