IOC Report
boatnet.mpsl.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
37.221.93.101
unknown
Germany
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f979041b000
page execute read
malicious
7f979041b000
page execute read
malicious
7f979041b000
page execute read
malicious
55c805ff8000
page execute read
7fffe98f3000
page execute read
7f98157a8000
page read and write
55c80829f000
page read and write
55c80829f000
page read and write
7f98158d9000
page read and write
55c80628a000
page read and write
7f9810021000
page read and write
7f979042d000
page read and write
7f9814bf7000
page read and write
55c808288000
page execute and read and write
7f9815296000
page read and write
7f98155c7000
page read and write
7f979042d000
page read and write
7f9814c05000
page read and write
7f98143ef000
page read and write
7f9810021000
page read and write
7f9814eb5000
page read and write
7f9815296000
page read and write
55c808288000
page execute and read and write
7fffe9819000
page read and write
7f98155c7000
page read and write
55c805ff8000
page execute read
55c8085b3000
page read and write
7f9810021000
page read and write
55c806280000
page read and write
7f98143ef000
page read and write
55c80829f000
page read and write
7f9810000000
page read and write
55c80628a000
page read and write
55c808288000
page execute and read and write
7fffe98f3000
page execute read
7f979042d000
page read and write
7fffe9819000
page read and write
7f9815256000
page read and write
7f9810000000
page read and write
7f9815296000
page read and write
7f98155c7000
page read and write
7f98158d1000
page read and write
7f9814eb5000
page read and write
55c80628a000
page read and write
55c806280000
page read and write
7f981591e000
page read and write
7f9790140000
page execute and read and write
7f9815279000
page read and write
55c8085b3000
page read and write
7f9814c05000
page read and write
7f98158d1000
page read and write
7fffe98f3000
page execute read
7f9814eb5000
page read and write
7f9790140000
page execute and read and write
7f98158d9000
page read and write
7fffe9819000
page read and write
7f981591e000
page read and write
55c806280000
page read and write
7f9814c05000
page read and write
7f9815279000
page read and write
55c8085b3000
page read and write
7f9814bf7000
page read and write
7f9814bf7000
page read and write
55c805ff8000
page execute read
7f9815256000
page read and write
7f98158d9000
page read and write
7f98158d1000
page read and write
7f981591e000
page read and write
7f98157a8000
page read and write
7f9790140000
page execute and read and write
7f9815279000
page read and write
7f98143ef000
page read and write
7f9810000000
page read and write
7f9815256000
page read and write
7f98157a8000
page read and write
There are 65 hidden memdumps, click here to show them.