IOC Report
AzRiLxCGXJ.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/AzRiLxCGXJ.elf
/tmp/AzRiLxCGXJ.elf
/tmp/AzRiLxCGXJ.elf
-
/tmp/AzRiLxCGXJ.elf
-
/tmp/AzRiLxCGXJ.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

IPs

IP
Domain
Country
Malicious
37.221.93.146
unknown
Germany
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f605c40c000
page execute read
malicious
7f605c40c000
page execute read
malicious
7f605c40c000
page execute read
malicious
7f60e0dc7000
page read and write
55c5022f7000
page read and write
55c5002da000
page read and write
55c50354f000
page read and write
7f60e1189000
page read and write
55c5002e2000
page read and write
7ffc3b235000
page execute read
7f60dc000000
page read and write
55c50354f000
page read and write
7f60e1189000
page read and write
7f60dc021000
page read and write
7f60e166f000
page read and write
55c5022e0000
page execute and read and write
7f60dc000000
page read and write
7f60e0b38000
page read and write
7f60e11ae000
page read and write
7f60e1622000
page read and write
7f60e0327000
page read and write
7ffc3b235000
page execute read
55c5022f7000
page read and write
7f60e14f9000
page read and write
55c5022e0000
page execute and read and write
7f60e162a000
page read and write
7f60e166f000
page read and write
55c5002e2000
page read and write
7f60e0b2a000
page read and write
7f605c41d000
page read and write
55c5002da000
page read and write
7f605c41e000
page read and write
7f60e0b38000
page read and write
7ffc3b235000
page execute read
55c5002da000
page read and write
7f60dc021000
page read and write
55c5002e2000
page read and write
7f60e0327000
page read and write
7f60e1622000
page read and write
55c50354f000
page read and write
55c5000c4000
page execute read
7f605c41e000
page read and write
7f605c41d000
page read and write
55c5000c4000
page execute read
7f60e0b2a000
page read and write
7ffc3b218000
page read and write
7f60e11ae000
page read and write
55c5000c4000
page execute read
7f605c41d000
page read and write
7f60e0327000
page read and write
7f60dc021000
page read and write
7f60e0b38000
page read and write
7f60dc000000
page read and write
55c5022e0000
page execute and read and write
7f60e0b2a000
page read and write
7f60e14f9000
page read and write
7f605c41e000
page read and write
7f60e11ae000
page read and write
7f60e0dc7000
page read and write
7f60e166f000
page read and write
7f60e1622000
page read and write
7f60e14f9000
page read and write
7f60e1189000
page read and write
55c5022f7000
page read and write
7f60e0dc7000
page read and write
7f60e162a000
page read and write
7ffc3b218000
page read and write
7f60e162a000
page read and write
7ffc3b218000
page read and write
There are 59 hidden memdumps, click here to show them.