IOC Report
XWHpNIPKrM.elf

loading gif

Processes

Path
Cmdline
Malicious
/tmp/XWHpNIPKrM.elf
/tmp/XWHpNIPKrM.elf
/tmp/XWHpNIPKrM.elf
-
/tmp/XWHpNIPKrM.elf
-
/tmp/XWHpNIPKrM.elf
-
/tmp/XWHpNIPKrM.elf
-
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
/usr/bin/xfce4-panel
-
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
There are 7 hidden processes, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7fc443721000
page read and write
55edb846e000
page execute and read and write
7fc443bc2000
page read and write
55edb61e5000
page execute read
7fc443a91000
page read and write
55edb61e5000
page execute read
7fc4430c2000
page read and write
7fc4428bf000
page read and write
7fc34c01e000
page read and write
7fc4430d0000
page read and write
55edb6468000
page read and write
7fc43c021000
page read and write
7fc443bba000
page read and write
7fc43c000000
page read and write
7fc443746000
page read and write
7fc443bba000
page read and write
55edb6468000
page read and write
7fc34c00d000
page execute read
55edb6470000
page read and write
55edba263000
page read and write
55edba263000
page read and write
7fc4430c2000
page read and write
7fc4428bf000
page read and write
7fc443721000
page read and write
7fc443721000
page read and write
7fc443c07000
page read and write
7fc443c07000
page read and write
7ffeb6b98000
page execute read
7fc34c023000
page read and write
55edb8484000
page read and write
7fc43c021000
page read and write
7fc443bc2000
page read and write
7fc34c023000
page read and write
7fc4430c2000
page read and write
55edba263000
page read and write
7ffeb6b98000
page execute read
7fc44335f000
page read and write
55edb846e000
page execute and read and write
7fc34c024000
page read and write
55edb6470000
page read and write
7fc443746000
page read and write
7fc43c000000
page read and write
7fc443746000
page read and write
7fc443bc2000
page read and write
7fc34c01e000
page read and write
7fc44335f000
page read and write
7fc443bba000
page read and write
55edb846e000
page execute and read and write
7ffeb6ac5000
page read and write
7ffeb6ac5000
page read and write
7fc34c00d000
page execute read
7fc43c021000
page read and write
7fc34c01e000
page read and write
7fc34c023000
page read and write
7fc4430d0000
page read and write
7fc443c07000
page read and write
55edb6470000
page read and write
7fc4428bf000
page read and write
7ffeb6b98000
page execute read
7ffeb6ac5000
page read and write
7fc44335f000
page read and write
7fc43c000000
page read and write
7fc443a91000
page read and write
55edb8484000
page read and write
7fc443a91000
page read and write
55edb61e5000
page execute read
7fc34c00d000
page execute read
7fc4430d0000
page read and write
55edb6468000
page read and write
55edb8484000
page read and write
7fc34c024000
page read and write
There are 61 hidden memdumps, click here to show them.