IOC Report
boatnet.sh4.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.sh4.elf
/tmp/boatnet.sh4.elf
/tmp/boatnet.sh4.elf
-
/tmp/boatnet.sh4.elf
-
/tmp/boatnet.sh4.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
37.221.93.101
unknown
Germany
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f441440c000
page execute read
malicious
7f441440c000
page execute read
malicious
7f441440c000
page execute read
malicious
7f4499ec5000
page read and write
7ffc00964000
page read and write
55f41d69f000
page read and write
55f41d6a7000
page read and write
7f4499874000
page read and write
7ffc00964000
page read and write
55f41d489000
page execute read
7f441441e000
page read and write
7f449a235000
page read and write
55f41d489000
page execute read
7f449a35e000
page read and write
7f449a35e000
page read and write
7ffc00964000
page read and write
7f4499eea000
page read and write
55f41d6a7000
page read and write
7f441441d000
page read and write
55f41f6bc000
page read and write
55f4215aa000
page read and write
7f4494021000
page read and write
55f4215aa000
page read and write
7f449a3ab000
page read and write
7ffc00972000
page execute read
7f4494021000
page read and write
7f4499ec5000
page read and write
7f4494021000
page read and write
55f41f6bc000
page read and write
7f4499866000
page read and write
7f4499866000
page read and write
7f449a3ab000
page read and write
7f4499b03000
page read and write
7f4494000000
page read and write
55f4215aa000
page read and write
7f4499eea000
page read and write
55f41d489000
page execute read
7f449a235000
page read and write
7ffc00972000
page execute read
7f449a235000
page read and write
7f441441d000
page read and write
7f449a366000
page read and write
7f4499063000
page read and write
55f41f6a5000
page execute and read and write
7f449a3ab000
page read and write
7f4499b03000
page read and write
55f41f6a5000
page execute and read and write
7f4494000000
page read and write
7f4499866000
page read and write
7f4499874000
page read and write
55f41d6a7000
page read and write
7f449a35e000
page read and write
7f441441e000
page read and write
7f449a366000
page read and write
55f41f6bc000
page read and write
55f41d69f000
page read and write
7f4499063000
page read and write
7ffc00972000
page execute read
55f41d69f000
page read and write
7f4499ec5000
page read and write
7f4499eea000
page read and write
7f4499b03000
page read and write
7f441441e000
page read and write
7f4499063000
page read and write
55f41f6a5000
page execute and read and write
7f4499874000
page read and write
7f4494000000
page read and write
7f449a366000
page read and write
7f441441d000
page read and write
There are 59 hidden memdumps, click here to show them.