Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/res.spc.elf
|
/tmp/res.spc.elf
|
||
/tmp/res.spc.elf
|
-
|
||
/tmp/res.spc.elf
|
-
|
||
/tmp/res.spc.elf
|
-
|
||
/usr/libexec/gnome-session-binary
|
-
|
||
/bin/sh
|
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
|
||
/usr/libexec/gsd-print-notifications
|
/usr/libexec/gsd-print-notifications
|
||
/usr/bin/xfce4-session
|
-
|
||
/usr/bin/rm
|
rm -f /home/saturnino/.cache/sessions/Thunar-2ec7c2e14-9c4d-40f3-9704-8617ab831fb4
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
244.88.126.107
|
unknown
|
Reserved
|
||
178.106.130.120
|
unknown
|
United Kingdom
|
||
255.29.62.234
|
unknown
|
Reserved
|
||
35.125.242.97
|
unknown
|
United States
|
||
161.55.217.56
|
unknown
|
United States
|
||
94.190.224.204
|
unknown
|
Hong Kong
|
||
70.170.35.167
|
unknown
|
United States
|
||
190.117.104.111
|
unknown
|
Peru
|
||
172.86.48.44
|
unknown
|
United States
|
||
83.91.48.246
|
unknown
|
Denmark
|
||
5.232.36.156
|
unknown
|
Iran (ISLAMIC Republic Of)
|
||
148.185.194.254
|
unknown
|
European Union
|
||
13.110.94.25
|
unknown
|
United States
|
||
115.238.69.229
|
unknown
|
China
|
||
196.142.7.209
|
unknown
|
Egypt
|
||
72.134.27.250
|
unknown
|
United States
|
||
240.238.27.55
|
unknown
|
Reserved
|
||
91.229.46.164
|
unknown
|
Iran (ISLAMIC Republic Of)
|
||
35.208.78.164
|
unknown
|
United States
|
||
190.25.0.185
|
unknown
|
Colombia
|
||
23.37.109.213
|
unknown
|
United States
|
||
122.159.16.106
|
unknown
|
China
|
||
248.210.23.18
|
unknown
|
Reserved
|
||
216.151.146.142
|
unknown
|
United States
|
||
34.80.115.33
|
unknown
|
United States
|
||
181.95.111.156
|
unknown
|
Argentina
|
||
63.133.174.216
|
unknown
|
United States
|
||
219.188.142.235
|
unknown
|
Japan
|
||
211.21.90.239
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
244.199.59.139
|
unknown
|
Reserved
|
||
105.127.45.217
|
unknown
|
Nigeria
|
||
33.46.218.241
|
unknown
|
United States
|
||
67.16.37.2
|
unknown
|
United States
|
||
114.111.41.112
|
unknown
|
Korea Republic of
|
||
250.201.146.215
|
unknown
|
Reserved
|
||
83.161.40.237
|
unknown
|
Netherlands
|
||
34.81.9.8
|
unknown
|
United States
|
||
213.203.35.34
|
unknown
|
Norway
|
||
61.249.26.31
|
unknown
|
Korea Republic of
|
||
29.116.98.125
|
unknown
|
United States
|
||
25.193.93.58
|
unknown
|
United Kingdom
|
||
122.160.6.68
|
unknown
|
India
|
||
41.96.238.17
|
unknown
|
Algeria
|
||
48.175.71.54
|
unknown
|
United States
|
||
41.234.182.9
|
unknown
|
Egypt
|
||
59.186.7.46
|
unknown
|
Korea Republic of
|
||
150.72.1.45
|
unknown
|
Japan
|
||
22.199.155.238
|
unknown
|
United States
|
||
186.95.209.142
|
unknown
|
Venezuela
|
||
204.22.16.90
|
unknown
|
United States
|
||
187.211.169.244
|
unknown
|
Mexico
|
||
111.117.222.124
|
unknown
|
China
|
||
246.130.191.156
|
unknown
|
Reserved
|
||
215.102.175.100
|
unknown
|
United States
|
||
48.236.189.149
|
unknown
|
United States
|
||
30.82.194.162
|
unknown
|
United States
|
||
81.60.121.184
|
unknown
|
Spain
|
||
124.90.27.13
|
unknown
|
China
|
||
211.98.54.204
|
unknown
|
China
|
||
215.35.158.22
|
unknown
|
United States
|
||
245.108.13.115
|
unknown
|
Reserved
|
||
206.137.137.135
|
unknown
|
United States
|
||
25.60.8.144
|
unknown
|
United Kingdom
|
||
222.253.216.239
|
unknown
|
Viet Nam
|
||
137.126.231.136
|
unknown
|
United States
|
||
137.150.107.61
|
unknown
|
United States
|
||
96.87.199.230
|
unknown
|
United States
|
||
