IOC Report
boatnet.mpsl.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
37.221.93.101
unknown
Germany
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f6a10412000
page execute read
malicious
7f6a10412000
page execute read
malicious
7f6a10412000
page execute read
malicious
7f6a98c90000
page read and write
7f6a982c0000
page read and write
7f6a97ab8000
page read and write
5569acca5000
page execute and read and write
7f6a10454000
page read and write
7f6a9857e000
page read and write
7f6a9895f000
page read and write
7f6a98f9a000
page read and write
7f6a982c0000
page read and write
7f6a98fa2000
page read and write
7f6a982c0000
page read and write
7f6a98fe7000
page read and write
7f6a98fe7000
page read and write
5569accbc000
page read and write
5569acca5000
page execute and read and write
5569accbc000
page read and write
7f6a9895f000
page read and write
5569aaa15000
page execute read
7ffd533f6000
page read and write
5569aac9d000
page read and write
7f6a98942000
page read and write
5569aaa15000
page execute read
7f6a982ce000
page read and write
5569adde0000
page read and write
7f6a98f9a000
page read and write
7f6a90021000
page read and write
7f6a98fe7000
page read and write
7f6a90000000
page read and write
7f6a98fa2000
page read and write
7f6a98e71000
page read and write
7f6a9857e000
page read and write
7f6a10454000
page read and write
7f6a10140000
page execute and read and write
7f6a9857e000
page read and write
7f6a98e71000
page read and write
7ffd533fd000
page execute read
5569aaca7000
page read and write
7f6a9891f000
page read and write
7ffd533fd000
page execute read
7f6a10454000
page read and write
5569accbc000
page read and write
7ffd533f6000
page read and write
7ffd533f6000
page read and write
5569aaca7000
page read and write
7f6a90000000
page read and write
7f6a97ab8000
page read and write
7f6a982ce000
page read and write
7f6a90021000
page read and write
7f6a10140000
page execute and read and write
7f6a9891f000
page read and write
7f6a98c90000
page read and write
5569adde0000
page read and write
5569aac9d000
page read and write
7f6a97ab8000
page read and write
7f6a98942000
page read and write
7f6a98f9a000
page read and write
7f6a98e71000
page read and write
5569aaa15000
page execute read
7f6a9895f000
page read and write
5569aaca7000
page read and write
7ffd533fd000
page execute read
7f6a98942000
page read and write
7f6a10140000
page execute and read and write
7f6a90000000
page read and write
5569adde0000
page read and write
7f6a98c90000
page read and write
7f6a90021000
page read and write
5569aac9d000
page read and write
7f6a98fa2000
page read and write
7f6a982ce000
page read and write
7f6a9891f000
page read and write
5569acca5000
page execute and read and write
There are 65 hidden memdumps, click here to show them.