Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.9.225.175 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: 5518.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5518.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5520.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5520.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5514.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5514.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5514, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5514, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5518, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5518, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5520, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5520, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3192, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3249, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3250, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3251, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3252, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3253, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3255, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3272, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3274, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3298, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5520, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5525, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5526, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5527, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5528, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5529, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5530, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5548, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5557, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3192, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3249, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3250, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3251, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3252, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3253, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3255, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3272, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3274, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 3298, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5520, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5525, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5526, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5527, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5528, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5529, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5530, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5548, result: successful | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | SIGKILL sent: pid: 5557, result: successful | Jump to behavior |
Source: 5518.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5518.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5520.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5520.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5514.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5514.1.00007f2f78400000.00007f2f78411000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5514, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5514, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5518, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5518, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5520, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.mpsl.elf PID: 5520, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5525) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5526) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5527) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5528) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/local/share/fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /home/saturnino/.local/share/fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /home/saturnino/.fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/X11/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/cMap/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/cmap/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/opentype/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/type1/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/X11/Type1/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/X11/encodings/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/X11/misc/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/X11/util/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/cmap/adobe-cns1/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/cmap/adobe-gb1/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/cmap/adobe-japan1/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/cmap/adobe-japan2/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/cmap/adobe-korea1/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/opentype/malayalam/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/opentype/mathjax/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/opentype/noto/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/opentype/urw-base35/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/Gargi/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/Gubbi/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/Nakula/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/Navilu/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/Sahadeva/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/Sarai/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/abyssinica/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/ancient-scripts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/dejavu/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/droid/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/freefont/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/kacst/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /usr/share/fonts/truetype/kacst-one/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /home/saturnino/.cache | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /home/saturnino/.local | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5529) | Directory: /home/saturnino/.config | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5530) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5548) | Directory: /home/saturnino/.cache | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5548) | Directory: /home/saturnino/.local | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5548) | Directory: /home/saturnino/.config | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5548) | Directory: /home/saturnino/.config | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5557) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5557) | Directory: /home/saturnino/.cache | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5557) | Directory: /home/saturnino/.local | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/notifyd/xfce4-notifyd (PID: 5557) | Directory: /home/saturnino/.config | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1185/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3241/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3483/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3235/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3234/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/911/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/515/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/914/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3255/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3253/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3252/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3251/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3250/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3249/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3368/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3246/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3488/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/766/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/800/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/888/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/802/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1509/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/803/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/804/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/5548/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3800/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3801/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1867/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3407/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3802/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1484/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/490/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1514/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1634/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1479/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1875/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/654/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3379/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/655/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/656/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/777/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/931/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1595/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/657/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/812/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/779/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/658/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/933/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/5557/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/418/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/419/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3419/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/5454/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3310/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3275/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3274/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3273/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3394/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3272/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/782/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3707/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3303/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1762/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3027/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1486/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/789/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1806/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1660/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3440/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/793/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/794/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3316/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/674/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/796/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/675/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/676/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1498/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1497/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1496/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3157/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3278/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3399/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3799/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1659/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3332/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3210/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3298/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3055/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3052/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/680/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/681/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/3292/cmdline | Jump to behavior |
Source: /tmp/boatnet.mpsl.elf (PID: 5516) | File opened: /proc/1701/cmdline | Jump to behavior |
Source: boatnet.mpsl.elf, 5514.1.000055f0deb19000.000055f0deba0000.rw-.sdmp, boatnet.mpsl.elf, 5518.1.000055f0deb19000.000055f0deba0000.rw-.sdmp, boatnet.mpsl.elf, 5520.1.000055f0deb19000.000055f0deba0000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: boatnet.mpsl.elf, 5514.1.00007ffd16e00000.00007ffd16e21000.rw-.sdmp, boatnet.mpsl.elf, 5518.1.00007ffd16e00000.00007ffd16e21000.rw-.sdmp, boatnet.mpsl.elf, 5520.1.00007ffd16e00000.00007ffd16e21000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/boatnet.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.mpsl.elf |
Source: boatnet.mpsl.elf, 5514.1.000055f0deb19000.000055f0deba0000.rw-.sdmp, boatnet.mpsl.elf, 5518.1.000055f0deb19000.000055f0deba0000.rw-.sdmp, boatnet.mpsl.elf, 5520.1.000055f0deb19000.000055f0deba0000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/mipsel |
Source: boatnet.mpsl.elf, 5514.1.00007ffd16e00000.00007ffd16e21000.rw-.sdmp, boatnet.mpsl.elf, 5518.1.00007ffd16e00000.00007ffd16e21000.rw-.sdmp, boatnet.mpsl.elf, 5520.1.00007ffd16e00000.00007ffd16e21000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-mipsel |