Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Kloki.arm5.elf

Overview

General Information

Sample name:Kloki.arm5.elf
Analysis ID:1586167
MD5:2634588bda3cf98c398c9c661671bcf2
SHA1:14fb2d51d539fc31e464702f4f384e4599ffe6e2
SHA256:8d6e4a2a63413d902527fcf5e8fe5224af17fa0b73621936fb21c8e8fc5f47df
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586167
Start date and time:2025-01-08 19:42:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.arm5.elf
Detection:MAL
Classification:mal52.spre.linELF@0/0@1/0
  • VT rate limit hit for: Kloki.arm5.elf
Command:/tmp/Kloki.arm5.elf
PID:5526
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5535, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • sh (PID: 5556, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5556, Parent: 1498, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5558, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5558, Parent: 1498, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • sh (PID: 5559, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5559, Parent: 1498, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • gdm3 New Fork (PID: 5560, Parent: 1333)
  • Default (PID: 5560, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5562, Parent: 1333)
  • Default (PID: 5562, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5567, Parent: 1)
  • systemd-user-runtime-dir (PID: 5567, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-08T19:43:02.009390+010025000362Misc Attack83.222.191.9013566192.168.2.1558100TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.arm5.elfReversingLabs: Detection: 21%
Source: global trafficTCP traffic: 192.168.2.15:52426 -> 83.222.244.111:13566
Source: global trafficTCP traffic: 192.168.2.15:51852 -> 83.222.9.114:13566
Source: global trafficTCP traffic: 192.168.2.15:34242 -> 83.222.235.187:13566
Source: global trafficTCP traffic: 192.168.2.15:57962 -> 83.222.226.251:13566
Source: global trafficTCP traffic: 192.168.2.15:58502 -> 83.222.106.221:13566
Source: global trafficTCP traffic: 192.168.2.15:38242 -> 83.222.129.70:13566
Source: global trafficTCP traffic: 192.168.2.15:41996 -> 83.222.139.195:13566
Source: global trafficTCP traffic: 192.168.2.15:50316 -> 83.222.117.43:13566
Source: global trafficTCP traffic: 192.168.2.15:44830 -> 83.222.7.117:13566
Source: global trafficTCP traffic: 192.168.2.15:52914 -> 83.222.116.82:13566
Source: global trafficTCP traffic: 192.168.2.15:38186 -> 83.222.186.138:13566
Source: global trafficTCP traffic: 192.168.2.15:56964 -> 83.222.208.28:13566
Source: global trafficTCP traffic: 192.168.2.15:38068 -> 83.222.13.174:13566
Source: global trafficTCP traffic: 192.168.2.15:50130 -> 83.222.21.183:13566
Source: global trafficTCP traffic: 192.168.2.15:54156 -> 83.222.199.14:13566
Source: global trafficTCP traffic: 192.168.2.15:60678 -> 83.222.146.188:13566
Source: global trafficTCP traffic: 192.168.2.15:56328 -> 83.222.125.156:13566
Source: global trafficTCP traffic: 192.168.2.15:35718 -> 83.222.46.104:13566
Source: global trafficTCP traffic: 192.168.2.15:38752 -> 83.222.87.17:13566
Source: global trafficTCP traffic: 192.168.2.15:54108 -> 83.222.99.194:13566
Source: global trafficTCP traffic: 192.168.2.15:50952 -> 83.222.238.228:13566
Source: global trafficTCP traffic: 192.168.2.15:57394 -> 83.222.8.121:13566
Source: global trafficTCP traffic: 192.168.2.15:43414 -> 83.222.167.126:13566
Source: global trafficTCP traffic: 192.168.2.15:34322 -> 83.222.164.174:13566
Source: global trafficTCP traffic: 192.168.2.15:51058 -> 83.222.243.24:13566
Source: global trafficTCP traffic: 192.168.2.15:32900 -> 83.222.0.173:13566
Source: global trafficTCP traffic: 192.168.2.15:38988 -> 83.222.162.209:13566
Source: global trafficTCP traffic: 192.168.2.15:59072 -> 83.222.201.175:13566
Source: global trafficTCP traffic: 192.168.2.15:41950 -> 83.222.127.223:13566
Source: global trafficTCP traffic: 192.168.2.15:53536 -> 83.222.102.71:13566
Source: global trafficTCP traffic: 192.168.2.15:45500 -> 83.222.237.249:13566
Source: global trafficTCP traffic: 192.168.2.15:57890 -> 83.222.3.106:13566
Source: global trafficTCP traffic: 192.168.2.15:37698 -> 83.222.149.49:13566
Source: global trafficTCP traffic: 192.168.2.15:44012 -> 83.222.210.236:13566
Source: global trafficTCP traffic: 192.168.2.15:55394 -> 83.222.66.53:13566
Source: global trafficTCP traffic: 192.168.2.15:51614 -> 83.222.174.48:13566
Source: global trafficTCP traffic: 192.168.2.15:59278 -> 83.222.25.183:13566
Source: global trafficTCP traffic: 192.168.2.15:40664 -> 83.222.169.192:13566
Source: global trafficTCP traffic: 192.168.2.15:59784 -> 83.222.53.78:13566
Source: global trafficTCP traffic: 192.168.2.15:55568 -> 83.222.111.40:13566
Source: global trafficTCP traffic: 192.168.2.15:58154 -> 83.222.102.111:13566
Source: global trafficTCP traffic: 192.168.2.15:48984 -> 83.222.213.9:13566
Source: global trafficTCP traffic: 192.168.2.15:58168 -> 83.222.64.159:13566
Source: global trafficTCP traffic: 192.168.2.15:36610 -> 83.222.184.192:13566
Source: global trafficTCP traffic: 192.168.2.15:45966 -> 83.222.126.31:13566
Source: global trafficTCP traffic: 192.168.2.15:53278 -> 83.222.7.107:13566
Source: global trafficTCP traffic: 192.168.2.15:37836 -> 83.222.24.10:13566
Source: global trafficTCP traffic: 192.168.2.15:41794 -> 83.222.213.173:13566
Source: global trafficTCP traffic: 192.168.2.15:33026 -> 83.222.59.167:13566
Source: global trafficTCP traffic: 192.168.2.15:54054 -> 83.222.153.126:13566
Source: global trafficTCP traffic: 192.168.2.15:47642 -> 83.222.220.72:13566
Source: global trafficTCP traffic: 192.168.2.15:34894 -> 83.222.174.245:13566
Source: global trafficTCP traffic: 192.168.2.15:58584 -> 83.222.255.88:13566
Source: global trafficTCP traffic: 192.168.2.15:58602 -> 83.222.181.52:13566
Source: global trafficTCP traffic: 192.168.2.15:50216 -> 83.222.166.36:13566
Source: global trafficTCP traffic: 192.168.2.15:51764 -> 83.222.92.12:13566
Source: global trafficTCP traffic: 192.168.2.15:36448 -> 83.222.148.49:13566
Source: global trafficTCP traffic: 192.168.2.15:36548 -> 83.222.21.212:13566
Source: global trafficTCP traffic: 192.168.2.15:55458 -> 83.222.208.206:13566
Source: global trafficTCP traffic: 192.168.2.15:45726 -> 83.222.148.78:13566
Source: global trafficTCP traffic: 192.168.2.15:48902 -> 83.222.237.155:13566
Source: global trafficTCP traffic: 192.168.2.15:38066 -> 83.222.185.5:13566
Source: global trafficTCP traffic: 192.168.2.15:46876 -> 83.222.165.142:13566
Source: global trafficTCP traffic: 192.168.2.15:56512 -> 83.222.178.225:13566
Source: global trafficTCP traffic: 192.168.2.15:39694 -> 83.222.53.75:13566
Source: global trafficTCP traffic: 192.168.2.15:56152 -> 83.222.95.17:13566
Source: global trafficTCP traffic: 192.168.2.15:43002 -> 83.222.147.13:13566
Source: global trafficTCP traffic: 192.168.2.15:39794 -> 83.222.6.146:13566
Source: global trafficTCP traffic: 192.168.2.15:35188 -> 83.222.101.188:13566
Source: global trafficTCP traffic: 192.168.2.15:36230 -> 83.222.198.11:13566
Source: global trafficTCP traffic: 192.168.2.15:52060 -> 83.222.224.34:13566
Source: global trafficTCP traffic: 192.168.2.15:46592 -> 83.222.24.116:13566
Source: global trafficTCP traffic: 192.168.2.15:36250 -> 83.222.84.45:13566
Source: global trafficTCP traffic: 192.168.2.15:38184 -> 83.222.73.36:13566
Source: global trafficTCP traffic: 192.168.2.15:47970 -> 83.222.251.221:13566
Source: global trafficTCP traffic: 192.168.2.15:37722 -> 83.222.115.232:13566
Source: global trafficTCP traffic: 192.168.2.15:38168 -> 83.222.121.44:13566
Source: global trafficTCP traffic: 192.168.2.15:38508 -> 83.222.237.30:13566
Source: global trafficTCP traffic: 192.168.2.15:55878 -> 83.222.187.159:13566
Source: global trafficTCP traffic: 192.168.2.15:51806 -> 83.222.255.240:13566
Source: global trafficTCP traffic: 192.168.2.15:37404 -> 83.222.235.94:13566
Source: global trafficTCP traffic: 192.168.2.15:35966 -> 83.222.2.126:13566
Source: global trafficTCP traffic: 192.168.2.15:49416 -> 83.222.108.8:13566
Source: global trafficTCP traffic: 192.168.2.15:42280 -> 83.222.17.209:13566
Source: global trafficTCP traffic: 192.168.2.15:58184 -> 83.222.196.215:13566
Source: global trafficTCP traffic: 192.168.2.15:44000 -> 83.222.221.165:13566
Source: global trafficTCP traffic: 192.168.2.15:35820 -> 83.222.250.245:13566
Source: global trafficTCP traffic: 192.168.2.15:35690 -> 83.222.25.78:13566
Source: global trafficTCP traffic: 192.168.2.15:35228 -> 83.222.34.98:13566
Source: global trafficTCP traffic: 192.168.2.15:53144 -> 83.222.114.30:13566
Source: global trafficTCP traffic: 192.168.2.15:57798 -> 83.222.64.229:13566
