IOC Report
PqReTARl5l.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/PqReTARl5l.elf
/tmp/PqReTARl5l.elf
/tmp/PqReTARl5l.elf
-
/tmp/PqReTARl5l.elf
-
/tmp/PqReTARl5l.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
207.244.199.140
unknown
United States

Memdumps

Base Address
Regiontype
Protect
Malicious
7fdb24391000
page execute read
malicious
7fdb24391000
page execute read
malicious
7fdb24391000
page execute read
malicious
7fdba4000000
page read and write
7fdba8862000
page read and write
7fdba957b000
page read and write
7fdba9405000
page read and write
7fdba4000000
page read and write
7fdba952e000
page read and write
55f5cef9e000
page execute and read and write
55f5cef9e000
page execute and read and write
7fdba8b12000
page read and write
7ffc6e918000
page execute read
7fdba9224000
page read and write
7fdba8854000
page read and write
7fdba9405000
page read and write
7fdba9536000
page read and write
55f5ccf96000
page read and write
7fdba9536000
page read and write
7fdba4021000
page read and write
7fdba8ef3000
page read and write
55f5ccd0e000
page execute read
55f5ccf96000
page read and write
7fdba9405000
page read and write
7fdba957b000
page read and write
55f5cfd82000
page read and write
7fdba8854000
page read and write
55f5cfd82000
page read and write
7ffc6e918000
page execute read
7fdba8ef3000
page read and write
55f5cef9e000
page execute and read and write
55f5cfd82000
page read and write
7fdb243d3000
page read and write
7fdb243d3000
page read and write
7fdba8862000
page read and write
7ffc6e883000
page read and write
7ffc6e918000
page execute read
7fdba8862000
page read and write
7fdba952e000
page read and write
55f5ccfa0000
page read and write
7fdba952e000
page read and write
7fdba8ed6000
page read and write
7fdba8ef3000
page read and write
7ffc6e883000
page read and write
7fdba4021000
page read and write
7fdba8ed6000
page read and write
7fdb240bf000
page execute and read and write
7fdba9224000
page read and write
7ffc6e883000
page read and write
55f5cefb5000
page read and write
55f5ccfa0000
page read and write
7fdba4021000
page read and write
55f5ccd0e000
page execute read
7fdba8eb3000
page read and write
55f5ccd0e000
page execute read
7fdba8eb3000
page read and write
7fdba9536000
page read and write
55f5cefb5000
page read and write
7fdba8b12000
page read and write
7fdba8eb3000
page read and write
7fdb240bf000
page execute and read and write
7fdba957b000
page read and write
7fdba8854000
page read and write
55f5ccf96000
page read and write
7fdba8ed6000
page read and write
7fdba9224000
page read and write
55f5ccfa0000
page read and write
7fdb243d3000
page read and write
55f5cefb5000
page read and write
7fdba8b12000
page read and write
7fdb240bf000
page execute and read and write
7fdba4000000
page read and write
There are 62 hidden memdumps, click here to show them.