IOC Report
boatnet.arm.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.arm.elf
/tmp/boatnet.arm.elf
/tmp/boatnet.arm.elf
-
/tmp/boatnet.arm.elf
-
/tmp/boatnet.arm.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
154.216.20.130
unknown
Seychelles
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fb210025000
page execute read
malicious
7fb210025000
page execute read
malicious
7fb210025000
page execute read
malicious
7fb30ffff000
page read and write
55cffcbea000
page read and write
55cfff472000
page read and write
7fb317fbe000
page read and write
7fb318510000
page read and write
55cffebe8000
page execute and read and write
7fb3186a2000
page read and write
7fb31795f000
page read and write
7ffdc6447000
page read and write
55cffc990000
page execute read
7fb317fe1000
page read and write
7fb317d53000
page read and write
7fb31814d000
page read and write
7fb318510000
page read and write
7fb317fbe000
page read and write
55cffebff000
page read and write
7fb30ffff000
page read and write
7fb317fe1000
page read and write
7fb3186a2000
page read and write
7fb31832f000
page read and write
7ffdc653e000
page execute read
7fb21002e000
page read and write
7fb21002e000
page read and write
7fb317fe1000
page read and write
7fb31865d000
page read and write
7fb318639000
page read and write
7fb3179f1000
page read and write
7ffdc6447000
page read and write
7fb31814d000
page read and write
55cffebff000
page read and write
7fb31832f000
page read and write
7fb31865d000
page read and write
7fb31832f000
page read and write
55cffcbe1000
page read and write
7fb317157000
page read and write
55cffcbea000
page read and write
7fb31814d000
page read and write
7fb317d53000
page read and write
7fb310021000
page read and write
55cfff472000
page read and write
7fb318639000
page read and write
7fb30ffff000
page read and write
55cffcbe1000
page read and write
7fb317d53000
page read and write
7ffdc653e000
page execute read
7fb317157000
page read and write
7fb31865d000
page read and write
7fb31795f000
page read and write
55cffebe8000
page execute and read and write
7fb318510000
page read and write
7fb3179f1000
page read and write
55cfff472000
page read and write
7fb310021000
page read and write
7fb21002e000
page read and write
55cffcbea000
page read and write
55cffc990000
page execute read
7fb3186a2000
page read and write
55cffcbe1000
page read and write
55cffc990000
page execute read
7ffdc653e000
page execute read
7ffdc6447000
page read and write
7fb31795f000
page read and write
55cffebe8000
page execute and read and write
7fb310021000
page read and write
7fb317fbe000
page read and write
7fb318639000
page read and write
7fb317157000
page read and write
7fb3179f1000
page read and write
55cffebff000
page read and write
There are 62 hidden memdumps, click here to show them.