Source: global trafficTCP traffic: 192.168.2.15:41754 -> 83.222.6.185:13566
Source: global trafficTCP traffic: 192.168.2.15:51350 -> 83.222.18.244:13566
Source: global trafficTCP traffic: 192.168.2.15:60202 -> 83.222.215.205:13566
Source: global trafficTCP traffic: 192.168.2.15:55686 -> 83.222.147.215:13566
Source: global trafficTCP traffic: 192.168.2.15:46704 -> 83.222.189.126:13566
Source: global trafficTCP traffic: 192.168.2.15:54982 -> 83.222.53.191:13566
Source: global trafficTCP traffic: 192.168.2.15:58100 -> 83.222.191.90:13566
Source: /tmp/Kloki.arm5.elf (PID: 5526)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500036 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 19 : 83.222.191.90:13566 -> 192.168.2.15:58100
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.111
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.111
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.111
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.111
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.9.114
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.235.187
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.226.251
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.9.114
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.106.221
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.235.187
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.129.70
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.226.251
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.139.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.106.221
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.117.43
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.129.70
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.7.117
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.139.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.116.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.117.43
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.7.117
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.186.138
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.116.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.208.28
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.186.138
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.13.174
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.21.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.208.28
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.199.14
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.13.174
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.146.188
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.125.156
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.21.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.46.104
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.87.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.199.14
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.146.188
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.99.194
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.125.156
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.228
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.46.104
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.87.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.8.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.99.194
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.167.126
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.228
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.164.174
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.243.24
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.8.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.167.126
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru

System Summary

barindex
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 931, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 933, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1553, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1659, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1669, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1679, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 3157, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 3332, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 3483, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5503, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5535, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5556, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5558, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5559, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5560, result: successfulJump to behavior
Source: LOAD without section mappingsProgram segment: 0x8000
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 931, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 933, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1553, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1659, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1669, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 1679, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 3157, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 3332, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 3483, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5503, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5535, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5556, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5558, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5559, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5532)SIGKILL sent: pid: 5560, result: successfulJump to behavior
Source: classification engineClassification label: mal52.spre.linELF@0/0@1/0
Source: Kloki.arm5.elfSubmission file: segment LOAD with 7.8876 entropy (max. 8.0)
Source: Kloki.arm5.elfSubmission file: segment LOAD with 7.9553 entropy (max. 8.0)
Source: /tmp/Kloki.arm5.elf (PID: 5526)Queries kernel information via 'uname': Jump to behavior
Source: Kloki.arm5.elf, 5526.1.00007ffded36a000.00007ffded38b000.rw-.sdmp, Kloki.arm5.elf, 5531.1.00007ffded36a000.00007ffded38b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/Kloki.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Kloki.arm5.elf
Source: Kloki.arm5.elf, 5526.1.00005638709c5000.0000563870b35000.rw-.sdmp, Kloki.arm5.elf, 5531.1.00005638709c5000.0000563870b35000.rw-.sdmpBinary or memory string: p8V!/etc/qemu-binfmt/arm
Source: Kloki.arm5.elf, 5526.1.00005638709c5000.0000563870b35000.rw-.sdmp, Kloki.arm5.elf, 5531.1.00005638709c5000.0000563870b35000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: Kloki.arm5.elf, 5526.1.00007ffded36a000.00007ffded38b000.rw-.sdmp, Kloki.arm5.elf, 5531.1.00007ffded36a000.00007ffded38b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1586167 Sample: Kloki.arm5.elf Startdate: 08/01/2025 Architecture: LINUX Score: 52 23 83.222.162.209, 13566, 38988 WAVENETLB Bulgaria 2->23 25 83.222.164.174, 13566, 34322 WAVENETLB Bulgaria 2->25 27 96 other IPs or domains 2->27 31 Multi AV Scanner detection for submitted file 2->31 8 Kloki.arm5.elf 2->8         started        10 gnome-session-binary sh gnome-shell 2->10         started        12 gnome-session-binary sh gsd-print-notifications 2->12         started        14 5 other processes 2->14 signatures3 process4 process5 16 Kloki.arm5.elf 8->16         started        process6 18 Kloki.arm5.elf 16->18         started        21 Kloki.arm5.elf 16->21         started        signatures7 29 Sample tries to kill multiple processes (SIGKILL) 18->29
SourceDetectionScannerLabelLink
Kloki.arm5.elf21%ReversingLabsLinux.Trojan.Svirtu
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.174.48
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.198.11
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.2.126
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.208.28
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.73.36
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.9.114
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.243.24
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.102.111
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.7.107
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.178.225
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.84.45
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.153.126
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.250.245
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.66.53
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.148.49
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.46.104
