IOC Report
QJ1MJ1roKY.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/QJ1MJ1roKY.elf
/tmp/QJ1MJ1roKY.elf
/tmp/QJ1MJ1roKY.elf
-
/tmp/QJ1MJ1roKY.elf
-
/tmp/QJ1MJ1roKY.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
51.79.141.153
unknown
Canada
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f04c840c000
page execute read
malicious
7f04c840c000
page execute read
malicious
7f04c840c000
page execute read
malicious
563b58704000
page read and write
7f0548000000
page read and write
7f04c841d000
page read and write
7f054fd70000
page read and write
7f0550211000
page read and write
563b55f2c000
page read and write
7f054f711000
page read and write
563b55f24000
page read and write
7fffe9cd6000
page read and write
7f054f71f000
page read and write
7f054ef0e000
page read and write
7f054f71f000
page read and write
7f054f711000
page read and write
7f0548021000
page read and write
7f04c841d000
page read and write
7f04c841e000
page read and write
7f054ef0e000
page read and write
7f04c841e000
page read and write
7f054fd95000
page read and write
7f0550209000
page read and write
563b57f41000
page read and write
7f0550209000
page read and write
563b55d0e000
page execute read
7fffe9cd6000
page read and write
7f054fd95000
page read and write
7fffe9d6a000
page execute read
7f054f9ae000
page read and write
563b55f24000
page read and write
7f0550209000
page read and write
7f054fd70000
page read and write
7f054fd70000
page read and write
563b55f24000
page read and write
7f0550256000
page read and write
563b57f2a000
page execute and read and write
7f054fd95000
page read and write
7fffe9d6a000
page execute read
563b57f41000
page read and write
563b55d0e000
page execute read
7f05500e0000
page read and write
563b55f2c000
page read and write
7f05500e0000
page read and write
7f0548021000
page read and write
7f0548000000
page read and write
7f0548000000
page read and write
7fffe9d6a000
page execute read
563b58704000
page read and write
563b57f2a000
page execute and read and write
7f0550211000
page read and write
7f0548021000
page read and write
563b58704000
page read and write
563b57f2a000
page execute and read and write
7f054f9ae000
page read and write
563b55f2c000
page read and write
7f04c841d000
page read and write
7f054f71f000
page read and write
7f054f711000
page read and write
7fffe9cd6000
page read and write
7f0550211000
page read and write
563b55d0e000
page execute read
7f05500e0000
page read and write
7f054ef0e000
page read and write
7f04c841e000
page read and write
7f0550256000
page read and write
7f0550256000
page read and write
563b57f41000
page read and write
7f054f9ae000
page read and write
There are 59 hidden memdumps, click here to show them.