Edit tour
Linux
Analysis Report
Kloki.arm4.elf
Overview
General Information
Sample name: | Kloki.arm4.elf |
Analysis ID: | 1586170 |
MD5: | 2e22660cb3d80c9b815c2c202aeb026e |
SHA1: | 90b64d1b75bf2187d5ff8b82420864f12929adfb |
SHA256: | 84a616beb7ec6f1461fd1228ba8f629dc2b9c1d45e9cb26395e9ca7338dfc871 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1586170 |
Start date and time: | 2025-01-08 19:46:00 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | Kloki.arm4.elf |
Detection: | MAL |
Classification: | mal52.spre.linELF@0/0@1/0 |
- VT rate limit hit for: Kloki.arm4.elf
Command: | /tmp/Kloki.arm4.elf |
PID: | 5531 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | suka |
Standard Error: |
- system is lnxubuntu20
- Kloki.arm4.elf New Fork (PID: 5533, Parent: 5531)
- Kloki.arm4.elf New Fork (PID: 5535, Parent: 5533)
- Kloki.arm4.elf New Fork (PID: 5537, Parent: 5533)
- gnome-session-binary New Fork (PID: 5539, Parent: 1383)
- gnome-session-binary New Fork (PID: 5559, Parent: 1383)
- gnome-session-binary New Fork (PID: 5560, Parent: 1383)
- gnome-session-binary New Fork (PID: 5561, Parent: 1383)
- gdm3 New Fork (PID: 5562, Parent: 1289)
- gdm3 New Fork (PID: 5566, Parent: 1289)
- systemd New Fork (PID: 5571, Parent: 1)
- cleanup
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-08T19:47:01.896811+0100 | 2500036 | 2 | Misc Attack | 83.222.191.90 | 13566 | 192.168.2.14 | 56486 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Program segment: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Source: | Submission file: | ||
Source: | Submission file: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | Path Interception | Path Interception | 1 Obfuscated Files or Information | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
21% | ReversingLabs | Linux.Trojan.Svirtu |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.90 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.230.31 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.5.255 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.46.234 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.127.11 | unknown | Russian Federation | 47328 | TRI-ASTrueRecordsIncES | false | |
83.222.136.115 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.31.41 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.188.55 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.1.234 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.159.40 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.164.170 | unknown | Bulgaria | 31037 | WAVENETLB | false | |
83.222.42.189 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.143.228 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.221.139 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.86.183 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.143.148 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.211.165 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.185.195 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.14.137 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.14.139 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.77.251 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.97.202 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.47.19 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.79.28 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.30.82 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.78.178 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.46.184 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.66.249 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.75.30 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.118.135 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.181.189 | unknown | Bulgaria | 12615 | GCN-ASGCNAD-SofiaBulgariaBG | false | |
83.222.62.144 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.85.68 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.173.21 | unknown | Bulgaria | 12615 | GCN-ASGCNAD-SofiaBulgariaBG | false | |