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.164.174
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.127.223
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.129.70
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.213.9
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.139.195
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.237.155
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.187.159
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.7.117
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.99.194
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.167.126
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.185.5
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.92.12
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.196.215
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.21.183
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.111.40
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.64.229
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.24.10
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.115.232
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.165.142
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.114.30
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.226.251
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.199.14
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.106.221
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.108.8
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.59.167
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.53.78
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.251.221
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.186.138
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.25.78
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.6.185
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.208.206
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.148.78
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.53.191
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.149.49
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.102.71
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.237.249
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.181.52
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.53.75
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.25.183
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.117.43
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.174.245
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.213.173
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.95.17
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.101.188
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.210.236
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.147.215
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.125.156
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.201.175
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.17.209
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.126.31
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.169.192
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.224.34
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.220.72
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.221.165
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.238.228
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.146.188
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.116.82
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.21.212
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.24.116
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.18.244
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.215.205
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.235.187
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.0.173
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.34.98
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.8.121
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.3.106
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.87.17
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.244.111
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.255.88
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.147.13
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.121.44
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.162.209
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.13.174
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.255.240
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.235.94
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.166.36
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.237.30
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.184.192
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.189.126
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.6.146
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.64.159
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    SYNTERRA-ASRUjklspc.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.147
    arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 213.243.99.148
    ppc.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.127
    rebirth.arm7.elfGet hashmaliciousMirai, OkiruBrowse
    • 83.229.145.146
    la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
    • 213.243.115.54
    5tSAlF2WkT.elfGet hashmaliciousMiraiBrowse
    • 83.229.251.180
    la.bot.sparc.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.139
    arm4.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.179
    SecuriteInfo.com.Linux.Siggen.9999.22286.12230.elfGet hashmaliciousMiraiBrowse
    • 83.229.251.163
    oVOImRIAaz.elfGet hashmaliciousMiraiBrowse
    • 83.229.251.144
    SYNTERRA-ASRUjklspc.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.147
    arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 213.243.99.148
    ppc.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.127
    rebirth.arm7.elfGet hashmaliciousMirai, OkiruBrowse
    • 83.229.145.146
    la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
    • 213.243.115.54
    5tSAlF2WkT.elfGet hashmaliciousMiraiBrowse
    • 83.229.251.180
    la.bot.sparc.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.139
    arm4.elfGet hashmaliciousUnknownBrowse
    • 83.229.251.179
    SecuriteInfo.com.Linux.Siggen.9999.22286.12230.elfGet hashmaliciousMiraiBrowse
    • 83.229.251.163
    oVOImRIAaz.elfGet hashmaliciousMiraiBrowse
    • 83.229.251.144
    MASTERHOST-ASMoscowRussiaRUhttps://klickskydd.skolverket.org/?url=https%3A%2F%2Fwww.gazeta.ru%2Fpolitics%2Fnews%2F2024%2F12%2F22%2F24684722.shtml&id=71de&rcpt=upplysningstjansten@skolverket.se&tss=1735469857&msgid=b53e7603-c5d3-11ef-8a2e-0050569b0508&html=1&h=ded85c63Get hashmaliciousHTMLPhisherBrowse
    • 87.242.127.163
    https://www.gazeta.ru/politics/news/2024/12/22/24684722.shtmlGet hashmaliciousHTMLPhisherBrowse
    • 87.242.127.163
    https://www.gazeta.ru/politics/news/2024/12/22/24684854.shtmlGet hashmaliciousHTMLPhisherBrowse
    • 87.242.127.163
    nabm68k.elfGet hashmaliciousUnknownBrowse
    • 84.252.174.53
    f5TWdT5EAc.exeGet hashmaliciousPhorpiex, RHADAMANTHYS, XmrigBrowse
    • 90.156.163.119
    newtpp.exeGet hashmaliciousXmrigBrowse
    • 90.156.160.43
    LM94OE0VNK.exeGet hashmaliciousUnknownBrowse
    • 90.156.160.6
    santi.exeGet hashmaliciousFormBookBrowse
    • 90.156.201.74
    arm.nn-20241122-0008.elfGet hashmaliciousMirai, OkiruBrowse
    • 217.16.29.179
    arm4.elfGet hashmaliciousMiraiBrowse
    • 84.252.144.212
    GCN-ASGCNAD-SofiaBulgariaBGIMG001.exeGet hashmaliciousXmrigBrowse
    • 212.70.158.89
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
    Entropy (8bit):7.95224077012436
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:Kloki.arm5.elf
    File size:30'628 bytes
    MD5:2634588bda3cf98c398c9c661671bcf2
    SHA1:14fb2d51d539fc31e464702f4f384e4599ffe6e2
    SHA256:8d6e4a2a63413d902527fcf5e8fe5224af17fa0b73621936fb21c8e8fc5f47df
    SHA512:c132359e8da69a1b9be06524307fbced3c5937098c869cbb046a99e69755ade557f25cc9609c0754916342873e3cdb9cbe08a14da510313266eab6e58e193ee4
    SSDEEP:768:/PzhmhytH/ADSdyHCOjTztYpbv4kheYuk04Z9J093UGQ:jMhyBtKzjTztYdAseYuk0m9JMQ
    TLSH:93D2D0B0197B9475D1B03D71C42EC40667DBA3E824B77C0727099EE82BD48492CFADAA
    File Content Preview:.ELF...a..........(.........4...........4. ...(......................................................v...v..........Q.td............................\...sfga....................P..........?.E.h;.}...^..........e...|.0.....4I.2....R....m..0T..[.Y.....*Q^...