249.37.103.19
|
unknown
|
Reserved
|
||
125.216.90.48
|
unknown
|
China
|
||
51.120.18.179
|
unknown
|
United Kingdom
|
||
102.3.9.108
|
unknown
|
unknown
|
||
147.206.127.204
|
unknown
|
United States
|
||
247.47.138.6
|
unknown
|
Reserved
|
||
29.94.89.141
|
unknown
|
United States
|
||
78.172.34.193
|
unknown
|
Turkey
|
||
99.18.178.106
|
unknown
|
United States
|
||
31.140.200.95
|
unknown
|
Turkey
|
||
191.18.161.25
|
unknown
|
Brazil
|
||
97.101.157.155
|
unknown
|
United States
|
||
36.90.163.250
|
unknown
|
Indonesia
|
||
154.253.50.77
|
unknown
|
Algeria
|
||
246.60.198.243
|
unknown
|
Reserved
|
||
72.80.146.109
|
unknown
|
United States
|
||
106.41.184.112
|
unknown
|
China
|
||
219.109.72.27
|
unknown
|
Japan
|
||
116.180.248.146
|
unknown
|
China
|
||
120.64.225.213
|
unknown
|
China
|
||
95.111.13.50
|
unknown
|
Bulgaria
|
||
56.120.255.8
|
unknown
|
United States
|
||
130.250.10.148
|
unknown
|
United States
|
||
44.50.94.43
|
unknown
|
United States
|
||
54.249.232.30
|
unknown
|
United States
|
||
44.99.103.103
|
unknown
|
United States
|
||
120.250.232.2
|
unknown
|
China
|
||
189.16.97.5
|
unknown
|
Brazil
|
||
253.56.137.215
|
unknown
|
Reserved
|
||
40.142.180.113
|
unknown
|
United States
|
||
68.63.202.176
|
unknown
|
United States
|
||
2.4.171.124
|
unknown
|
France
|
||
7.234.183.27
|
unknown
|
United States
|
There are 90 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
56480e0d6000
|
page read and write
|
|||
7fc195b94000
|
page read and write
|
|||
7fc09006c000
|
page read and write
|
|||
56480e0b6000
|
page read and write
|
|||
7fc1957ad000
|
page read and write
|
|||
7fc196010000
|
page read and write
|
|||
7fc196055000
|
page read and write
|
|||
56480b609000
|
page read and write
|
|||
56480b3db000
|
page execute read
|
|||
7fc09002c000
|
page read and write
|
|||
7ffd3db46000
|
page read and write
|
|||
7fc09001c000
|
page execute read
|
|||
56480d610000
|
page execute and read and write
|
|||
7ffd3db83000
|
page execute read
|
|||
7fc195510000
|
page read and write
|
|||
7fc196010000
|
page read and write
|
|||
7fc190021000
|
page read and write
|
|||
56480d627000
|
page read and write
|
|||
7fc196008000
|
page read and write
|
|||
7fc190000000
|
page read and write
|
|||
56480b612000
|
page read and write
|
|||
7fc195510000
|
page read and write
|
|||
56480b612000
|
page read and write
|
|||
7fc196055000
|
page read and write
|
|||
7ffd3db46000
|
page read and write
|
|||
7fc19551e000
|
page read and write
|
|||
56480d610000
|
page execute and read and write
|
|||
7fc194d0d000
|
page read and write
|
|||
56480d627000
|
page read and write
|
|||
7fc09002d000
|
page read and write
|
|||
7fc194d0d000
|
page read and write
|
|||
7fc09002d000
|
page read and write
|
|||
7fc190021000
|
page read and write
|
|||
7fc09001c000
|
page execute read
|
|||
7ffd3db83000
|
page execute read
|
|||
7fc195edf000
|
page read and write
|
|||
7fc195b6f000
|
page read and write
|
|||
7fc09002c000
|
page read and write
|
|||
56480b609000
|
page read and write
|
|||
7fc195b6f000
|
page read and write
|
|||
7fc190000000
|
page read and write
|
|||
7fc196008000
|
page read and write
|
|||
56480e0d6000
|
page read and write
|
|||
7fc195b94000
|
page read and write
|
|||
7fc195edf000
|
page read and write
|
|||
7fc1957ad000
|
page read and write
|
|||
56480b3db000
|
page execute read
|
|||
7fc19551e000
|
page read and write
|
There are 38 hidden memdumps, click here to show them.