Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
boatnet.x86.elf

Overview

General Information

Sample name:boatnet.x86.elf
Analysis ID:1582472
MD5:d2610e796559edd586be4f3cfea659da
SHA1:67ac4e25ed9856b839f2b11c32e758766a140e23
SHA256:75754fcc1c6ecbdee1bc04eb2e4a986d6fb12a63e8a6b663a012ff41b031aef6
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Machine Learning detection for sample
Sample is packed with UPX
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582472
Start date and time:2024-12-30 17:43:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:boatnet.x86.elf
Detection:MAL
Classification:mal76.spre.troj.evad.linELF@0/0@2/0
  • VT rate limit hit for: boatnet.x86.elf
Command:/tmp/boatnet.x86.elf
PID:5508
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5496, Parent: 3633)
  • rm (PID: 5496, Parent: 3633, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.s41XKiKcH3 /tmp/tmp.L2G72Ho1mZ /tmp/tmp.zBAgX0UGv5
  • dash New Fork (PID: 5497, Parent: 3633)
  • rm (PID: 5497, Parent: 3633, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.s41XKiKcH3 /tmp/tmp.L2G72Ho1mZ /tmp/tmp.zBAgX0UGv5
  • wrapper-2.0 (PID: 5521, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 5522, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 5523, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 5524, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
    • xfpm-power-backlight-helper (PID: 5543, Parent: 5524, MD5: 3d221ad23f28ca3259f599b1664e2427) Arguments: /usr/sbin/xfpm-power-backlight-helper --get-max-brightness
  • wrapper-2.0 (PID: 5525, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5526, Parent: 3172, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • xfconfd (PID: 5542, Parent: 5541, MD5: 4c7a0d6d258bb970905b19b84abcd8e9) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
  • systemd New Fork (PID: 5553, Parent: 2955)
  • xfce4-notifyd (PID: 5553, Parent: 2955, MD5: eee956f1b227c1d5031f9c61223255d1) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
5511.1.0000000008048000.0000000008057000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    5511.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xc998:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcab0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcac4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcad8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcaec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcb00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcb14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcb28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    5511.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xcf34:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    5511.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0x5d30:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    5511.1.0000000008048000.0000000008057000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
    • 0x80a2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
    Click to see the 31 entries
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: boatnet.x86.elfReversingLabs: Detection: 42%
    Source: boatnet.x86.elfJoe Sandbox ML: detected
    Source: global trafficTCP traffic: 192.168.2.14:56104 -> 154.216.17.216:3778
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.17.216
    Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
    Source: boatnet.x86.elfString found in binary or memory: http://upx.sf.net