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:ARM
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:ARM - ABI
    ABI Version:0
    Entry Point Address:0x2e50c
    Flags:0x2
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:40
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80000x80000x10000x1a78c7.88760x6RW 0x8000
    LOAD0x00x280000x280000x76bb0x76bb7.95530x5R E0x8000
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
    2025-01-08T19:43:02.009390+01002500036ET COMPROMISED Known Compromised or Hostile Host Traffic group 19283.222.191.9013566192.168.2.1558100TCP
    TimestampSource PortDest PortSource IPDest IP
    Jan 8, 2025 19:43:01.710055113 CET5242613566192.168.2.1583.222.244.111
    Jan 8, 2025 19:43:01.714910984 CET135665242683.222.244.111192.168.2.15
    Jan 8, 2025 19:43:01.714962959 CET5242613566192.168.2.1583.222.244.111
    Jan 8, 2025 19:43:01.727437019 CET5242613566192.168.2.1583.222.244.111
    Jan 8, 2025 19:43:01.732284069 CET135665242683.222.244.111192.168.2.15
    Jan 8, 2025 19:43:01.732328892 CET5242613566192.168.2.1583.222.244.111
    Jan 8, 2025 19:43:01.743618965 CET5185213566192.168.2.1583.222.9.114
    Jan 8, 2025 19:43:01.745960951 CET3424213566192.168.2.1583.222.235.187
    Jan 8, 2025 19:43:01.748188019 CET5796213566192.168.2.1583.222.226.251
    Jan 8, 2025 19:43:01.748393059 CET135665185283.222.9.114192.168.2.15
    Jan 8, 2025 19:43:01.748444080 CET5185213566192.168.2.1583.222.9.114
    Jan 8, 2025 19:43:01.750279903 CET5850213566192.168.2.1583.222.106.221
    Jan 8, 2025 19:43:01.750802040 CET135663424283.222.235.187192.168.2.15
    Jan 8, 2025 19:43:01.750845909 CET3424213566192.168.2.1583.222.235.187
    Jan 8, 2025 19:43:01.752471924 CET3824213566192.168.2.1583.222.129.70
    Jan 8, 2025 19:43:01.752942085 CET135665796283.222.226.251192.168.2.15
    Jan 8, 2025 19:43:01.752990007 CET5796213566192.168.2.1583.222.226.251
    Jan 8, 2025 19:43:01.754589081 CET4199613566192.168.2.1583.222.139.195
    Jan 8, 2025 19:43:01.755104065 CET135665850283.222.106.221192.168.2.15
    Jan 8, 2025 19:43:01.755150080 CET5850213566192.168.2.1583.222.106.221
    Jan 8, 2025 19:43:01.756824970 CET5031613566192.168.2.1583.222.117.43
    Jan 8, 2025 19:43:01.757332087 CET135663824283.222.129.70192.168.2.15
    Jan 8, 2025 19:43:01.757370949 CET3824213566192.168.2.1583.222.129.70
    Jan 8, 2025 19:43:01.758898020 CET4483013566192.168.2.1583.222.7.117
    Jan 8, 2025 19:43:01.759362936 CET135664199683.222.139.195192.168.2.15
    Jan 8, 2025 19:43:01.759399891 CET4199613566192.168.2.1583.222.139.195
    Jan 8, 2025 19:43:01.761121988 CET5291413566192.168.2.1583.222.116.82
    Jan 8, 2025 19:43:01.761625051 CET135665031683.222.117.43192.168.2.15
    Jan 8, 2025 19:43:01.761658907 CET5031613566192.168.2.1583.222.117.43
    Jan 8, 2025 19:43:01.763645887 CET135664483083.222.7.117192.168.2.15
    Jan 8, 2025 19:43:01.763684988 CET4483013566192.168.2.1583.222.7.117
    Jan 8, 2025 19:43:01.765033960 CET3818613566192.168.2.1583.222.186.138
    Jan 8, 2025 19:43:01.765847921 CET135665291483.222.116.82192.168.2.15
    Jan 8, 2025 19:43:01.765889883 CET5291413566192.168.2.1583.222.116.82
    Jan 8, 2025 19:43:01.768433094 CET5696413566192.168.2.1583.222.208.28
    Jan 8, 2025 19:43:01.769804955 CET135663818683.222.186.138192.168.2.15
    Jan 8, 2025 19:43:01.769850969 CET3818613566192.168.2.1583.222.186.138
    Jan 8, 2025 19:43:01.770304918 CET3806813566192.168.2.1583.222.13.174
    Jan 8, 2025 19:43:01.772689104 CET5013013566192.168.2.1583.222.21.183
    Jan 8, 2025 19:43:01.773209095 CET135665696483.222.208.28192.168.2.15
    Jan 8, 2025 19:43:01.773252964 CET5696413566192.168.2.1583.222.208.28
    Jan 8, 2025 19:43:01.774525881 CET5415613566192.168.2.1583.222.199.14
    Jan 8, 2025 19:43:01.775018930 CET135663806883.222.13.174192.168.2.15
    Jan 8, 2025 19:43:01.775059938 CET3806813566192.168.2.1583.222.13.174
    Jan 8, 2025 19:43:01.775882006 CET6067813566192.168.2.1583.222.146.188
    Jan 8, 2025 19:43:01.776830912 CET5632813566192.168.2.1583.222.125.156
    Jan 8, 2025 19:43:01.777475119 CET135665013083.222.21.183192.168.2.15
    Jan 8, 2025 19:43:01.777518988 CET5013013566192.168.2.1583.222.21.183
    Jan 8, 2025 19:43:01.778024912 CET3571813566192.168.2.1583.222.46.104
    Jan 8, 2025 19:43:01.779216051 CET3875213566192.168.2.1583.222.87.17
    Jan 8, 2025 19:43:01.779294014 CET135665415683.222.199.14192.168.2.15
    Jan 8, 2025 19:43:01.779330015 CET5415613566192.168.2.1583.222.199.14
    Jan 8, 2025 19:43:01.780709982 CET135666067883.222.146.188192.168.2.15
    Jan 8, 2025 19:43:01.780754089 CET6067813566192.168.2.1583.222.146.188
    Jan 8, 2025 19:43:01.781476021 CET5410813566192.168.2.1583.222.99.194
    Jan 8, 2025 19:43:01.781663895 CET135665632883.222.125.156192.168.2.15
    Jan 8, 2025 19:43:01.781696081 CET5632813566192.168.2.1583.222.125.156
    Jan 8, 2025 19:43:01.782686949 CET5095213566192.168.2.1583.222.238.228
    Jan 8, 2025 19:43:01.782753944 CET135663571883.222.46.104192.168.2.15
    Jan 8, 2025 19:43:01.782788992 CET3571813566192.168.2.1583.222.46.104
    Jan 8, 2025 19:43:01.784020901 CET135663875283.222.87.17192.168.2.15
