IOC Report
9AJs2Q5zFg.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/9AJs2Q5zFg.elf
/tmp/9AJs2Q5zFg.elf
/tmp/9AJs2Q5zFg.elf
-
/tmp/9AJs2Q5zFg.elf
-
/tmp/9AJs2Q5zFg.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
There are 10 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
207.244.199.140
unknown
United States
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f184400e000
page execute and read and write
7f1938629000
page read and write
7f1934000000
page read and write
7f19397fb000
page read and write
7ffc037a9000
page execute read
55e0afdad000
page read and write
7ffc03748000
page read and write
7f19397fb000
page read and write
55e0afdad000
page read and write
7f184400e000
page execute and read and write
7f1844002000
page execute read
7ffc037a9000
page execute read
55e0afdad000
page read and write
7f1938e3a000
page read and write
7f193948b000
page read and write
7f1934021000
page read and write
55e0add99000
page read and write
7f1844002000
page execute read
7f193992c000
page read and write
7f1934000000
page read and write
7f19390c9000
page read and write
7f1938e3a000
page read and write
55e0add91000
page read and write
7ffc037a9000
page execute read
55e0afd97000
page execute and read and write
7f1934021000
page read and write
7f1844020000
page read and write
55e0adb0e000
page execute read
55e0add91000
page read and write
7f1934021000
page read and write
7f1844007000
page execute and read and write
7f19390c9000
page read and write
7f1844020000
page read and write
7f1938629000
page read and write
7f193948b000
page read and write
55e0adb0e000
page execute read
7f1938e2c000
page read and write
55e0b0ad7000
page read and write
55e0adb0e000
page execute read
7f1938e2c000
page read and write
55e0afd97000
page execute and read and write
7f1939971000
page read and write
7f1939924000
page read and write
7f184400e000
page execute and read and write
7f193992c000
page read and write
7f1844002000
page execute read
7f184400d000
page execute read
55e0b0ad7000
page read and write
7f19394b0000
page read and write
7f193948b000
page read and write
7f19397fb000
page read and write
7f1939971000
page read and write
55e0add91000
page read and write
7f184400d000
page execute read
7f193992c000
page read and write
7f1939924000
page read and write
55e0b0ad7000
page read and write
7f1938e3a000
page read and write
7f1939924000
page read and write
7f19394b0000
page read and write
55e0add99000
page read and write
7f1938629000
page read and write
7f1844007000
page execute and read and write
7ffc03748000
page read and write
7f1939971000
page read and write
7f19394b0000
page read and write
7f19390c9000
page read and write
7f1934000000
page read and write
7f1844020000
page read and write
55e0afd97000
page execute and read and write
7f1938e2c000
page read and write
7f184400d000
page execute read
7ffc03748000
page read and write
55e0add99000
page read and write
7f1844007000
page execute and read and write
There are 65 hidden memdumps, click here to show them.