Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
wind.arm7.elf

Overview

General Information

Sample name:wind.arm7.elf
Analysis ID:1583158
MD5:2783e361b89161f63de2ff6247a5a493
SHA1:b870328c8f8a4a2be4f6d279d6c486400254ef73
SHA256:7a15574774ebe273a94d072c3de699220e7b977e224fb50f172a95f8db07f768
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583158
Start date and time:2025-01-02 05:21:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:wind.arm7.elf
Detection:MAL
Classification:mal72.spre.troj.evad.linELF@0/0@2/0
Command:/tmp/wind.arm7.elf
PID:5455
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • wrapper-2.0 (PID: 5468, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 5469, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 5470, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 5471, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
    • xfpm-power-backlight-helper (PID: 5490, Parent: 5471, MD5: 3d221ad23f28ca3259f599b1664e2427) Arguments: /usr/sbin/xfpm-power-backlight-helper --get-max-brightness
  • wrapper-2.0 (PID: 5472, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5473, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • xfconfd (PID: 5489, Parent: 5488, MD5: 4c7a0d6d258bb970905b19b84abcd8e9) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
  • systemd New Fork (PID: 5496, Parent: 2935)
  • xfce4-notifyd (PID: 5496, Parent: 2935, MD5: eee956f1b227c1d5031f9c61223255d1) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
5455.1.00007efeec017000.00007efeec02b000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    5455.1.00007efeec017000.00007efeec02b000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x11dec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11e8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11ea0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11eb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11ec8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11edc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11ef0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11f04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11f18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11f2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11f40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11f54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11f68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x11f7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    5455.1.00007efeec017000.00007efeec02b000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0x12344:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    5461.1.00007efeec017000.00007efeec02b000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5461.1.00007efeec017000.00007efeec02b000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x11dec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ea0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11eb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ec8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11edc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ef0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      Click to see the 13 entries
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: wind.arm7.elfVirustotal: Detection: 52%Perma Link
      Source: wind.arm7.elfReversingLabs: Detection: 63%
      Source: global trafficTCP traffic: 192.168.2.13:48586 -> 45.95.169.120:3778
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: unknownTCP traffic detected without corresponding DNS query: 45.95.169.120
      Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
      Source: wind.arm7.elfString found in binary or memory: http://upx.sf.net

      System Summary

      barindex
      Source: 5455.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5455.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 5461.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5461.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 5459.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5459.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: wind.arm7.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: wind.arm7.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: wind.arm7.elf PID: 5459, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: wind.arm7.elf PID: 5459, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: wind.arm7.elf PID: 5461, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: wind.arm7.elf PID: 5461, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3104, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3161, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3162, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3163, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3164, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3165, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3170, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3182, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3208, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3212, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5461, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5468, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5469, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5470, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5471, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5472, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5473, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5489, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5496, result: successfulJump to behavior
      Source: LOAD without section mappingsProgram segment: 0x8000
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3104, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3161, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3162, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3163, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3164, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3165, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3170, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3182, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3208, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 3212, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5461, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5468, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5469, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5470, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5471, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5472, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5473, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5489, result: successfulJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)SIGKILL sent: pid: 5496, result: successfulJump to behavior
      Source: 5455.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5455.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 5461.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5461.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 5459.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5459.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: wind.arm7.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: wind.arm7.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: wind.arm7.elf PID: 5459, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: wind.arm7.elf PID: 5459, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: wind.arm7.elf PID: 5461, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: wind.arm7.elf PID: 5461, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: classification engineClassification label: mal72.spre.troj.evad.linELF@0/0@2/0