    Jan 8, 2025 19:43:01.784065962 CET3875213566192.168.2.1583.222.87.17
    Jan 8, 2025 19:43:01.785317898 CET5739413566192.168.2.1583.222.8.121
    Jan 8, 2025 19:43:01.786202908 CET135665410883.222.99.194192.168.2.15
    Jan 8, 2025 19:43:01.786248922 CET5410813566192.168.2.1583.222.99.194
    Jan 8, 2025 19:43:01.786644936 CET4341413566192.168.2.1583.222.167.126
    Jan 8, 2025 19:43:01.787471056 CET135665095283.222.238.228192.168.2.15
    Jan 8, 2025 19:43:01.787517071 CET5095213566192.168.2.1583.222.238.228
    Jan 8, 2025 19:43:01.788091898 CET3432213566192.168.2.1583.222.164.174
    Jan 8, 2025 19:43:01.789094925 CET5105813566192.168.2.1583.222.243.24
    Jan 8, 2025 19:43:01.790113926 CET135665739483.222.8.121192.168.2.15
    Jan 8, 2025 19:43:01.790266037 CET5739413566192.168.2.1583.222.8.121
    Jan 8, 2025 19:43:01.791352987 CET135664341483.222.167.126192.168.2.15
    Jan 8, 2025 19:43:01.791403055 CET4341413566192.168.2.1583.222.167.126
    Jan 8, 2025 19:43:01.792870998 CET135663432283.222.164.174192.168.2.15
    Jan 8, 2025 19:43:01.792917013 CET3432213566192.168.2.1583.222.164.174
    Jan 8, 2025 19:43:01.793858051 CET135665105883.222.243.24192.168.2.15
    Jan 8, 2025 19:43:01.793905020 CET5105813566192.168.2.1583.222.243.24
    Jan 8, 2025 19:43:01.800353050 CET3290013566192.168.2.1583.222.0.173
    Jan 8, 2025 19:43:01.801893950 CET3898813566192.168.2.1583.222.162.209
    Jan 8, 2025 19:43:01.802887917 CET5907213566192.168.2.1583.222.201.175
    Jan 8, 2025 19:43:01.803406000 CET4195013566192.168.2.1583.222.127.223
    Jan 8, 2025 19:43:01.805217028 CET135663290083.222.0.173192.168.2.15
    Jan 8, 2025 19:43:01.805257082 CET3290013566192.168.2.1583.222.0.173
    Jan 8, 2025 19:43:01.805963039 CET5353613566192.168.2.1583.222.102.71
    Jan 8, 2025 19:43:01.806723118 CET135663898883.222.162.209192.168.2.15
    Jan 8, 2025 19:43:01.806768894 CET3898813566192.168.2.1583.222.162.209
    Jan 8, 2025 19:43:01.807638884 CET135665907283.222.201.175192.168.2.15
    Jan 8, 2025 19:43:01.807673931 CET5907213566192.168.2.1583.222.201.175
    Jan 8, 2025 19:43:01.808002949 CET4550013566192.168.2.1583.222.237.249
    Jan 8, 2025 19:43:01.808162928 CET135664195083.222.127.223192.168.2.15
    Jan 8, 2025 19:43:01.808199883 CET4195013566192.168.2.1583.222.127.223
    Jan 8, 2025 19:43:01.809282064 CET5789013566192.168.2.1583.222.3.106
    Jan 8, 2025 19:43:01.810708046 CET135665353683.222.102.71192.168.2.15
    Jan 8, 2025 19:43:01.810753107 CET5353613566192.168.2.1583.222.102.71
    Jan 8, 2025 19:43:01.811739922 CET3769813566192.168.2.1583.222.149.49
    Jan 8, 2025 19:43:01.812724113 CET135664550083.222.237.249192.168.2.15
    Jan 8, 2025 19:43:01.812773943 CET4550013566192.168.2.1583.222.237.249
    Jan 8, 2025 19:43:01.813621998 CET4401213566192.168.2.1583.222.210.236
    Jan 8, 2025 19:43:01.814047098 CET135665789083.222.3.106192.168.2.15
    Jan 8, 2025 19:43:01.814085007 CET5789013566192.168.2.1583.222.3.106
    Jan 8, 2025 19:43:01.816485882 CET135663769883.222.149.49192.168.2.15
    Jan 8, 2025 19:43:01.816534996 CET3769813566192.168.2.1583.222.149.49
    Jan 8, 2025 19:43:01.818417072 CET135664401283.222.210.236192.168.2.15
    Jan 8, 2025 19:43:01.818475008 CET4401213566192.168.2.1583.222.210.236
    Jan 8, 2025 19:43:01.821168900 CET4401213566192.168.2.1583.222.210.236
    Jan 8, 2025 19:43:01.821912050 CET5539413566192.168.2.1583.222.66.53
    Jan 8, 2025 19:43:01.823599100 CET5161413566192.168.2.1583.222.174.48
    Jan 8, 2025 19:43:01.825936079 CET135664401283.222.210.236192.168.2.15
    Jan 8, 2025 19:43:01.825972080 CET4401213566192.168.2.1583.222.210.236
    Jan 8, 2025 19:43:01.826638937 CET135665539483.222.66.53192.168.2.15
    Jan 8, 2025 19:43:01.826695919 CET5539413566192.168.2.1583.222.66.53
    Jan 8, 2025 19:43:01.828361034 CET5927813566192.168.2.1583.222.25.183
    Jan 8, 2025 19:43:01.828372955 CET135665161483.222.174.48192.168.2.15
    Jan 8, 2025 19:43:01.828418016 CET5161413566192.168.2.1583.222.174.48
    Jan 8, 2025 19:43:01.833107948 CET135665927883.222.25.183192.168.2.15
    Jan 8, 2025 19:43:01.833158016 CET5927813566192.168.2.1583.222.25.183
    Jan 8, 2025 19:43:01.835530996 CET4066413566192.168.2.1583.222.169.192
    Jan 8, 2025 19:43:01.837902069 CET5978413566192.168.2.1583.222.53.78
    Jan 8, 2025 19:43:01.840322018 CET135664066483.222.169.192192.168.2.15
    Jan 8, 2025 19:43:01.840358019 CET4066413566192.168.2.1583.222.169.192
    Jan 8, 2025 19:43:01.842694998 CET135665978483.222.53.78192.168.2.15
    Jan 8, 2025 19:43:01.842742920 CET5978413566192.168.2.1583.222.53.78
    Jan 8, 2025 19:43:01.846657991 CET5556813566192.168.2.1583.222.111.40
    Jan 8, 2025 19:43:01.849742889 CET5815413566192.168.2.1583.222.102.111
    Jan 8, 2025 19:43:01.851370096 CET135665556883.222.111.40192.168.2.15
    Jan 8, 2025 19:43:01.851424932 CET5556813566192.168.2.1583.222.111.40
    Jan 8, 2025 19:43:01.852103949 CET4898413566192.168.2.1583.222.213.9
    Jan 8, 2025 19:43:01.854335070 CET5816813566192.168.2.1583.222.64.159
    Jan 8, 2025 19:43:01.854547024 CET135665815483.222.102.111192.168.2.15
    Jan 8, 2025 19:43:01.854589939 CET5815413566192.168.2.1583.222.102.111