    System Summary

    barindex
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
    Source: Process Memory Space: boatnet.x86.elf PID: 5508, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: boatnet.x86.elf PID: 5508, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: Process Memory Space: boatnet.x86.elf PID: 5510, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: boatnet.x86.elf PID: 5510, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: Process Memory Space: boatnet.x86.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: boatnet.x86.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3129, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3184, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3187, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3188, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3189, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3190, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3193, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3207, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3215, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3235, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5511, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5521, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5522, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5523, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5524, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5525, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5526, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5542, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5553, result: successfulJump to behavior
    Source: LOAD without section mappingsProgram segment: 0xc01000
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3129, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3184, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3187, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3188, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3189, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3190, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3193, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3207, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3215, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 3235, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5511, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5521, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5522, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5523, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5524, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5525, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5526, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5542, result: successfulJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)SIGKILL sent: pid: 5553, result: successfulJump to behavior
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
    Source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
    Source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
    Source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
    Source: Process Memory Space: boatnet.x86.elf PID: 5508, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: boatnet.x86.elf PID: 5508, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: Process Memory Space: boatnet.x86.elf PID: 5510, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: boatnet.x86.elf PID: 5510, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: Process Memory Space: boatnet.x86.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: boatnet.x86.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: classification engineClassification label: mal76.spre.troj.evad.linELF@0/0@2/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5521)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /home/saturnino/.fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/X11/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5523)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /home/saturnino/.fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/X11/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /home/saturnino/.fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/X11/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /home/saturnino/.cacheJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /home/saturnino/.localJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Directory: /home/saturnino/.configJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /home/saturnino/.fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/X11/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5542)Directory: /home/saturnino/.cacheJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5542)Directory: /home/saturnino/.localJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5542)Directory: /home/saturnino/.configJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5542)Directory: /home/saturnino/.configJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5553)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5553)Directory: /home/saturnino/.cacheJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5553)Directory: /home/saturnino/.localJump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5553)Directory: /home/saturnino/.configJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/5542/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/2672/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1583/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3244/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3120/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3361/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3239/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1577/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1610/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/512/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1299/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3235/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/514/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/519/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/2946/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/917/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/5553/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3134/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1593/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3011/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3094/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3406/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1589/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3129/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1588/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3402/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3125/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3246/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3245/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/767/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/800/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/888/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/801/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/769/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/803/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/806/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/807/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/928/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/2956/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3420/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/490/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3142/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1635/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1633/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1599/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3139/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1873/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1630/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3412/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/657/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/658/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/659/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/418/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/419/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1639/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1638/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/5454/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3398/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1371/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3392/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/780/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/660/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/661/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/782/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1369/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3304/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3425/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/785/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1642/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/940/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/941/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1640/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3147/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3268/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1364/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/548/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1647/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/2991/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1383/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1382/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1381/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/791/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/671/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/794/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1655/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/2986/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/795/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/674/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1653/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/797/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/2983/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3159/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/678/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1650/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3157/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/679/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3675/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1659/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3834/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3319/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/5350/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3178/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/1394/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3172/cmdlineJump to behavior
    Source: /tmp/boatnet.x86.elf (PID: 5509)File opened: /proc/3171/cmdlineJump to behavior
    Source: /usr/bin/dash (PID: 5496)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.s41XKiKcH3 /tmp/tmp.L2G72Ho1mZ /tmp/tmp.zBAgX0UGv5Jump to behavior
    Source: /usr/bin/dash (PID: 5497)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.s41XKiKcH3 /tmp/tmp.L2G72Ho1mZ /tmp/tmp.zBAgX0UGv5Jump to behavior
    Source: boatnet.x86.elfSubmission file: segment LOAD with 7.8789 entropy (max. 8.0)
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5521)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5522)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5523)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5524)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5553)Queries kernel information via 'uname': Jump to behavior

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: boatnet.x86.elf PID: 5508, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: boatnet.x86.elf PID: 5510, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: boatnet.x86.elf PID: 5511, type: MEMORYSTR

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: 5511.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: 5510.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: 5508.1.0000000008048000.0000000008057000.r-x.sdmp, type: MEMORY
    Source: Yara matchFile source: Process Memory Space: boatnet.x86.elf PID: 5508, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: boatnet.x86.elf PID: 5510, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: boatnet.x86.elf PID: 5511, type: MEMORYSTR
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Hidden Files and Directories
    1
    OS Credential Dumping
    1
    Security Software Discovery
    Remote ServicesData from Local System1
    Non-Standard Port
    Exfiltration Over Other Network Medium1
    Service Stop
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
    Obfuscated Files or Information
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
    File Deletion
    Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1582472 Sample: boatnet.x86.elf Startdate: 30/12/2024 Architecture: LINUX Score: 76 24 154.216.17.216, 3778, 56104, 56106 SKHT-ASShenzhenKatherineHengTechnologyInformationCo Seychelles 2->24 26 daisy.ubuntu.com 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Mirai 2->32 34 2 other signatures 2->34 7 dash rm boatnet.x86.elf 2->7         started        9 xfce4-panel wrapper-2.0 2->9         started        11 dash rm 2->11         started        13 7 other processes 2->13 signatures3 process4 process5 15 boatnet.x86.elf 7->15         started        18 boatnet.x86.elf 7->18         started        20 boatnet.x86.elf 7->20         started        22 wrapper-2.0 xfpm-power-backlight-helper 9->22         started        signatures6 36 Sample tries to kill multiple processes (SIGKILL) 15->36