      Data Obfuscation

      barindex
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
      Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5468)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5469)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /home/saturnino/.fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/X11/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /home/saturnino/.fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/X11/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /home/saturnino/.fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/X11/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /home/saturnino/.cacheJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /home/saturnino/.localJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Directory: /home/saturnino/.configJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /home/saturnino/.fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/X11/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5489)Directory: /home/saturnino/.cacheJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5489)Directory: /home/saturnino/.localJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5489)Directory: /home/saturnino/.configJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5489)Directory: /home/saturnino/.configJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5496)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5496)Directory: /home/saturnino/.cacheJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5496)Directory: /home/saturnino/.localJump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5496)Directory: /home/saturnino/.configJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3122/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3117/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3114/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/914/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/518/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/519/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/917/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3134/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3375/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3132/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3095/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1745/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1866/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1588/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/884/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1982/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/765/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3246/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/767/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/800/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3641/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1906/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/802/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/803/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1748/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3420/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1482/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/490/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1480/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1755/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1238/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1875/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/2964/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3413/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1751/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1872/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/2961/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1475/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/656/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/778/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/657/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/658/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/659/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/418/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/5437/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/936/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/419/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/5438/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/816/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1879/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/5295/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1891/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3310/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3153/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/780/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/660/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1921/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3705/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/783/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1765/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3706/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/2974/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3707/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1400/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1884/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3424/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3708/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/2972/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3147/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/2970/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1881/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3146/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3300/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1805/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1925/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1804/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1648/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1922/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3429/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/5461/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/5463/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3442/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3165/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3164/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3163/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3162/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/790/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3161/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/792/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/793/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/672/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1930/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/795/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/674/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3315/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1411/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/2984/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/1410/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/797/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/676/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3434/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3158/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/678/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/679/cmdlineJump to behavior
      Source: /tmp/wind.arm7.elf (PID: 5457)File opened: /proc/3795/cmdlineJump to behavior
      Source: wind.arm7.elfSubmission file: segment LOAD with 7.9534 entropy (max. 8.0)
      Source: /tmp/wind.arm7.elf (PID: 5455)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5468)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5469)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5470)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5471)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5472)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5473)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5496)Queries kernel information via 'uname': Jump to behavior
      Source: wind.arm7.elf, 5455.1.000055f9b1cc0000.000055f9b1e8e000.rw-.sdmp, wind.arm7.elf, 5459.1.000055f9b1cc0000.000055f9b1e8e000.rw-.sdmp, wind.arm7.elf, 5461.1.000055f9b1cc0000.000055f9b1e8e000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
      Source: wind.arm7.elf, 5455.1.000055f9b1cc0000.000055f9b1e8e000.rw-.sdmp, wind.arm7.elf, 5459.1.000055f9b1cc0000.000055f9b1e8e000.rw-.sdmp, wind.arm7.elf, 5461.1.000055f9b1cc0000.000055f9b1e8e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
      Source: wind.arm7.elf, 5455.1.00007fffe04bb000.00007fffe04dc000.rw-.sdmp, wind.arm7.elf, 5459.1.00007fffe04bb000.00007fffe04dc000.rw-.sdmp, wind.arm7.elf, 5461.1.00007fffe04bb000.00007fffe04dc000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
      Source: wind.arm7.elf, 5455.1.00007fffe04bb000.00007fffe04dc000.rw-.sdmp, wind.arm7.elf, 5459.1.00007fffe04bb000.00007fffe04dc000.rw-.sdmp, wind.arm7.elf, 5461.1.00007fffe04bb000.00007fffe04dc000.rw-.sdmpBinary or memory string: vqtx86_64/usr/bin/qemu-arm/tmp/wind.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/wind.arm7.elf

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 5455.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5461.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5459.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: wind.arm7.elf PID: 5455, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: wind.arm7.elf PID: 5459, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: wind.arm7.elf PID: 5461, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 5455.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5461.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 5459.1.00007efeec017000.00007efeec02b000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: wind.arm7.elf PID: 5455, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: wind.arm7.elf PID: 5459, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: wind.arm7.elf PID: 5461, type: MEMORYSTR
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
      Hidden Files and Directories
      1
      OS Credential Dumping
      11
      Security Software Discovery
      Remote ServicesData from Local System1
      Non-Standard Port
      Exfiltration Over Other Network Medium1
      Service Stop
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
      Obfuscated Files or Information
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583158 Sample: wind.arm7.elf Startdate: 02/01/2025 Architecture: LINUX Score: 72 24 45.95.169.120, 3778, 48586, 48588 GIGANET-HUGigaNetInternetServiceProviderCoHU Croatia (LOCAL Name: Hrvatska) 2->24 26 daisy.ubuntu.com 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Mirai 2->32 34 Sample is packed with UPX 2->34 7 wind.arm7.elf 2->7         started        9 xfce4-panel wrapper-2.0 2->9         started        11 xfce4-panel wrapper-2.0 2->11         started        13 6 other processes 2->13 signatures3 process4 process5 15 wind.arm7.elf 7->15         started        18 wind.arm7.elf 7->18         started        20 wind.arm7.elf 7->20         started        22 wrapper-2.0 xfpm-power-backlight-helper 9->22         started        signatures6 36 Sample tries to kill multiple processes (SIGKILL) 15->36