    Jan 8, 2025 19:43:01.855573893 CET3661013566192.168.2.1583.222.184.192
    Jan 8, 2025 19:43:01.856339931 CET4596613566192.168.2.1583.222.126.31
    Jan 8, 2025 19:43:01.856947899 CET135664898483.222.213.9192.168.2.15
    Jan 8, 2025 19:43:01.856990099 CET4898413566192.168.2.1583.222.213.9
    Jan 8, 2025 19:43:01.857829094 CET5327813566192.168.2.1583.222.7.107
    Jan 8, 2025 19:43:01.859116077 CET135665816883.222.64.159192.168.2.15
    Jan 8, 2025 19:43:01.859158039 CET5816813566192.168.2.1583.222.64.159
    Jan 8, 2025 19:43:01.859488964 CET3783613566192.168.2.1583.222.24.10
    Jan 8, 2025 19:43:01.860343933 CET135663661083.222.184.192192.168.2.15
    Jan 8, 2025 19:43:01.860382080 CET3661013566192.168.2.1583.222.184.192
    Jan 8, 2025 19:43:01.861027002 CET4179413566192.168.2.1583.222.213.173
    Jan 8, 2025 19:43:01.861120939 CET135664596683.222.126.31192.168.2.15
    Jan 8, 2025 19:43:01.861160994 CET4596613566192.168.2.1583.222.126.31
    Jan 8, 2025 19:43:01.862585068 CET135665327883.222.7.107192.168.2.15
    Jan 8, 2025 19:43:01.862606049 CET3302613566192.168.2.1583.222.59.167
    Jan 8, 2025 19:43:01.862627029 CET5327813566192.168.2.1583.222.7.107
    Jan 8, 2025 19:43:01.864172935 CET5405413566192.168.2.1583.222.153.126
    Jan 8, 2025 19:43:01.864270926 CET135663783683.222.24.10192.168.2.15
    Jan 8, 2025 19:43:01.864308119 CET3783613566192.168.2.1583.222.24.10
    Jan 8, 2025 19:43:01.865716934 CET4764213566192.168.2.1583.222.220.72
    Jan 8, 2025 19:43:01.865777969 CET135664179483.222.213.173192.168.2.15
    Jan 8, 2025 19:43:01.865817070 CET4179413566192.168.2.1583.222.213.173
    Jan 8, 2025 19:43:01.866997004 CET3489413566192.168.2.1583.222.174.245
    Jan 8, 2025 19:43:01.867403030 CET135663302683.222.59.167192.168.2.15
    Jan 8, 2025 19:43:01.867444992 CET3302613566192.168.2.1583.222.59.167
    Jan 8, 2025 19:43:01.868485928 CET5858413566192.168.2.1583.222.255.88
    Jan 8, 2025 19:43:01.868977070 CET135665405483.222.153.126192.168.2.15
    Jan 8, 2025 19:43:01.869018078 CET5405413566192.168.2.1583.222.153.126
    Jan 8, 2025 19:43:01.869889021 CET5860213566192.168.2.1583.222.181.52
    Jan 8, 2025 19:43:01.870516062 CET135664764283.222.220.72192.168.2.15
    Jan 8, 2025 19:43:01.870558977 CET4764213566192.168.2.1583.222.220.72
    Jan 8, 2025 19:43:01.871733904 CET135663489483.222.174.245192.168.2.15
    Jan 8, 2025 19:43:01.871776104 CET3489413566192.168.2.1583.222.174.245
    Jan 8, 2025 19:43:01.872823954 CET5021613566192.168.2.1583.222.166.36
    Jan 8, 2025 19:43:01.873280048 CET135665858483.222.255.88192.168.2.15
    Jan 8, 2025 19:43:01.873317957 CET5858413566192.168.2.1583.222.255.88
    Jan 8, 2025 19:43:01.874624014 CET135665860283.222.181.52192.168.2.15
    Jan 8, 2025 19:43:01.874660969 CET5860213566192.168.2.1583.222.181.52
    Jan 8, 2025 19:43:01.875195980 CET5176413566192.168.2.1583.222.92.12
    Jan 8, 2025 19:43:01.877321959 CET3644813566192.168.2.1583.222.148.49
    Jan 8, 2025 19:43:01.877615929 CET135665021683.222.166.36192.168.2.15
    Jan 8, 2025 19:43:01.877654076 CET5021613566192.168.2.1583.222.166.36
    Jan 8, 2025 19:43:01.879048109 CET3654813566192.168.2.1583.222.21.212
    Jan 8, 2025 19:43:01.879993916 CET135665176483.222.92.12192.168.2.15
    Jan 8, 2025 19:43:01.880034924 CET5176413566192.168.2.1583.222.92.12
    Jan 8, 2025 19:43:01.881184101 CET5545813566192.168.2.1583.222.208.206
    Jan 8, 2025 19:43:01.882077932 CET135663644883.222.148.49192.168.2.15
    Jan 8, 2025 19:43:01.882113934 CET3644813566192.168.2.1583.222.148.49
    Jan 8, 2025 19:43:01.882982016 CET4572613566192.168.2.1583.222.148.78
    Jan 8, 2025 19:43:01.883804083 CET135663654883.222.21.212192.168.2.15
    Jan 8, 2025 19:43:01.883841038 CET3654813566192.168.2.1583.222.21.212
    Jan 8, 2025 19:43:01.885121107 CET4890213566192.168.2.1583.222.237.155
    Jan 8, 2025 19:43:01.886002064 CET135665545883.222.208.206192.168.2.15
    Jan 8, 2025 19:43:01.886034012 CET5545813566192.168.2.1583.222.208.206
    Jan 8, 2025 19:43:01.886893988 CET3806613566192.168.2.1583.222.185.5
    Jan 8, 2025 19:43:01.887753963 CET135664572683.222.148.78192.168.2.15
    Jan 8, 2025 19:43:01.887799025 CET4572613566192.168.2.1583.222.148.78
    Jan 8, 2025 19:43:01.889086008 CET4687613566192.168.2.1583.222.165.142
    Jan 8, 2025 19:43:01.889928102 CET135664890283.222.237.155192.168.2.15
    Jan 8, 2025 19:43:01.889957905 CET4890213566192.168.2.1583.222.237.155
    Jan 8, 2025 19:43:01.890830994 CET5651213566192.168.2.1583.222.178.225
    Jan 8, 2025 19:43:01.891673088 CET135663806683.222.185.5192.168.2.15
    Jan 8, 2025 19:43:01.891712904 CET3806613566192.168.2.1583.222.185.5
    Jan 8, 2025 19:43:01.893030882 CET3969413566192.168.2.1583.222.53.75
    Jan 8, 2025 19:43:01.893862009 CET135664687683.222.165.142192.168.2.15
    Jan 8, 2025 19:43:01.893896103 CET4687613566192.168.2.1583.222.165.142
    Jan 8, 2025 19:43:01.895555019 CET135665651283.222.178.225192.168.2.15
    Jan 8, 2025 19:43:01.895593882 CET5651213566192.168.2.1583.222.178.225
    Jan 8, 2025 19:43:01.895632982 CET5615213566192.168.2.1583.222.95.17
