IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
109.202.202.202
unknown
Switzerland
188.212.158.45
unknown
Romania
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7fdc5002b000
page execute read
malicious
7fdc5002b000
page execute read
malicious
7fdc5002b000
page execute read
malicious
7fdd56881000
page read and write
7fdd56c44000
page read and write
7fdd56a63000
page read and write
7fdd56dd6000
page read and write
55aa98b26000
page execute read
7fdc50038000
page read and write
55aa9ad95000
page read and write
7fdd56715000
page read and write
7fdd4ffff000
page read and write
7fdd56a63000
page read and write
7ffd2b6e4000
page read and write
55aa98d80000
page read and write
7fdd56093000
page read and write
7fdd566f2000
page read and write
55aa98d77000
page read and write
7fdd56715000
page read and write
55aa98d80000
page read and write
7fdd56c44000
page read and write
7fdd5588b000
page read and write
7fdd56881000
page read and write
7fdd56715000
page read and write
7fdd56d91000
page read and write
55aa9ba94000
page read and write
7ffd2b7ab000
page execute read
7fdd56d91000
page read and write
7fdd56487000
page read and write
7fdc50038000
page read and write
55aa9ad7e000
page execute and read and write
7fdd56093000
page read and write
7ffd2b7ab000
page execute read
7fdd56125000
page read and write
55aa98b26000
page execute read
7fdd50021000
page read and write
7fdd5588b000
page read and write
7ffd2b6e4000
page read and write
55aa98b26000
page execute read
55aa98d77000
page read and write
7fdd56c44000
page read and write
7fdd56d6d000
page read and write
7fdd56d6d000
page read and write
7fdd56d6d000
page read and write
7fdd56487000
page read and write
7fdd566f2000
page read and write
7fdd56125000
page read and write
7fdd50021000
page read and write
55aa98d77000
page read and write
7fdd56a63000
page read and write
7fdd4ffff000
page read and write
55aa9ad95000
page read and write
7fdd5588b000
page read and write
7fdd56487000
page read and write
7fdd56093000
page read and write
7fdd566f2000
page read and write
55aa9ad95000
page read and write
7fdd50021000
page read and write
55aa9ad7e000
page execute and read and write
7fdd56125000
page read and write
7fdd56dd6000
page read and write
7fdd56d91000
page read and write
7fdd56881000
page read and write
7fdd56dd6000
page read and write
55aa9ba94000
page read and write
7fdc50038000
page read and write
55aa9ad7e000
page execute and read and write
7ffd2b6e4000
page read and write
55aa9ba94000
page read and write
7ffd2b7ab000
page execute read
55aa98d80000
page read and write
7fdd4ffff000
page read and write
There are 62 hidden memdumps, click here to show them.