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      wind.arm7.elf52%VirustotalBrowse
      wind.arm7.elf63%ReversingLabsLinux.Trojan.Mirai
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      daisy.ubuntu.com
      162.213.35.24
      truefalse
        high
        NameSourceMaliciousAntivirus DetectionReputation
        http://upx.sf.netwind.arm7.elffalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          45.95.169.120
          unknownCroatia (LOCAL Name: Hrvatska)
          42864GIGANET-HUGigaNetInternetServiceProviderCoHUfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          45.95.169.120arm.elfGet hashmaliciousMiraiBrowse
            x86.elfGet hashmaliciousMiraiBrowse
              45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                qlmOM0y98BGet hashmaliciousUnknownBrowse
                  3tgXa7CGc1Get hashmaliciousUnknownBrowse
                    rijsTqU0IfGet hashmaliciousUnknownBrowse
                      csB31kWt10Get hashmaliciousUnknownBrowse
                        QWg2NTuodYGet hashmaliciousUnknownBrowse
                          SL92Sz9pl2Get hashmaliciousUnknownBrowse
                            YpKL484IG5Get hashmaliciousUnknownBrowse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              daisy.ubuntu.comarm.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              i.elfGet hashmaliciousUnknownBrowse
                              • 162.213.35.25
                              loligang.arm6.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              loligang.arm5.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              B_Y_T_E_x86.elfGet hashmaliciousMirai, OkiruBrowse
                              • 162.213.35.25
                              main_x86_64.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                              • 162.213.35.25
                              89.250.72.36-mips-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                              • 162.213.35.24
                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              boatnet.mips.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              GIGANET-HUGigaNetInternetServiceProviderCoHUarm.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              x86.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              45.95.169.120-mips-2025-01-02T00_17_36.elfGet hashmaliciousMiraiBrowse
                              • 45.95.169.120
                              x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                              • 92.52.211.236
                              bin.i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                              • 88.209.217.191
                              la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                              • 5.180.123.145
                              IsopYwsaG5.elfGet hashmaliciousUnknownBrowse
                              • 45.95.169.122
                              na.elfGet hashmaliciousGafgytBrowse
                              • 45.95.169.14
                              S91AYfMUT0.exeGet hashmaliciousRemcosBrowse
                              • 45.95.169.137
                              bot_library.exeGet hashmaliciousUnknownBrowse
                              • 45.95.169.164
                              No context
                              No context
                              No created / dropped files found
                              File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, no section header
                              Entropy (8bit):7.974736168467682
                              TrID:
                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                              File name:wind.arm7.elf
                              File size:46'624 bytes
                              MD5:2783e361b89161f63de2ff6247a5a493
                              SHA1:b870328c8f8a4a2be4f6d279d6c486400254ef73
                              SHA256:7a15574774ebe273a94d072c3de699220e7b977e224fb50f172a95f8db07f768
                              SHA512:694bb82129773ca4078106fe0096f5b7bda4389170cdd953307fe43b08cf765bb7d3b78b75214262ef4307e73a25ca1d479205773d0656840682f9ded33f6dd2
                              SSDEEP:768:D/TYCoIxdEk+AxoTZAZHFeq8b36n29q3UELbUXfi6nVMQHI4vcGpv3:DECFd+A6YHAx6nbLRQZ3
                              TLSH:ED23F271450E9DF124703C36EA95D793BAF11AB1C66B302396280A3C2FB57531E5BE4E
                              File Content Preview:.ELF..............(.....H...4...........4. ...(.....................5{..5{..............dd..dd..dd..................Q.td...............................OUPX!....................h..........?.E.h;....#..$...o...xm...o.c.....W..8YG_^.q..._.2,..i........)^....