    Jan 8, 2025 19:43:01.897809982 CET135663969483.222.53.75192.168.2.15
    Jan 8, 2025 19:43:01.897849083 CET3969413566192.168.2.1583.222.53.75
    Jan 8, 2025 19:43:01.897861958 CET4300213566192.168.2.1583.222.147.13
    Jan 8, 2025 19:43:01.899540901 CET3979413566192.168.2.1583.222.6.146
    Jan 8, 2025 19:43:01.900336027 CET135665615283.222.95.17192.168.2.15
    Jan 8, 2025 19:43:01.900372028 CET5615213566192.168.2.1583.222.95.17
    Jan 8, 2025 19:43:01.901525974 CET3518813566192.168.2.1583.222.101.188
    Jan 8, 2025 19:43:01.902637005 CET135664300283.222.147.13192.168.2.15
    Jan 8, 2025 19:43:01.902676105 CET4300213566192.168.2.1583.222.147.13
    Jan 8, 2025 19:43:01.904287100 CET135663979483.222.6.146192.168.2.15
    Jan 8, 2025 19:43:01.904325008 CET3979413566192.168.2.1583.222.6.146
    Jan 8, 2025 19:43:01.904681921 CET3623013566192.168.2.1583.222.198.11
    Jan 8, 2025 19:43:01.906292915 CET135663518883.222.101.188192.168.2.15
    Jan 8, 2025 19:43:01.906409979 CET3518813566192.168.2.1583.222.101.188
    Jan 8, 2025 19:43:01.908032894 CET5206013566192.168.2.1583.222.224.34
    Jan 8, 2025 19:43:01.909432888 CET135663623083.222.198.11192.168.2.15
    Jan 8, 2025 19:43:01.909477949 CET3623013566192.168.2.1583.222.198.11
    Jan 8, 2025 19:43:01.910288095 CET4659213566192.168.2.1583.222.24.116
    Jan 8, 2025 19:43:01.912801027 CET135665206083.222.224.34192.168.2.15
    Jan 8, 2025 19:43:01.912846088 CET5206013566192.168.2.1583.222.224.34
    Jan 8, 2025 19:43:01.913505077 CET3625013566192.168.2.1583.222.84.45
    Jan 8, 2025 19:43:01.915091991 CET135664659283.222.24.116192.168.2.15
    Jan 8, 2025 19:43:01.915128946 CET4659213566192.168.2.1583.222.24.116
    Jan 8, 2025 19:43:01.916063070 CET3818413566192.168.2.1583.222.73.36
    Jan 8, 2025 19:43:01.918303013 CET135663625083.222.84.45192.168.2.15
    Jan 8, 2025 19:43:01.918340921 CET3625013566192.168.2.1583.222.84.45
    Jan 8, 2025 19:43:01.919320107 CET4797013566192.168.2.1583.222.251.221
    Jan 8, 2025 19:43:01.920823097 CET135663818483.222.73.36192.168.2.15
    Jan 8, 2025 19:43:01.920865059 CET3818413566192.168.2.1583.222.73.36
    Jan 8, 2025 19:43:01.921808004 CET3772213566192.168.2.1583.222.115.232
    Jan 8, 2025 19:43:01.924088955 CET135664797083.222.251.221192.168.2.15
    Jan 8, 2025 19:43:01.924127102 CET4797013566192.168.2.1583.222.251.221
    Jan 8, 2025 19:43:01.925331116 CET3816813566192.168.2.1583.222.121.44
    Jan 8, 2025 19:43:01.926534891 CET135663772283.222.115.232192.168.2.15
    Jan 8, 2025 19:43:01.926579952 CET3772213566192.168.2.1583.222.115.232
    Jan 8, 2025 19:43:01.928354979 CET3850813566192.168.2.1583.222.237.30
    Jan 8, 2025 19:43:01.930088043 CET135663816883.222.121.44192.168.2.15
    Jan 8, 2025 19:43:01.930124044 CET3816813566192.168.2.1583.222.121.44
    Jan 8, 2025 19:43:01.932498932 CET5587813566192.168.2.1583.222.187.159
    Jan 8, 2025 19:43:01.933181047 CET135663850883.222.237.30192.168.2.15
    Jan 8, 2025 19:43:01.933223009 CET3850813566192.168.2.1583.222.237.30
    Jan 8, 2025 19:43:01.934874058 CET5180613566192.168.2.1583.222.255.240
    Jan 8, 2025 19:43:01.937285900 CET135665587883.222.187.159192.168.2.15
    Jan 8, 2025 19:43:01.937335968 CET5587813566192.168.2.1583.222.187.159
    Jan 8, 2025 19:43:01.937778950 CET3740413566192.168.2.1583.222.235.94
    Jan 8, 2025 19:43:01.939613104 CET135665180683.222.255.240192.168.2.15
    Jan 8, 2025 19:43:01.939649105 CET5180613566192.168.2.1583.222.255.240
    Jan 8, 2025 19:43:01.940193892 CET3596613566192.168.2.1583.222.2.126
    Jan 8, 2025 19:43:01.942579985 CET135663740483.222.235.94192.168.2.15
    Jan 8, 2025 19:43:01.942617893 CET3740413566192.168.2.1583.222.235.94
    Jan 8, 2025 19:43:01.943130970 CET4941613566192.168.2.1583.222.108.8
    Jan 8, 2025 19:43:01.944927931 CET135663596683.222.2.126192.168.2.15
    Jan 8, 2025 19:43:01.944966078 CET3596613566192.168.2.1583.222.2.126
    Jan 8, 2025 19:43:01.945213079 CET4228013566192.168.2.1583.222.17.209
    Jan 8, 2025 19:43:01.947933912 CET5818413566192.168.2.1583.222.196.215
    Jan 8, 2025 19:43:01.947953939 CET135664941683.222.108.8192.168.2.15
    Jan 8, 2025 19:43:01.947993040 CET4941613566192.168.2.1583.222.108.8
    Jan 8, 2025 19:43:01.949979067 CET4400013566192.168.2.1583.222.221.165
    Jan 8, 2025 19:43:01.949981928 CET135664228083.222.17.209192.168.2.15
    Jan 8, 2025 19:43:01.950022936 CET4228013566192.168.2.1583.222.17.209
    Jan 8, 2025 19:43:01.952512026 CET3582013566192.168.2.1583.222.250.245
    Jan 8, 2025 19:43:01.952735901 CET135665818483.222.196.215192.168.2.15
    Jan 8, 2025 19:43:01.952776909 CET5818413566192.168.2.1583.222.196.215
    Jan 8, 2025 19:43:01.954560995 CET3569013566192.168.2.1583.222.25.78
    Jan 8, 2025 19:43:01.954741001 CET135664400083.222.221.165192.168.2.15
    Jan 8, 2025 19:43:01.954785109 CET4400013566192.168.2.1583.222.221.165
    Jan 8, 2025 19:43:01.957214117 CET3522813566192.168.2.1583.222.34.98
    Jan 8, 2025 19:43:01.957396984 CET135663582083.222.250.245192.168.2.15
    Jan 8, 2025 19:43:01.957442045 CET3582013566192.168.2.1583.222.250.245
    Jan 8, 2025 19:43:01.959309101 CET135663569083.222.25.78192.168.2.15
