IOC Report
na.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/na.elf
/tmp/na.elf
/tmp/na.elf
-
/tmp/na.elf
-
/tmp/na.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
There are 10 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
37.221.93.146
unknown
Germany

Memdumps

Base Address
Regiontype
Protect
Malicious
7f9adc411000
page execute read
malicious
7f9adc411000
page execute read
malicious
7f9adc411000
page execute read
malicious
7f9b64e02000
page read and write
7f9adc453000
page read and write
7ffe7e1ad000
page read and write
7f9adc140000
page execute and read and write
7f9b64db5000
page read and write
7f9b64c8c000
page read and write
7f9b5c000000
page read and write
5576b97e4000
page execute read
5576bcf4f000
page read and write
5576bba74000
page execute and read and write
5576b9a6c000
page read and write
7f9b64399000
page read and write
7f9b64db5000
page read and write
7f9adc453000
page read and write
7ffe7e1ad000
page read and write
7f9b64399000
page read and write
5576b9a76000
page read and write
7f9b6473a000
page read and write
7f9b64c8c000
page read and write
7f9b64aab000
page read and write
7f9adc453000
page read and write
7f9b638d3000
page read and write
7f9b64e02000
page read and write
7f9b6473a000
page read and write
7f9b5c000000
page read and write
5576b97e4000
page execute read
7f9adc140000
page execute and read and write
7f9b6477a000
page read and write
7f9adc140000
page execute and read and write
7f9b640db000
page read and write
7f9b638d3000
page read and write
7f9b6475d000
page read and write
7f9b6477a000
page read and write
5576bba8b000
page read and write
5576bba74000
page execute and read and write
7f9b6477a000
page read and write
7f9b640e9000
page read and write
7f9b5c021000
page read and write
5576b97e4000
page execute read
7f9b6475d000
page read and write
5576bba8b000
page read and write
5576bba8b000
page read and write
5576bcf4f000
page read and write
5576b9a6c000
page read and write
7f9b640e9000
page read and write
7f9b5c021000
page read and write
5576b9a6c000
page read and write
7ffe7e1c3000
page execute read
7f9b5c021000
page read and write
5576b9a76000
page read and write
7f9b64dbd000
page read and write
7f9b64aab000
page read and write
7f9b640db000
page read and write
5576bba74000
page execute and read and write
7f9b6473a000
page read and write
7f9b64db5000
page read and write
7f9b64dbd000
page read and write
7ffe7e1ad000
page read and write
7f9b640db000
page read and write
7f9b640e9000
page read and write
7f9b638d3000
page read and write
7f9b64dbd000
page read and write
7f9b64399000
page read and write
5576bcf4f000
page read and write
7f9b6475d000
page read and write
7f9b64e02000
page read and write
7f9b64c8c000
page read and write
7f9b64aab000
page read and write
7ffe7e1c3000
page execute read
5576b9a76000
page read and write
7f9b5c000000
page read and write
7ffe7e1c3000
page execute read
There are 65 hidden memdumps, click here to show them.