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    boatnet.x86.elf42%ReversingLabsLinux.Backdoor.Mirai
    boatnet.x86.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    daisy.ubuntu.com
    162.213.35.25
    truefalse
      high
      NameSourceMaliciousAntivirus DetectionReputation
      http://upx.sf.netboatnet.x86.elffalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        154.216.17.216
        unknownSeychelles
        135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        154.216.17.216154.216.17.216-boatnet.mips-2024-12-29T22_41_29.elfGet hashmaliciousMiraiBrowse
          g082Q9DajU.exeGet hashmaliciousPureCrypter, LummaC, Amadey, Clipboard Hijacker, CryptOne, Cryptbot, PureLog StealerBrowse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            daisy.ubuntu.comfenty.arm6.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.25
            vcimanagement.i586.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 162.213.35.25
            vcimanagement.armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 162.213.35.25
            vcimanagement.armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 162.213.35.24
            bin.sh.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.25
            vcimanagement.powerpc.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 162.213.35.25
            vcimanagement.armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 162.213.35.25
            vcimanagement.arm.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.24
            vcimanagement.arm6.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.24
            vcimanagement.ppc.elfGet hashmaliciousMiraiBrowse
            • 162.213.35.25
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            SKHT-ASShenzhenKatherineHengTechnologyInformationCo154.216.17.216-boatnet.mips-2024-12-29T22_41_29.elfGet hashmaliciousMiraiBrowse
            • 154.216.17.216
            vcimanagement.armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 156.226.9.167
            vcimanagement.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
            • 156.254.70.178
            db0fa4b8db0333367e9bda3ab68b8042.spc.elfGet hashmaliciousMirai, GafgytBrowse
            • 156.230.19.172
            byte.arm.elfGet hashmaliciousMirai, OkiruBrowse
            • 154.216.19.138
            byte.spc.elfGet hashmaliciousMirai, OkiruBrowse
            • 154.216.19.138
            byte.m68k.elfGet hashmaliciousMirai, OkiruBrowse
            • 154.216.19.138
            byte.sh4.elfGet hashmaliciousMirai, OkiruBrowse
            • 154.216.19.138
            INV-#0020242312.docGet hashmaliciousAsyncRAT, DarkTortilla, VenomRATBrowse
            • 154.216.18.37
            Space.x86.elfGet hashmaliciousUnknownBrowse
            • 154.216.20.216
            No context
            No context
            No created / dropped files found
            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
            Entropy (8bit):7.874262789579672
            TrID:
            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
            File name:boatnet.x86.elf
            File size:29'044 bytes
            MD5:d2610e796559edd586be4f3cfea659da
            SHA1:67ac4e25ed9856b839f2b11c32e758766a140e23
            SHA256:75754fcc1c6ecbdee1bc04eb2e4a986d6fb12a63e8a6b663a012ff41b031aef6
            SHA512:910228016a57f6c76fcf29e7bd0a4d79a6772cda30489b99d9a10b92a00f56fc6829b35460ee09bc99c9fa7dc9607763dd01f39c0730c9975988c595c58bdf7a
            SSDEEP:768:0IUEbJVnDejywrBh61e+bRTCfol+52qCu:qqyhrB0e+bsfoW
            TLSH:3ED2E0F5A84C812BC811D13B82A71E8C666E6C8017779645A7DDC0BEEC832ECB635DC8
            File Content Preview:.ELF.....................x..4...........4. ...(.....................kp..kp..........................................Q.td...............................4UPX!........P...P.......Z........?d..ELF.......d.......4....4. (.......k.-.#................p.....)d..l