    Jan 8, 2025 19:43:01.959347963 CET3569013566192.168.2.1583.222.25.78
    Jan 8, 2025 19:43:01.960149050 CET5314413566192.168.2.1583.222.114.30
    Jan 8, 2025 19:43:01.961978912 CET135663522883.222.34.98192.168.2.15
    Jan 8, 2025 19:43:01.962014914 CET3522813566192.168.2.1583.222.34.98
    Jan 8, 2025 19:43:01.962891102 CET5779813566192.168.2.1583.222.64.229
    Jan 8, 2025 19:43:01.964895964 CET135665314483.222.114.30192.168.2.15
    Jan 8, 2025 19:43:01.964936018 CET5314413566192.168.2.1583.222.114.30
    Jan 8, 2025 19:43:01.965656042 CET4175413566192.168.2.1583.222.6.185
    Jan 8, 2025 19:43:01.967699051 CET135665779883.222.64.229192.168.2.15
    Jan 8, 2025 19:43:01.967732906 CET5779813566192.168.2.1583.222.64.229
    Jan 8, 2025 19:43:01.968708038 CET5135013566192.168.2.1583.222.18.244
    Jan 8, 2025 19:43:01.970398903 CET135664175483.222.6.185192.168.2.15
    Jan 8, 2025 19:43:01.970432997 CET4175413566192.168.2.1583.222.6.185
    Jan 8, 2025 19:43:01.971126080 CET6020213566192.168.2.1583.222.215.205
    Jan 8, 2025 19:43:01.973464012 CET135665135083.222.18.244192.168.2.15
    Jan 8, 2025 19:43:01.973509073 CET5135013566192.168.2.1583.222.18.244
    Jan 8, 2025 19:43:01.974109888 CET5568613566192.168.2.1583.222.147.215
    Jan 8, 2025 19:43:01.975898981 CET135666020283.222.215.205192.168.2.15
    Jan 8, 2025 19:43:01.975938082 CET6020213566192.168.2.1583.222.215.205
    Jan 8, 2025 19:43:01.977144957 CET4670413566192.168.2.1583.222.189.126
    Jan 8, 2025 19:43:01.978879929 CET135665568683.222.147.215192.168.2.15
    Jan 8, 2025 19:43:01.978924036 CET5568613566192.168.2.1583.222.147.215
    Jan 8, 2025 19:43:01.980137110 CET5498213566192.168.2.1583.222.53.191
    Jan 8, 2025 19:43:01.981908083 CET135664670483.222.189.126192.168.2.15
    Jan 8, 2025 19:43:01.981945038 CET4670413566192.168.2.1583.222.189.126
    Jan 8, 2025 19:43:01.984894037 CET135665498283.222.53.191192.168.2.15
    Jan 8, 2025 19:43:01.984935999 CET5498213566192.168.2.1583.222.53.191
    Jan 8, 2025 19:43:02.004246950 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:43:02.009390116 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:43:02.009430885 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:43:02.013051033 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:43:02.017790079 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:43:02.017844915 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:43:02.022641897 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:43:12.013993979 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:43:12.018909931 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:43:12.218344927 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:43:12.218414068 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:43:12.586009026 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:43:12.586069107 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:44:12.640261889 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:44:12.645296097 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:44:12.853059053 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:44:12.853151083 CET5810013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:44:13.585056067 CET135665810083.222.191.90192.168.2.15
    Jan 8, 2025 19:44:13.585154057 CET5810013566192.168.2.1583.222.191.90
    TimestampSource PortDest PortSource IPDest IP
    Jan 8, 2025 19:43:01.985161066 CET5871253192.168.2.158.8.8.8
    Jan 8, 2025 19:43:02.002417088 CET53587128.8.8.8192.168.2.15
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jan 8, 2025 19:43:01.985161066 CET192.168.2.158.8.8.80x7900Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jan 8, 2025 19:43:02.002417088 CET8.8.8.8192.168.2.150x7900No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:/tmp/Kloki.arm5.elf
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/usr/bin/gnome-shell
    Arguments:/usr/bin/gnome-shell
    File size:23168 bytes
    MD5 hash:da7a257239677622fe4b3a65972c9e87

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-print-notifications
    Arguments:/usr/libexec/gsd-print-notifications
    File size:51840 bytes
    MD5 hash:71539698aa691718cee775d6b9450ae2

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:43:00
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-rfkill
    Arguments:/usr/libexec/gsd-rfkill
    File size:51808 bytes
    MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

    Start time (UTC):18:43:01
    Start date (UTC):08/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:43:01
    Start date (UTC):08/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:43:01
    Start date (UTC):08/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:43:01
    Start date (UTC):08/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:43:11
    Start date (UTC):08/01/2025
    Path:/usr/lib/systemd/systemd
    Arguments:-
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    Start time (UTC):18:43:11
    Start date (UTC):08/01/2025
    Path:/lib/systemd/systemd-user-runtime-dir
    Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
    File size:22672 bytes
    MD5 hash:d55f4b0847f88131dbcfb07435178e54