IOC Report
boatnet.mpsl.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/tmp/boatnet.mpsl.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
There are 10 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
malicious

IPs

IP
Domain
Country
Malicious
212.224.93.228
unknown
Germany
109.202.202.202
unknown
Switzerland
91.189.91.43
unknown
United Kingdom
91.189.91.42
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7f8d8c412000
page execute read
malicious
7f8d8c412000
page execute read
malicious
7f8d8c412000
page execute read
malicious
55cb446c8000
page read and write
7f8e122f5000
page read and write
55cb4801b000
page read and write
7f8d8c454000
page read and write
7f8e13824000
page read and write
7f8e12dbb000
page read and write
7f8e136ae000
page read and write
7f8e1315c000
page read and write
7f8e12afd000
page read and write
7f8e136ae000
page read and write
55cb466d0000
page execute and read and write
55cb446c8000
page read and write
7f8d8c454000
page read and write
7f8e13824000
page read and write
55cb466d0000
page execute and read and write
55cb44440000
page execute read
7f8e1319c000
page read and write
7f8e0c000000
page read and write
7f8e0c000000
page read and write
7ffc1badc000
page read and write
7f8e0c021000
page read and write
7f8e12afd000
page read and write
7f8e13824000
page read and write
7f8e1315c000
page read and write
55cb446d2000
page read and write
7f8e12dbb000
page read and write
7f8d8c454000
page read and write
7ffc1badc000
page read and write
7ffc1bb66000
page execute read
7f8e1315c000
page read and write
55cb44440000
page execute read
7f8e12afd000
page read and write
7f8e0c021000
page read and write
7f8e1319c000
page read and write
7f8d8c140000
page execute and read and write
7f8e137d7000
page read and write
7f8e1317f000
page read and write
7ffc1badc000
page read and write
7f8e1319c000
page read and write
55cb446c8000
page read and write
7ffc1bb66000
page execute read
7ffc1bb66000
page execute read
7f8d8c140000
page execute and read and write
55cb466e7000
page read and write
7f8e134cd000
page read and write
7f8e1317f000
page read and write
7f8e122f5000
page read and write
55cb446d2000
page read and write
55cb4801b000
page read and write
7f8e137df000
page read and write
7f8e12b0b000
page read and write
55cb466e7000
page read and write
7f8e12b0b000
page read and write
55cb466e7000
page read and write
7f8e134cd000
page read and write
7f8e122f5000
page read and write
7f8e137df000
page read and write
7f8e0c021000
page read and write
7f8e0c000000
page read and write
7f8d8c140000
page execute and read and write
7f8e137df000
page read and write
7f8e137d7000
page read and write
7f8e134cd000
page read and write
7f8e1317f000
page read and write
55cb466d0000
page execute and read and write
7f8e137d7000
page read and write
55cb4801b000
page read and write
55cb44440000
page execute read
7f8e12b0b000
page read and write
7f8e136ae000
page read and write
55cb446d2000
page read and write
7f8e12dbb000
page read and write
There are 65 hidden memdumps, click here to show them.