            ELF header

            Class:ELF32
            Data:2's complement, little endian
            Version:1 (current)
            Machine:Intel 80386
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - Linux
            ABI Version:0
            Entry Point Address:0xc07888
            Flags:0x0
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:0
            Section Header Size:40
            Number of Section Headers:0
            Header String Table Index:0
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00xc010000xc010000x706b0x706b7.87890x5R E0x1000
            LOAD0x9000x80599000x80599000x00x00.00000x6RW 0x1000
            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
            TimestampSource PortDest PortSource IPDest IP
            Dec 30, 2024 17:43:58.024364948 CET561043778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.029279947 CET377856104154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:58.029328108 CET561043778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.029388905 CET561043778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.034125090 CET377856104154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:58.034168005 CET561043778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.040033102 CET377856104154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:58.699225903 CET377856104154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:58.699430943 CET561043778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.699430943 CET561043778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.699430943 CET561063778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.704233885 CET377856106154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:58.704310894 CET561063778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.704324007 CET561063778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.709116936 CET377856106154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:58.709162951 CET561063778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:58.713924885 CET377856106154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:59.361426115 CET377856106154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:59.361546040 CET561063778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:59.361567974 CET561063778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:59.361613989 CET561083778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:59.366406918 CET377856108154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:59.366481066 CET561083778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:59.366494894 CET561083778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:59.371254921 CET377856108154.216.17.216192.168.2.14
            Dec 30, 2024 17:43:59.371316910 CET561083778192.168.2.14154.216.17.216
            Dec 30, 2024 17:43:59.376100063 CET377856108154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.032373905 CET377856108154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.032481909 CET561083778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.032510042 CET561083778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.032558918 CET561103778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.037334919 CET377856110154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.037420988 CET561103778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.037440062 CET561103778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.042273045 CET377856110154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.042324066 CET561103778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.047166109 CET377856110154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.704849958 CET377856110154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.705100060 CET561123778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.705105066 CET561103778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.705105066 CET561103778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.709969997 CET377856112154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.710031033 CET561123778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.710056067 CET561123778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.714811087 CET377856112154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:00.714858055 CET561123778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:00.719643116 CET377856112154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:01.365415096 CET377856112154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:01.365535975 CET561123778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:01.365714073 CET561123778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:01.365714073 CET561143778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:01.370719910 CET377856114154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:01.370793104 CET561143778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:01.370872974 CET561143778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:01.375617981 CET377856114154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:01.375659943 CET561143778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:01.380517960 CET377856114154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.032959938 CET377856114154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.033072948 CET561143778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.033101082 CET561143778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.033148050 CET561163778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.038121939 CET377856116154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.038191080 CET561163778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.038213968 CET561163778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.043298960 CET377856116154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.043338060 CET561163778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.048228979 CET377856116154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.706161976 CET377856116154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.706537962 CET561163778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.706537962 CET561163778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.706537962 CET561183778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.711438894 CET377856118154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.711514950 CET561183778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.711543083 CET561183778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.716336012 CET377856118154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:02.716382027 CET561183778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:02.721179962 CET377856118154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:03.352344990 CET561183778192.168.2.14154.216.17.216
            Dec 30, 2024 17:44:03.357378960 CET377856118154.216.17.216192.168.2.14
            Dec 30, 2024 17:44:03.357430935 CET561183778192.168.2.14154.216.17.216
            TimestampSource PortDest PortSource IPDest IP
            Dec 30, 2024 17:46:43.771825075 CET3512653192.168.2.148.8.8.8
            Dec 30, 2024 17:46:43.771878958 CET5941753192.168.2.148.8.8.8
            Dec 30, 2024 17:46:43.778206110 CET53594178.8.8.8192.168.2.14
            Dec 30, 2024 17:46:43.778414011 CET53351268.8.8.8192.168.2.14
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Dec 30, 2024 17:46:43.771825075 CET192.168.2.148.8.8.80x26ceStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
            Dec 30, 2024 17:46:43.771878958 CET192.168.2.148.8.8.80x2242Standard query (0)daisy.ubuntu.com28IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Dec 30, 2024 17:46:43.778414011 CET8.8.8.8192.168.2.140x26ceNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
            Dec 30, 2024 17:46:43.778414011 CET8.8.8.8192.168.2.140x26ceNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

            System Behavior

            Start time (UTC):16:43:49
            Start date (UTC):30/12/2024
            Path:/usr/bin/dash
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):16:43:49
            Start date (UTC):30/12/2024
            Path:/usr/bin/rm
            Arguments:rm -f /tmp/tmp.s41XKiKcH3 /tmp/tmp.L2G72Ho1mZ /tmp/tmp.zBAgX0UGv5
            File size:72056 bytes
            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

