IOC Report
m7Bm4mCkhy.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/m7Bm4mCkhy.elf
/tmp/m7Bm4mCkhy.elf
/tmp/m7Bm4mCkhy.elf
-
/tmp/m7Bm4mCkhy.elf
-
/tmp/m7Bm4mCkhy.elf
-
/tmp/m7Bm4mCkhy.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
There are 11 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://scan.chromies.cf/9x83HE5AFD/arm7.jade
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown

Domains

Name
IP
Malicious
cnc.chromies.cf
5.181.156.131

IPs

IP
Domain
Country
Malicious
41.227.130.15
unknown
Tunisia
197.179.188.147
unknown
Kenya
197.202.142.106
unknown
Algeria
41.113.116.35
unknown
South Africa
197.114.240.235
unknown
Algeria
41.160.78.204
unknown
South Africa
156.250.39.43
unknown
Seychelles
156.82.246.164
unknown
United States
156.19.205.12
unknown
United States
197.118.196.115
unknown
Algeria
197.253.181.174
unknown
Morocco
41.85.67.89
unknown
South Africa
197.205.216.128
unknown
Algeria
197.131.5.115
unknown
Morocco
41.98.9.80
unknown
Algeria
197.158.155.110
unknown
Zambia
197.233.153.123
unknown
Namibia
156.206.150.238
unknown
Egypt
197.225.170.110
unknown
Mauritius
156.93.245.159
unknown
United States
156.24.69.15
unknown
United States
41.242.253.56
unknown
South Africa
156.19.248.151
unknown
United States
197.99.25.223
unknown
South Africa
156.13.199.31
unknown
New Zealand
41.238.160.237
unknown
Egypt
41.206.79.23
unknown
Cote D'ivoire
156.16.94.234
unknown
unknown
197.10.60.136
unknown
Tunisia
41.172.174.98
unknown
South Africa
156.7.114.118
unknown
United States
197.58.218.76
unknown
Egypt
41.144.121.243
unknown
South Africa
41.36.8.133
unknown
Egypt
197.115.66.146
unknown
Algeria
156.145.16.105
unknown
United States
156.15.110.4
unknown
United States
41.234.171.155
unknown
Egypt
41.128.164.189
unknown
Egypt
156.233.154.33
unknown
Seychelles
156.42.246.248
unknown
United States
41.207.190.185
unknown
Togo
41.87.44.187
unknown
unknown
156.209.39.54
unknown
Egypt
41.237.17.55
unknown
Egypt
197.170.12.9
unknown
South Africa
197.217.101.169
unknown
Angola
41.250.112.251
unknown
Morocco
197.245.206.236
unknown
South Africa
156.23.248.204
unknown
United States
41.96.193.72
unknown
Algeria
41.12.96.5
unknown
South Africa
197.18.142.180
unknown
Tunisia
197.247.24.219
unknown
Morocco
197.32.199.121
unknown
Egypt
156.74.43.47
unknown
United States
41.109.28.90
unknown
Algeria
197.65.42.112
unknown
South Africa
156.178.14.133
unknown
Egypt
197.140.173.215
unknown
Algeria
197.124.237.52
unknown
Egypt
197.65.117.43
unknown
South Africa
41.167.180.4
unknown
South Africa
197.217.157.185
unknown
Angola
156.142.178.145
unknown
United States
156.123.164.31
unknown
United States
197.68.119.191
unknown
South Africa
41.239.215.167
unknown
Egypt
197.147.224.47
unknown
Morocco
156.95.224.119
unknown
United States
156.115.72.20
unknown
Switzerland
41.80.171.50
unknown
Kenya
197.50.228.94
unknown
Egypt
156.108.56.192
unknown
United States
41.133.38.116
unknown
South Africa
41.151.59.137
unknown
South Africa
41.22.7.35
unknown
South Africa
197.242.164.145
unknown
Mozambique
156.156.25.153
unknown
Tanzania United Republic of
41.191.83.90
unknown
Egypt
197.18.31.28
unknown
Tunisia
197.160.138.193
unknown
Egypt
197.28.135.217
unknown
Tunisia
197.164.50.35
unknown
Egypt
156.24.175.175
unknown
United States
156.140.224.69
unknown
United States
197.139.22.151
unknown
Kenya
156.211.39.227
unknown
Egypt
41.180.70.72
unknown
South Africa
197.3.142.100
unknown
Tunisia
197.198.52.28
unknown
Egypt
156.153.188.52
unknown
United States
156.67.238.31
unknown
Germany
41.187.249.142
unknown
Egypt
197.94.56.124
unknown
South Africa
156.60.62.179
unknown
United States
41.13.60.195
unknown
South Africa
197.149.162.180
unknown
South Africa
197.27.130.70
unknown
Tunisia
197.112.173.249
unknown
Algeria
There are 90 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
8061000
page execute read
malicious
8061000
page execute read
malicious
8061000
page execute read
malicious
ff90d000
page read and write
ff90d000
page read and write
8064000
page read and write
9aef000
page read and write
f7f3b000
page read and write
8062000
page read and write
9aef000
page read and write
ff90d000
page read and write
f7f3f000
page execute read
9af0000
page read and write
f7f3f000
page execute read
8062000
page read and write
9aef000
page read and write
f7f3f000
page execute read
8064000
page read and write
8064000
page read and write
8062000
page read and write
There are 10 hidden memdumps, click here to show them.