IOC Report
boatnet.arm.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.arm.elf
/tmp/boatnet.arm.elf
/tmp/boatnet.arm.elf
-
/tmp/boatnet.arm.elf
-
/tmp/boatnet.arm.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
37.221.93.101
unknown
Germany
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fcf4c028000
page execute read
malicious
7fcf4c028000
page execute read
malicious
7fcf4c028000
page execute read
malicious
7fd053ed4000
page read and write
7fd0535ca000
page read and write
7fd053ed4000
page read and write
55d6c7f27000
page read and write
7fd053835000
page read and write
55d6c82ae000
page read and write
55d6c5f12000
page read and write
7fd053268000
page read and write
7fd04bfff000
page read and write
7fd053835000
page read and write
7fd0531d6000
page read and write
7fd0529ce000
page read and write
7fd053eb0000
page read and write
7fd053835000
page read and write
7fd04c021000
page read and write
55d6c82ae000
page read and write
7fffeddfc000
page execute read
7fd053d87000
page read and write
55d6c5cb8000
page execute read
55d6c82ae000
page read and write
7fd053268000
page read and write
7fd0539c4000
page read and write
7fd053f19000
page read and write
55d6c7f10000
page execute and read and write
7fd053f19000
page read and write
7fd04bfff000
page read and write
7fd053268000
page read and write
7fd0529ce000
page read and write
7fd053858000
page read and write
7fd053d87000
page read and write
7fd0531d6000
page read and write
7fd0535ca000
page read and write
7fd053ba6000
page read and write
55d6c7f10000
page execute and read and write
7fd053eb0000
page read and write
7fd053d87000
page read and write
7fd053ba6000
page read and write
7fd053ba6000
page read and write
55d6c7f27000
page read and write
7fcf4c033000
page read and write
7fd0531d6000
page read and write
7fd053ed4000
page read and write
7fcf4c033000
page read and write
7fcf4c033000
page read and write
7fffeddfc000
page execute read
55d6c5f12000
page read and write
7fd053f19000
page read and write
55d6c5cb8000
page execute read
7fd053858000
page read and write
7fffedd63000
page read and write
7fd0539c4000
page read and write
7fd0539c4000
page read and write
7fffedd63000
page read and write
55d6c7f27000
page read and write
7fd04c021000
page read and write
55d6c7f10000
page execute and read and write
7fd0535ca000
page read and write
7fd053858000
page read and write
7fd0529ce000
page read and write
55d6c5f09000
page read and write
55d6c5f09000
page read and write
7fd04bfff000
page read and write
55d6c5cb8000
page execute read
7fffedd63000
page read and write
7fd053eb0000
page read and write
7fd04c021000
page read and write
55d6c5f12000
page read and write
55d6c5f09000
page read and write
7fffeddfc000
page execute read
There are 62 hidden memdumps, click here to show them.