            Start time (UTC):16:43:49
            Start date (UTC):30/12/2024
            Path:/usr/bin/dash
            Arguments:-
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

            Start time (UTC):16:43:49
            Start date (UTC):30/12/2024
            Path:/usr/bin/rm
            Arguments:rm -f /tmp/tmp.s41XKiKcH3 /tmp/tmp.L2G72Ho1mZ /tmp/tmp.zBAgX0UGv5
            File size:72056 bytes
            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

            Start time (UTC):16:43:57
            Start date (UTC):30/12/2024
            Path:/tmp/boatnet.x86.elf
            Arguments:/tmp/boatnet.x86.elf
            File size:29044 bytes
            MD5 hash:d2610e796559edd586be4f3cfea659da

            Start time (UTC):16:43:57
            Start date (UTC):30/12/2024
            Path:/tmp/boatnet.x86.elf
            Arguments:-
            File size:29044 bytes
            MD5 hash:d2610e796559edd586be4f3cfea659da

            Start time (UTC):16:43:57
            Start date (UTC):30/12/2024
            Path:/tmp/boatnet.x86.elf
            Arguments:-
            File size:29044 bytes
            MD5 hash:d2610e796559edd586be4f3cfea659da

            Start time (UTC):16:43:57
            Start date (UTC):30/12/2024
            Path:/tmp/boatnet.x86.elf
            Arguments:-
            File size:29044 bytes
            MD5 hash:d2610e796559edd586be4f3cfea659da
            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/bin/xfce4-panel
            Arguments:-
            File size:375768 bytes
            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
            File size:35136 bytes
            MD5 hash:ac0b8a906f359a8ae102244738682e76

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/bin/xfce4-panel
            Arguments:-
            File size:375768 bytes
            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
            File size:35136 bytes
            MD5 hash:ac0b8a906f359a8ae102244738682e76

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/bin/xfce4-panel
            Arguments:-
            File size:375768 bytes
            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
            File size:35136 bytes
            MD5 hash:ac0b8a906f359a8ae102244738682e76

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/bin/xfce4-panel
            Arguments:-
            File size:375768 bytes
            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
            File size:35136 bytes
            MD5 hash:ac0b8a906f359a8ae102244738682e76

            Start time (UTC):16:44:07
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
            Arguments:-
            File size:35136 bytes
            MD5 hash:ac0b8a906f359a8ae102244738682e76

            Start time (UTC):16:44:07
            Start date (UTC):30/12/2024
            Path:/usr/sbin/xfpm-power-backlight-helper
            Arguments:/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
            File size:14656 bytes
            MD5 hash:3d221ad23f28ca3259f599b1664e2427

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/bin/xfce4-panel
            Arguments:-
            File size:375768 bytes
            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
            File size:35136 bytes
            MD5 hash:ac0b8a906f359a8ae102244738682e76

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/bin/xfce4-panel
            Arguments:-
            File size:375768 bytes
            MD5 hash:a15b657c7d54ac1385f1f15004ea6784

            Start time (UTC):16:44:02
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
            File size:35136 bytes
            MD5 hash:ac0b8a906f359a8ae102244738682e76

            Start time (UTC):16:44:07
            Start date (UTC):30/12/2024
            Path:/usr/bin/dbus-daemon
            Arguments:-
            File size:249032 bytes
            MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

            Start time (UTC):16:44:07
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
            File size:112880 bytes
            MD5 hash:4c7a0d6d258bb970905b19b84abcd8e9

            Start time (UTC):16:44:11
            Start date (UTC):30/12/2024
            Path:/usr/lib/systemd/systemd
            Arguments:-
            File size:1620224 bytes
            MD5 hash:9b2bec7092a40488108543f9334aab75

            Start time (UTC):16:44:11
            Start date (UTC):30/12/2024
            Path:/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
            Arguments:/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
            File size:112872 bytes
            MD5 hash:eee956f1b227c1d5031f9c61223255d1