IOC Report
boatnet.m68k.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.m68k.elf
/tmp/boatnet.m68k.elf
/tmp/boatnet.m68k.elf
-
/tmp/boatnet.m68k.elf
-
/tmp/boatnet.m68k.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
37.221.93.101
unknown
Germany
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f7d7000f000
page execute read
malicious
7f7d7000f000
page execute read
malicious
7f7df5a5e000
page read and write
7f7df58e8000
page read and write
7f7df5a11000
page read and write
558083685000
page execute read
7f7df5a5e000
page read and write
5580838b7000
page read and write
7f7d70012000
page read and write
7ffe74152000
page execute read
558085954000
page read and write
5580858bd000
page execute and read and write
7f7d70012000
page read and write
7f7df58e8000
page read and write
7f7df5578000
page read and write
5580838bf000
page read and write
7ffe74142000
page read and write
7f7df4716000
page read and write
7f7df559d000
page read and write
558085954000
page read and write
7f7df4f27000
page read and write
558086d03000
page read and write
7f7df51b6000
page read and write
7f7df51b6000
page read and write
7f7df559d000
page read and write
5580838b7000
page read and write
558086d03000
page read and write
7ffe74142000
page read and write
7ffe74152000
page execute read
7f7df4f19000
page read and write
7f7d70011000
page read and write
5580858bd000
page execute and read and write
5580838bf000
page read and write
7f7df5578000
page read and write
7f7d70011000
page read and write
7f7df5a19000
page read and write
7f7df0000000
page read and write
7f7df0000000
page read and write
7f7df0021000
page read and write
7f7df5a19000
page read and write
558083685000
page execute read
7f7df4f27000
page read and write
7f7df5a11000
page read and write
7f7df4f19000
page read and write
7f7df4716000
page read and write
7f7df0021000
page read and write
There are 36 hidden memdumps, click here to show them.