IOC Report
yHQNHlgi7z.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/yHQNHlgi7z.elf
/tmp/yHQNHlgi7z.elf
/tmp/yHQNHlgi7z.elf
-
/tmp/yHQNHlgi7z.elf
-
/tmp/yHQNHlgi7z.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
51.79.141.153
unknown
Canada

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3ae8412000
page execute read
malicious
7f3ae8412000
page execute read
malicious
7f3ae8412000
page execute read
malicious
7f3ae8454000
page read and write
7f3b68000000
page read and write
7f3b6d241000
page read and write
7ffc55ed2000
page read and write
7f3b6ce60000
page read and write
7f3ae8140000
page execute and read and write
56452af74000
page read and write
7f3b6d884000
page read and write
7f3b6d241000
page read and write
7f3b6d8c9000
page read and write
5645271e1000
page execute read
7f3b6d572000
page read and write
564529471000
page execute and read and write
7f3b68021000
page read and write
7f3b6d241000
page read and write
7ffc55ed2000
page read and write
7f3ae8140000
page execute and read and write
5645271e1000
page execute read
7f3b6c39a000
page read and write
564529488000
page read and write
7f3b6d201000
page read and write
7ffc55ed2000
page read and write
7f3b6d201000
page read and write
7f3b68000000
page read and write
7f3b6ce60000
page read and write
7ffc55fb4000
page execute read
7f3b6cbb0000
page read and write
7f3b68021000
page read and write
7f3b6d572000
page read and write
7f3b6d224000
page read and write
7f3b6cba2000
page read and write
7f3b6cbb0000
page read and write
7f3b6ce60000
page read and write
7f3b68021000
page read and write
7f3ae8454000
page read and write
5645271e1000
page execute read
564527473000
page read and write
564529471000
page execute and read and write
564527473000
page read and write
564527469000
page read and write
564527473000
page read and write
7f3b6d753000
page read and write
7f3b6cba2000
page read and write
7f3b6d753000
page read and write
7f3b6d87c000
page read and write
564529488000
page read and write
7f3b6d87c000
page read and write
7ffc55fb4000
page execute read
7f3b6d753000
page read and write
7f3b6c39a000
page read and write
56452af74000
page read and write
7ffc55fb4000
page execute read
7f3b6d224000
page read and write
7f3b6d224000
page read and write
56452af74000
page read and write
7f3b6d8c9000
page read and write
7f3b6d884000
page read and write
7f3b6cbb0000
page read and write
7f3ae8140000
page execute and read and write
7f3b6d884000
page read and write
7f3b6d572000
page read and write
564527469000
page read and write
7f3b6cba2000
page read and write
564529471000
page execute and read and write
564527469000
page read and write
7f3ae8454000
page read and write
7f3b6d87c000
page read and write
564529488000
page read and write
7f3b68000000
page read and write
7f3b6d201000
page read and write
7f3b6d8c9000
page read and write
7f3b6c39a000
page read and write
There are 65 hidden memdumps, click here to show them.