83.222.135.132 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.208.172 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.43.128 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.42.78 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.67.154 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.66.82 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.188.177 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.238.10 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.212.155 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.210.140 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.9.15 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.115.89 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.116.199 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.156.223 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.170.68 | unknown | Bulgaria | 49040 | KIG-UNISAT-TVBG | false | |
83.222.116.194 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.206.178 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.73.212 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.123.106 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.37.9 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.191.90 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.97.55 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.209.249 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.33.3 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.146.84 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.110.86 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.30.99 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.4.239 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.226.122 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.237.252 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.38.250 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.217.180 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.253.28 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.151.76 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.154.225 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
COGECO-PEER1CA | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
LOL-ASluLU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
MASTERHOST-ASMoscowRussiaRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phorpiex, RHADAMANTHYS, Xmrig | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
TRI-ASTrueRecordsIncES | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 7.953025596579037 |
TrID: |
|
File name: | Kloki.arm4.elf |
File size: | 32'164 bytes |
MD5: | 2e22660cb3d80c9b815c2c202aeb026e |
SHA1: | 90b64d1b75bf2187d5ff8b82420864f12929adfb |
SHA256: | 84a616beb7ec6f1461fd1228ba8f629dc2b9c1d45e9cb26395e9ca7338dfc871 |
SHA512: | 86221993ce4adc082ff93f687b706fb1d37971af608c3d9938c04274e120b99c2c26e8dffe6c0224a44858b7e5b3fea957dd31c2a018895983df56c7059e93e0 |
SSDEEP: | 768:heh2UMosaCcZeOHVBT/M5ZD1k05EQCO14gFfosBKUHnC3UGwt:urVPT/IthkO1TwPUHnewt |
TLSH: | ACE2E1236590E8B3C63111B3DC3D9902779BA6A521DAB075070CC2B67F89D9318BB87F |
File Content Preview: | .ELF...a..........(......k..4...........4. ...(..........................5...........................|...|..........Q.td............................\...sfga........\...\.......P..........?.E.h;.}...^..........f<....%.",.....n7..Io..a...e...9.<...B9..{..j. |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 0 |
Section Header Size: | 40 |
Number of Section Headers: | 0 |
Header String Table Index: | 0 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x8000 | 0x8000 | 0x1000 | 0x13500 | 7.8901 | 0x6 | RW | 0x8000 | ||
LOAD | 0x0 | 0x20000 | 0x20000 | 0x7cb3 | 0x7cb3 | 7.9555 | 0x5 | R E | 0x8000 | ||
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-08T19:47:01.896811+0100 | 2500036 | ET COMPROMISED Known Compromised or Hostile Host Traffic group 19 | 2 | 83.222.191.90 | 13566 | 192.168.2.14 | 56486 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 8, 2025 19:47:01.569853067 CET | 44754 | 13566 | 192.168.2.14 | 83.222.143.148 |
