IOC Report
boatnet.arm7.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.arm7.elf
/tmp/boatnet.arm7.elf
/tmp/boatnet.arm7.elf
-
/tmp/boatnet.arm7.elf
-
/tmp/boatnet.arm7.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
37.221.93.146
unknown
Germany

Memdumps

Base Address
Regiontype
Protect
Malicious
7fe4b002b000
page execute read
malicious
7fe4b002b000
page execute read
malicious
7fe4b002b000
page execute read
malicious
5584fbfe8000
page read and write
5584fab9a000
page read and write
7fe5b553f000
page read and write
7fe5affff000
page read and write
5584f892b000
page execute read
5584f8b7c000
page read and write
5584f892b000
page execute read
7fe5b6282000
page read and write
7fe5b55d1000
page read and write
5584fab83000
page execute and read and write
7fe5b5933000
page read and write
7fe5b5bc1000
page read and write
5584f8b85000
page read and write
5584fab83000
page execute and read and write
5584fbfe8000
page read and write
7fe5b6219000
page read and write
7fe5b4d37000
page read and write
7fe5b5f0f000
page read and write
7fe5b6282000
page read and write
7ffc263d0000
page execute read
7fe4b0038000
page read and write
7fe5b5f0f000
page read and write
5584f8b85000
page read and write
7ffc263d0000
page execute read
5584f892b000
page execute read
7fe5b5b9e000
page read and write
7fe5b553f000
page read and write
7fe5b6282000
page read and write
7ffc263d0000
page execute read
7fe5b623d000
page read and write
7fe4b0038000
page read and write
7fe5b0021000
page read and write
5584fbfe8000
page read and write
5584f8b7c000
page read and write
7fe5b5933000
page read and write
7fe5affff000
page read and write
5584fab9a000
page read and write
7fe5b60f0000
page read and write
5584fab9a000
page read and write
7fe5b0021000
page read and write
7fe5b5d2d000
page read and write
5584f8b85000
page read and write
7fe5b6219000
page read and write
7fe5b4d37000
page read and write
7fe5b6219000
page read and write
7fe5b5bc1000
page read and write
7fe5b553f000
page read and write
5584f8b7c000
page read and write
7fe5affff000
page read and write
7fe5b5bc1000
page read and write
7fe5b60f0000
page read and write
7fe5b623d000
page read and write
7ffc263aa000
page read and write
7fe5b5b9e000
page read and write
7fe5b4d37000
page read and write
7fe4b0038000
page read and write
7fe5b5f0f000
page read and write
7fe5b0021000
page read and write
7fe5b623d000
page read and write
7fe5b5933000
page read and write
7ffc263aa000
page read and write
7fe5b5d2d000
page read and write
7ffc263aa000
page read and write
7fe5b55d1000
page read and write
7fe5b55d1000
page read and write
7fe5b5d2d000
page read and write
7fe5b60f0000
page read and write
7fe5b5b9e000
page read and write
5584fab83000
page execute and read and write
There are 62 hidden memdumps, click here to show them.