IOC Report
boatnet.arm7.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.arm7.elf
/tmp/boatnet.arm7.elf
/tmp/boatnet.arm7.elf
-
/tmp/boatnet.arm7.elf
-
/tmp/boatnet.arm7.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
37.221.93.101
unknown
Germany

Memdumps

Base Address
Regiontype
Protect
Malicious
7f771c02b000
page execute read
malicious
7f771c02b000
page execute read
malicious
7f771c02b000
page execute read
malicious
7f78210c6000
page read and write
55c9f3219000
page read and write
7fffcd949000
page read and write
55c9f72d7000
page read and write
7f781bfff000
page read and write
7f78218ce000
page read and write
7f78225a8000
page read and write
7f7821960000
page read and write
7fffcd949000
page read and write
7f781c021000
page read and write
7f7822611000
page read and write
55c9f5237000
page read and write
7f78225cc000
page read and write
7f781c021000
page read and write
7f7822611000
page read and write
7f781bfff000
page read and write
7f782247f000
page read and write
7f771c038000
page read and write
7f7821960000
page read and write
7f771c038000
page read and write
55c9f3222000
page read and write
55c9f2fc8000
page execute read
55c9f72d7000
page read and write
7f78218ce000
page read and write
7f78210c6000
page read and write
7fffcd949000
page read and write
55c9f2fc8000
page execute read
7f7821f50000
page read and write
7f7821960000
page read and write
7f782247f000
page read and write
7f78220bc000
page read and write
7f78225cc000
page read and write
7fffcd960000
page execute read
7f7821f50000
page read and write
55c9f3219000
page read and write
55c9f5220000
page execute and read and write
7f78218ce000
page read and write
7f781bfff000
page read and write
7f771c038000
page read and write
7f78225a8000
page read and write
55c9f2fc8000
page execute read
7fffcd960000
page execute read
7f7821f50000
page read and write
55c9f3219000
page read and write
55c9f5237000
page read and write
7f78225a8000
page read and write
55c9f3222000
page read and write
7f7821cc2000
page read and write
55c9f5220000
page execute and read and write
7f7821f2d000
page read and write
7f78225cc000
page read and write
7f7821f2d000
page read and write
7f7821f2d000
page read and write
55c9f72d7000
page read and write
7f7822611000
page read and write
7f78220bc000
page read and write
55c9f3222000
page read and write
7fffcd960000
page execute read
7f781c021000
page read and write
7f782229e000
page read and write
7f7821cc2000
page read and write
7f78210c6000
page read and write
7f78220bc000
page read and write
7f782229e000
page read and write
7f7821cc2000
page read and write
7f782229e000
page read and write
55c9f5237000
page read and write
7f782247f000
page read and write
55c9f5220000
page execute and read and write
There are 62 hidden memdumps, click here to show them.