                              ELF header

                              Class:ELF32
                              Data:2's complement, little endian
                              Version:1 (current)
                              Machine:ARM
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:UNIX - Linux
                              ABI Version:0
                              Entry Point Address:0xe948
                              Flags:0x4000002
                              ELF Header Size:52
                              Program Header Offset:52
                              Program Header Size:32
                              Number of Program Headers:3
                              Section Header Offset:0
                              Section Header Size:40
                              Number of Section Headers:0
                              Header String Table Index:0
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x80000x80000x7b350x7b357.95340x5R E0x8000
                              LOAD0x64640x264640x264640x00x00.00000x6RW 0x8000
                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 2, 2025 05:21:53.785620928 CET485863778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:53.790606976 CET37784858645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:53.790658951 CET485863778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:53.814491987 CET485863778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.010797024 CET37784858645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:54.010858059 CET485863778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.015691042 CET37784858645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:54.453664064 CET37784858645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:54.453804970 CET485863778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.454317093 CET485863778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.454838991 CET485883778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.459680080 CET37784858845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:54.459753036 CET485883778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.460712910 CET485883778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.465523005 CET37784858845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:54.465574026 CET485883778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:54.470443010 CET37784858845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.106550932 CET37784858845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.106723070 CET485883778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.106761932 CET485883778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.107451916 CET485903778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.113254070 CET37784859045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.113356113 CET485903778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.114157915 CET485903778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.119926929 CET37784859045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.119993925 CET485903778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.125857115 CET37784859045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.757599115 CET37784859045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.757838011 CET485903778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.757838011 CET485903778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.758374929 CET485923778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.763299942 CET37784859245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.763360023 CET485923778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.764025927 CET485923778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.768831015 CET37784859245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:55.768927097 CET485923778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:55.773807049 CET37784859245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:56.418107986 CET37784859245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:56.418380976 CET485923778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:56.418380976 CET485923778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:56.418921947 CET485943778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:56.423719883 CET37784859445.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:56.423799992 CET485943778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:56.424595118 CET485943778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:56.429442883 CET37784859445.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:56.429531097 CET485943778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:56.434355021 CET37784859445.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.083306074 CET37784859445.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.083494902 CET485943778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.083530903 CET485943778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.084075928 CET485963778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.088857889 CET37784859645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.088917971 CET485963778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.089648008 CET485963778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.094413996 CET37784859645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.094491005 CET485963778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.099284887 CET37784859645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.738147974 CET37784859645.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.738383055 CET485963778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.738383055 CET485963778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.738883972 CET485983778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.743715048 CET37784859845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.743774891 CET485983778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.744476080 CET485983778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.749253988 CET37784859845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:57.749316931 CET485983778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:57.754122019 CET37784859845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:58.391760111 CET37784859845.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:58.391973972 CET485983778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:58.391973972 CET485983778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:58.392501116 CET486003778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:58.397341013 CET37784860045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:58.397438049 CET486003778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:58.398021936 CET486003778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:58.403414011 CET37784860045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:58.403469086 CET486003778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:58.408261061 CET37784860045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:59.048918962 CET37784860045.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:59.048995018 CET486003778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:59.049020052 CET486003778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:59.049407959 CET486023778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:59.054195881 CET37784860245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:59.054261923 CET486023778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:59.055155039 CET486023778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:59.059953928 CET37784860245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:59.059988976 CET486023778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:59.064814091 CET37784860245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:59.215871096 CET486023778192.168.2.1345.95.169.120
                              Jan 2, 2025 05:21:59.263501883 CET37784860245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:59.543066025 CET37784860245.95.169.120192.168.2.13
                              Jan 2, 2025 05:21:59.543133974 CET486023778192.168.2.1345.95.169.120
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 2, 2025 05:24:38.922354937 CET5614353192.168.2.138.8.8.8
                              Jan 2, 2025 05:24:38.922434092 CET4790253192.168.2.138.8.8.8
                              Jan 2, 2025 05:24:38.928953886 CET53561438.8.8.8192.168.2.13
                              Jan 2, 2025 05:24:38.928993940 CET53479028.8.8.8192.168.2.13
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Jan 2, 2025 05:24:38.922354937 CET192.168.2.138.8.8.80x72c6Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                              Jan 2, 2025 05:24:38.922434092 CET192.168.2.138.8.8.80xd69cStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Jan 2, 2025 05:24:38.928953886 CET8.8.8.8192.168.2.130x72c6No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                              Jan 2, 2025 05:24:38.928953886 CET8.8.8.8192.168.2.130x72c6No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                              System Behavior

                              Start time (UTC):04:21:52
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.arm7.elf
                              Arguments:/tmp/wind.arm7.elf
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):04:21:52
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.arm7.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):04:21:52
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.arm7.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):04:21:52
                              Start date (UTC):02/01/2025
                              Path:/tmp/wind.arm7.elf
                              Arguments:-
                              File size:4956856 bytes
                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:22:03
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:-
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:22:03
                              Start date (UTC):02/01/2025
                              Path:/usr/sbin/xfpm-power-backlight-helper
                              Arguments:/usr/sbin/xfpm-power-backlight-helper --get-max-brightness
                              File size:14656 bytes
                              MD5 hash:3d221ad23f28ca3259f599b1664e2427

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):04:21:58
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):04:22:03
                              Start date (UTC):02/01/2025
                              Path:/usr/bin/dbus-daemon
                              Arguments:-
                              File size:249032 bytes
                              MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                              Start time (UTC):04:22:03
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                              File size:112880 bytes
                              MD5 hash:4c7a0d6d258bb970905b19b84abcd8e9

                              Start time (UTC):04:22:06
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/systemd/systemd
                              Arguments:-
                              File size:1620224 bytes
                              MD5 hash:9b2bec7092a40488108543f9334aab75

                              Start time (UTC):04:22:06
                              Start date (UTC):02/01/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd
                              File size:112872 bytes
                              MD5 hash:eee956f1b227c1d5031f9c61223255d1