IOC Report
boatnet.ppc.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.ppc.elf
/tmp/boatnet.ppc.elf
/tmp/boatnet.ppc.elf
-
/tmp/boatnet.ppc.elf
-
/tmp/boatnet.ppc.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
37.221.93.101
unknown
Germany

Memdumps

Base Address
Regiontype
Protect
Malicious
7fba017ef000
page read and write
7fba01a8c000
page read and write
7fba02334000
page read and write
7fb90c007000
page execute and read and write
7fb9fc021000
page read and write
7fb9fc021000
page read and write
559a47aa0000
page read and write
7ffe1a93e000
page execute read
559a43fcd000
page read and write
7fba00fec000
page read and write
559a45fe9000
page read and write
7fb9fc000000
page read and write
7fb90c00e000
page execute and read and write
7fba00fec000
page read and write
7fba01e4e000
page read and write
7fba017ef000
page read and write
7fba01e4e000
page read and write
7fb90c002000
page execute read
7ffe1a903000
page read and write
559a43fcd000
page read and write
7ffe1a903000
page read and write
559a43fcd000
page read and write
7fb90c020000
page read and write
7fba017fd000
page read and write
559a45fd3000
page execute and read and write
7fba021be000
page read and write
7fb90c00d000
page execute read
7fb9fc000000
page read and write
7fba01a8c000
page read and write
559a45fe9000
page read and write
7fb90c020000
page read and write
559a43fd5000
page read and write
559a45fd3000
page execute and read and write
7fba017ef000
page read and write
7fb90c00e000
page execute and read and write
559a43fd5000
page read and write
7fb90c002000
page execute read
7fba017fd000
page read and write
7ffe1a93e000
page execute read
7fba021be000
page read and write
7fba02334000
page read and write
7fb9fc021000
page read and write
7fba02334000
page read and write
559a45fe9000
page read and write
7fb90c00d000
page execute read
7fb90c007000
page execute and read and write
7fba022e7000
page read and write
7fba022e7000
page read and write
7fba022ef000
page read and write
7fba022ef000
page read and write
7fba01a8c000
page read and write
7fba01e73000
page read and write
7fba017fd000
page read and write
7fb90c007000
page execute and read and write
7fba01e73000
page read and write
559a47aa0000
page read and write
7fb90c020000
page read and write
7ffe1a93e000
page execute read
559a43d4a000
page execute read
7ffe1a903000
page read and write
7fb9fc000000
page read and write
7fba01e73000
page read and write
559a45fd3000
page execute and read and write
7fb90c00e000
page execute and read and write
7fba022ef000
page read and write
7fba022e7000
page read and write
7fb90c002000
page execute read
559a43fd5000
page read and write
7fba01e4e000
page read and write
7fba00fec000
page read and write
7fb90c00d000
page execute read
559a43d4a000
page execute read
7fba021be000
page read and write
559a43d4a000
page execute read
559a47aa0000
page read and write
There are 65 hidden memdumps, click here to show them.