IOC Report
XCpzABZN79.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/XCpzABZN79.elf
/tmp/XCpzABZN79.elf
/tmp/XCpzABZN79.elf
-
/tmp/XCpzABZN79.elf
-
/tmp/XCpzABZN79.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
There are 14 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
51.79.141.153
unknown
Canada

Memdumps

Base Address
Regiontype
Protect
Malicious
7f674002b000
page execute read
malicious
7f674002b000
page execute read
malicious
7f674002b000
page execute read
malicious
7f6848cbb000
page read and write
55c98cece000
page execute and read and write
7f684837d000
page read and write
7f6848fe9000
page read and write
7f68482eb000
page read and write
55c98e488000
page read and write
55c98cee5000
page read and write
7f684902e000
page read and write
55c98e488000
page read and write
7f68486df000
page read and write
7f6848e9c000
page read and write
7f684837d000
page read and write
7f6848ad9000
page read and write
7ffeb0085000
page read and write
7f683ffff000
page read and write
7f684896d000
page read and write
7f684894a000
page read and write
55c98cee5000
page read and write
7ffeb0085000
page read and write
55c98aed0000
page read and write
55c98aec7000
page read and write
7f6848fe9000
page read and write
7f684837d000
page read and write
55c98ac76000
page execute read
7f6848fc5000
page read and write
7f6740038000
page read and write
7ffeb009f000
page execute read
55c98aed0000
page read and write
7f68486df000
page read and write
7f68482eb000
page read and write
7f6848e9c000
page read and write
7f6847ae3000
page read and write
7ffeb009f000
page execute read
7f68482eb000
page read and write
55c98aec7000
page read and write
7f6848fc5000
page read and write
55c98aed0000
page read and write
7f684896d000
page read and write
7f684902e000
page read and write
55c98aec7000
page read and write
7f6840021000
page read and write
7f6847ae3000
page read and write
7f6840021000
page read and write
7f6740038000
page read and write
7f6848ad9000
page read and write
55c98cece000
page execute and read and write
7f6848fe9000
page read and write
55c98e488000
page read and write
7f6847ae3000
page read and write
7f6848e9c000
page read and write
7f68486df000
page read and write
55c98cee5000
page read and write
55c98ac76000
page execute read
7ffeb0085000
page read and write
7f684902e000
page read and write
7f684896d000
page read and write
7f6840021000
page read and write
7f6848fc5000
page read and write
7f684894a000
page read and write
7f6848ad9000
page read and write
55c98cece000
page execute and read and write
7f6848cbb000
page read and write
7f683ffff000
page read and write
55c98ac76000
page execute read
7f6740038000
page read and write
7f683ffff000
page read and write
7f684894a000
page read and write
7ffeb009f000
page execute read
7f6848cbb000
page read and write
There are 62 hidden memdumps, click here to show them.