IOC Report
kYeWacX52V.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/kYeWacX52V.elf
/tmp/kYeWacX52V.elf
/tmp/kYeWacX52V.elf
-
/tmp/kYeWacX52V.elf
-
/tmp/kYeWacX52V.elf
-
/tmp/kYeWacX52V.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
There are 7 hidden processes, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7fa4b9ce9000
page read and write
7fa434016000
page read and write
5629b019f000
page read and write
7fa4ba82e000
page read and write
5629ad029000
page read and write
7fa4b4021000
page read and write
7fa434016000
page read and write
7ffeae362000
page execute read
7fa434015000
page read and write
5629b019f000
page read and write
7fa4b4000000
page read and write
7fa4ba7e1000
page read and write
5629acdef000
page execute read
7fa434010000
page read and write
7fa4b9f86000
page read and write
7fa4ba7e9000
page read and write
7fa434015000
page read and write
7fa4ba82e000
page read and write
5629af0be000
page read and write
7fa4b94e6000
page read and write
7fa4ba7e1000
page read and write
7fa4b4021000
page read and write
5629acdef000
page execute read
5629acdef000
page execute read
7ffeae362000
page execute read
5629af0be000
page read and write
5629af027000
page execute and read and write
7fa434010000
page read and write
5629af0be000
page read and write
7fa4b94e6000
page read and write
7fa434015000
page read and write
5629ad029000
page read and write
7fa4b9f86000
page read and write
7fa4ba82e000
page read and write
5629af027000
page execute and read and write
5629af027000
page execute and read and write
7fa4ba36d000
page read and write
7fa4b9cf7000
page read and write
7fa4ba348000
page read and write
5629b019f000
page read and write
7fa4ba6b8000
page read and write
7fa4b9ce9000
page read and write
5629ad021000
page read and write
7fa43400d000
page execute read
7ffeae362000
page execute read
7ffeae266000
page read and write
7ffeae266000
page read and write
7fa4ba348000
page read and write
7fa4b4000000
page read and write
7fa4ba36d000
page read and write
7fa4ba6b8000
page read and write
7fa434010000
page read and write
7fa4ba7e1000
page read and write
7fa4ba36d000
page read and write
7fa43400d000
page execute read
5629ad021000
page read and write
7fa4ba348000
page read and write
7fa4ba7e9000
page read and write
7fa4b9ce9000
page read and write
7fa4ba7e9000
page read and write
5629b01c0000
page read and write
7fa4b4021000
page read and write
7fa4b9cf7000
page read and write
7fa43400d000
page execute read
7fa4b94e6000
page read and write
5629ad029000
page read and write
7fa4b9cf7000
page read and write
7fa4b9f86000
page read and write
7fa4ba6b8000
page read and write
5629b01c0000
page read and write
5629ad021000
page read and write
7fa4b4000000
page read and write
7ffeae266000
page read and write
There are 63 hidden memdumps, click here to show them.