IOC Report
6NTauFuNV1.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/6NTauFuNV1.elf
/tmp/6NTauFuNV1.elf
/tmp/6NTauFuNV1.elf
-
/tmp/6NTauFuNV1.elf
-
/tmp/6NTauFuNV1.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.24

IPs

IP
Domain
Country
Malicious
37.221.93.146
unknown
Germany

Memdumps

Base Address
Regiontype
Protect
Malicious
7fc22400f000
page execute read
malicious
7fc22400f000
page execute read
malicious
7fc2aa555000
page read and write
560749925000
page read and write
7fc2ab09a000
page read and write
7fc224011000
page read and write
56074992d000
page read and write
7ffc6a2c9000
page read and write
7fc2a4000000
page read and write
56074d2e9000
page read and write
56074d2e9000
page read and write
56074992d000
page read and write
5607496f3000
page execute read
7ffc6a2c9000
page read and write
7fc2ab09a000
page read and write
7fc2ab055000
page read and write
7fc2aabd9000
page read and write
7fc2a9d52000
page read and write
7fc2aa563000
page read and write
7fc2aaf24000
page read and write
7fc2ab055000
page read and write
560749925000
page read and write
7fc224012000
page read and write
7ffc6a3a0000
page execute read
5607496f3000
page execute read
56074b92b000
page execute and read and write
7fc2aa7f2000
page read and write
7ffc6a3a0000
page execute read
56074b92b000
page execute and read and write
7fc2aaf24000
page read and write
56074b9c2000
page read and write
7fc2aa555000
page read and write
7fc2aa7f2000
page read and write
7fc224011000
page read and write
56074b9c2000
page read and write
7fc2aa563000
page read and write
7fc2a4000000
page read and write
7fc2a4021000
page read and write
7fc2a9d52000
page read and write
7fc2ab04d000
page read and write
7fc2aabb4000
page read and write
7fc224012000
page read and write
7fc2a4021000
page read and write
7fc2ab04d000
page read and write
7fc2aabb4000
page read and write
7fc2aabd9000
page read and write
There are 36 hidden memdumps, click here to show them.