IOC Report
dQ10NiRRby.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/dQ10NiRRby.elf
/tmp/dQ10NiRRby.elf
/tmp/dQ10NiRRby.elf
-
/tmp/dQ10NiRRby.elf
-
/tmp/dQ10NiRRby.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
51.79.141.153
unknown
Canada
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fb158028000
page execute read
malicious
7fb158028000
page execute read
malicious
7fb158028000
page execute read
malicious
7fb25e846000
page read and write
7fb257fff000
page read and write
556895c48000
page execute and read and write
556893c4a000
page read and write
7ffcabaed000
page execute read
7fb25f48e000
page read and write
556897577000
page read and write
556897577000
page read and write
7fb158033000
page read and write
7fb257fff000
page read and write
7fb25ee13000
page read and write
556895c48000
page execute and read and write
5568939f0000
page execute read
556893c41000
page read and write
556893c4a000
page read and write
7fb25ee13000
page read and write
7fb25eba8000
page read and write
7fb25f184000
page read and write
7fb25f4f7000
page read and write
7fb25f4b2000
page read and write
7fb258021000
page read and write
7fb257fff000
page read and write
7fb25dfac000
page read and write
7fb158033000
page read and write
7fb25ee36000
page read and write
7fb25f184000
page read and write
7fb25efa2000
page read and write
7ffcaba5f000
page read and write
556895c5f000
page read and write
5568939f0000
page execute read
7fb25e846000
page read and write
7fb25ee36000
page read and write
7fb25f48e000
page read and write
7fb25eba8000
page read and write
7fb25e7b4000
page read and write
7fb25efa2000
page read and write
7fb25e7b4000
page read and write
7fb25f48e000
page read and write
7fb25f365000
page read and write
7fb25f365000
page read and write
556893c41000
page read and write
7fb25ee36000
page read and write
7fb25f365000
page read and write
7ffcabaed000
page execute read
7fb25dfac000
page read and write
7fb25f184000
page read and write
5568939f0000
page execute read
7fb258021000
page read and write
7fb25f4f7000
page read and write
7fb25ee13000
page read and write
556895c5f000
page read and write
7fb25f4b2000
page read and write
7fb25f4f7000
page read and write
556895c5f000
page read and write
7fb158033000
page read and write
556893c4a000
page read and write
7ffcaba5f000
page read and write
7ffcabaed000
page execute read
7fb258021000
page read and write
556895c48000
page execute and read and write
7fb25eba8000
page read and write
7fb25e846000
page read and write
7fb25efa2000
page read and write
7fb25dfac000
page read and write
7fb25f4b2000
page read and write
556897577000
page read and write
556893c41000
page read and write
7fb25e7b4000
page read and write
7ffcaba5f000
page read and write
There are 62 hidden memdumps, click here to show them.