IOC Report
boatnet.sh4.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.sh4.elf
/tmp/boatnet.sh4.elf
/tmp/boatnet.sh4.elf
-
/tmp/boatnet.sh4.elf
-
/tmp/boatnet.sh4.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
154.216.20.130
unknown
Seychelles
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f713440c000
page execute read
malicious
7f713440c000
page execute read
malicious
7f713440c000
page execute read
malicious
5579e594b000
page read and write
7f71ba2f2000
page read and write
5579e5735000
page execute read
7f71ba2f2000
page read and write
7f71b9a97000
page read and write
7f71b4021000
page read and write
7f713441d000
page read and write
7f71ba33f000
page read and write
7f71b9e7e000
page read and write
5579e7951000
page execute and read and write
7f71b9e59000
page read and write
5579e7951000
page execute and read and write
7f71b9e7e000
page read and write
5579e7951000
page execute and read and write
5579e5953000
page read and write
7f71ba2f2000
page read and write
7f71b9e59000
page read and write
7ffdce67f000
page read and write
7f713441e000
page read and write
5579e7f61000
page read and write
5579e5953000
page read and write
5579e5735000
page execute read
7f71ba1c9000
page read and write
7f71ba2fa000
page read and write
7ffdce737000
page execute read
5579e5735000
page execute read
7ffdce67f000
page read and write
5579e594b000
page read and write
7f71b97fa000
page read and write
5579e7f61000
page read and write
7f713441e000
page read and write
7f713441d000
page read and write
7f71b4000000
page read and write
5579e594b000
page read and write
5579e7968000
page read and write
7f71ba33f000
page read and write
5579e7f61000
page read and write
7f71b4000000
page read and write
7f71b9e7e000
page read and write
7f71b97fa000
page read and write
7f71ba1c9000
page read and write
7f71b4021000
page read and write
7f71b8ff7000
page read and write
7f71b9808000
page read and write
7f71b9808000
page read and write
7f71ba2fa000
page read and write
7f713441d000
page read and write
7f71b9e59000
page read and write
7f71b9808000
page read and write
5579e7968000
page read and write
7f71b9a97000
page read and write
5579e5953000
page read and write
7f71b8ff7000
page read and write
7f71b97fa000
page read and write
5579e7968000
page read and write
7f71ba1c9000
page read and write
7f71b9a97000
page read and write
7f71b8ff7000
page read and write
7f713441e000
page read and write
7ffdce67f000
page read and write
7ffdce737000
page execute read
7f71b4021000
page read and write
7ffdce737000
page execute read
7f71b4000000
page read and write
7f71ba2fa000
page read and write
7f71ba33f000
page read and write
There are 59 hidden memdumps, click here to show them.