IOC Report
boatnet.m68k.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/boatnet.m68k.elf
/tmp/boatnet.m68k.elf
/tmp/boatnet.m68k.elf
-
/tmp/boatnet.m68k.elf
-
/tmp/boatnet.m68k.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
-
/usr/sbin/xfpm-power-backlight-helper
/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
/usr/bin/dbus-daemon
-
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
/usr/lib/systemd/systemd
-
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
There are 12 hidden processes, click here to show them.

Domains

Name
IP
Malicious
daisy.ubuntu.com
162.213.35.25

IPs

IP
Domain
Country
Malicious
5.253.247.166
unknown
Germany
185.125.190.26
unknown
United Kingdom

Memdumps

Base Address
Regiontype
Protect
Malicious
7ff28400f000
page execute read
malicious
7ff28400f000
page execute read
malicious
55ff4a3d7000
page read and write
7ff304021000
page read and write
7ff30bf0a000
page read and write
7ffe49597000
page read and write
7ff284011000
page read and write
7ff284011000
page read and write
55ff4a3df000
page read and write
55ff4a1a5000
page execute read
7ff30c3cb000
page read and write
55ff4cc3c000
page read and write
7ff30c37e000
page read and write
55ff4cc3c000
page read and write
55ff4c3dd000
page execute and read and write
7ff30bee5000
page read and write
55ff4c474000
page read and write
7ff30b886000
page read and write
55ff4a1a5000
page execute read
7ff304021000
page read and write
55ff4a3df000
page read and write
55ff4c3dd000
page execute and read and write
7ffe495f3000
page execute read
7ff30b894000
page read and write
7ff30c386000
page read and write
7ff30c3cb000
page read and write
7ff304000000
page read and write
55ff4c474000
page read and write
7ff30c255000
page read and write
7ff30bf0a000
page read and write
7ff30b886000
page read and write
7ff30bee5000
page read and write
7ffe49597000
page read and write
7ff30c37e000
page read and write
7ff30b894000
page read and write
55ff4a3d7000
page read and write
7ff30c255000
page read and write
7ffe495f3000
page execute read
7ff30b083000
page read and write
7ff284012000
page read and write
7ff30bb23000
page read and write
7ff30c386000
page read and write
7ff304000000
page read and write
7ff284012000
page read and write
7ff30bb23000
page read and write
7ff30b083000
page read and write
There are 36 hidden memdumps, click here to show them.