IOC Report
boatnet.mpsl.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
There are 6 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
93.123.85.38
unknown
Bulgaria
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f3020412000
page execute read
malicious
7f3020412000
page execute read
malicious
7f3020412000
page execute read
malicious
7f30a0021000
page read and write
7f30a0000000
page read and write
55c03d827000
page read and write
7f30a5b2c000
page read and write
55c03d810000
page execute and read and write
7ffd76dac000
page execute read
7f30a680e000
page read and write
7f30a5dea000
page read and write
55c03b808000
page read and write
55c03d810000
page execute and read and write
7ffd76dac000
page execute read
7f30a0000000
page read and write
7f3020454000
page read and write
55c03b812000
page read and write
55c03d810000
page execute and read and write
7f30a61ae000
page read and write
7f30a6806000
page read and write
7f30a64fc000
page read and write
7f30a61cb000
page read and write
7f30a64fc000
page read and write
55c03b580000
page execute read
7f3020454000
page read and write
7f3020140000
page execute and read and write
7f30a5b3a000
page read and write
55c03d827000
page read and write
7f30a5b3a000
page read and write
7f30a5324000
page read and write
7f30a680e000
page read and write
55c03b808000
page read and write
7f30a61ae000
page read and write
55c03e386000
page read and write
7f30a5dea000
page read and write
55c03d827000
page read and write
7ffd76dac000
page execute read
7f30a618b000
page read and write
7f30a66dd000
page read and write
7ffd76d88000
page read and write
7f30a66dd000
page read and write
7f30a0021000
page read and write
55c03e386000
page read and write
7ffd76d88000
page read and write
55c03b580000
page execute read
7f30a618b000
page read and write
7f3020140000
page execute and read and write
7f30a0021000
page read and write
7f30a61ae000
page read and write
7f30a5324000
page read and write
7f30a64fc000
page read and write
7f30a6806000
page read and write
7f3020140000
page execute and read and write
7f30a6853000
page read and write
7f30a618b000
page read and write
55c03b812000
page read and write
7f30a5324000
page read and write
7f30a5b2c000
page read and write
7f30a6853000
page read and write
7f30a0000000
page read and write
7f30a5b3a000
page read and write
55c03b808000
page read and write
55c03b812000
page read and write
7f3020454000
page read and write
7f30a61cb000
page read and write
7ffd76d88000
page read and write
55c03e386000
page read and write
7f30a6806000
page read and write
55c03b580000
page execute read
7f30a5b2c000
page read and write
7f30a680e000
page read and write
7f30a5dea000
page read and write
7f30a66dd000
page read and write
7f30a61cb000
page read and write
7f30a6853000
page read and write
There are 65 hidden memdumps, click here to show them.