Jan 8, 2025 19:47:01.574610949 CET | 13566 | 44754 | 83.222.143.148 | 192.168.2.14 |
Jan 8, 2025 19:47:01.574692011 CET | 44754 | 13566 | 192.168.2.14 | 83.222.143.148 |
Jan 8, 2025 19:47:01.576587915 CET | 44754 | 13566 | 192.168.2.14 | 83.222.143.148 |
Jan 8, 2025 19:47:01.581446886 CET | 13566 | 44754 | 83.222.143.148 | 192.168.2.14 |
Jan 8, 2025 19:47:01.581495047 CET | 44754 | 13566 | 192.168.2.14 | 83.222.143.148 |
Jan 8, 2025 19:47:01.600162983 CET | 58470 | 13566 | 192.168.2.14 | 83.222.30.82 |
Jan 8, 2025 19:47:01.604962111 CET | 13566 | 58470 | 83.222.30.82 | 192.168.2.14 |
Jan 8, 2025 19:47:01.605015039 CET | 58470 | 13566 | 192.168.2.14 | 83.222.30.82 |
Jan 8, 2025 19:47:01.618233919 CET | 58470 | 13566 | 192.168.2.14 | 83.222.30.82 |
Jan 8, 2025 19:47:01.623116016 CET | 13566 | 58470 | 83.222.30.82 | 192.168.2.14 |
Jan 8, 2025 19:47:01.623147964 CET | 58470 | 13566 | 192.168.2.14 | 83.222.30.82 |
Jan 8, 2025 19:47:01.625601053 CET | 47508 | 13566 | 192.168.2.14 | 83.222.42.78 |
Jan 8, 2025 19:47:01.629892111 CET | 55548 | 13566 | 192.168.2.14 | 83.222.37.9 |
Jan 8, 2025 19:47:01.630403996 CET | 13566 | 47508 | 83.222.42.78 | 192.168.2.14 |
Jan 8, 2025 19:47:01.630450010 CET | 47508 | 13566 | 192.168.2.14 | 83.222.42.78 |
Jan 8, 2025 19:47:01.631341934 CET | 48446 | 13566 | 192.168.2.14 | 83.222.47.19 |
Jan 8, 2025 19:47:01.634639025 CET | 13566 | 55548 | 83.222.37.9 | 192.168.2.14 |
Jan 8, 2025 19:47:01.634689093 CET | 55548 | 13566 | 192.168.2.14 | 83.222.37.9 |
Jan 8, 2025 19:47:01.636176109 CET | 13566 | 48446 | 83.222.47.19 | 192.168.2.14 |
Jan 8, 2025 19:47:01.636244059 CET | 48446 | 13566 | 192.168.2.14 | 83.222.47.19 |
Jan 8, 2025 19:47:01.643153906 CET | 48446 | 13566 | 192.168.2.14 | 83.222.47.19 |
Jan 8, 2025 19:47:01.646699905 CET | 59576 | 13566 | 192.168.2.14 | 83.222.14.137 |
Jan 8, 2025 19:47:01.648053885 CET | 13566 | 48446 | 83.222.47.19 | 192.168.2.14 |
Jan 8, 2025 19:47:01.648103952 CET | 48446 | 13566 | 192.168.2.14 | 83.222.47.19 |
Jan 8, 2025 19:47:01.648237944 CET | 53404 | 13566 | 192.168.2.14 | 83.222.79.28 |
Jan 8, 2025 19:47:01.651485920 CET | 13566 | 59576 | 83.222.14.137 | 192.168.2.14 |
Jan 8, 2025 19:47:01.651539087 CET | 59576 | 13566 | 192.168.2.14 | 83.222.14.137 |
Jan 8, 2025 19:47:01.653003931 CET | 13566 | 53404 | 83.222.79.28 | 192.168.2.14 |
Jan 8, 2025 19:47:01.653048992 CET | 53404 | 13566 | 192.168.2.14 | 83.222.79.28 |
Jan 8, 2025 19:47:01.660068035 CET | 53404 | 13566 | 192.168.2.14 | 83.222.79.28 |
Jan 8, 2025 19:47:01.661174059 CET | 56458 | 13566 | 192.168.2.14 | 83.222.237.252 |
Jan 8, 2025 19:47:01.663919926 CET | 33388 | 13566 | 192.168.2.14 | 83.222.33.3 |
Jan 8, 2025 19:47:01.664877892 CET | 13566 | 53404 | 83.222.79.28 | 192.168.2.14 |
Jan 8, 2025 19:47:01.664923906 CET | 53404 | 13566 | 192.168.2.14 | 83.222.79.28 |
Jan 8, 2025 19:47:01.665920973 CET | 13566 | 56458 | 83.222.237.252 | 192.168.2.14 |
Jan 8, 2025 19:47:01.665966988 CET | 56458 | 13566 | 192.168.2.14 | 83.222.237.252 |
Jan 8, 2025 19:47:01.666832924 CET | 43956 | 13566 | 192.168.2.14 | 83.222.67.154 |
Jan 8, 2025 19:47:01.668704033 CET | 13566 | 33388 | 83.222.33.3 | 192.168.2.14 |
Jan 8, 2025 19:47:01.668772936 CET | 33388 | 13566 | 192.168.2.14 | 83.222.33.3 |
Jan 8, 2025 19:47:01.669761896 CET | 51952 | 13566 | 192.168.2.14 | 83.222.164.170 |
Jan 8, 2025 19:47:01.671674013 CET | 13566 | 43956 | 83.222.67.154 | 192.168.2.14 |
Jan 8, 2025 19:47:01.671708107 CET | 43956 | 13566 | 192.168.2.14 | 83.222.67.154 |
Jan 8, 2025 19:47:01.673381090 CET | 38646 | 13566 | 192.168.2.14 | 83.222.226.122 |
Jan 8, 2025 19:47:01.674518108 CET | 13566 | 51952 | 83.222.164.170 | 192.168.2.14 |
Jan 8, 2025 19:47:01.674559116 CET | 51952 | 13566 | 192.168.2.14 | 83.222.164.170 |
Jan 8, 2025 19:47:01.676362038 CET | 50828 | 13566 | 192.168.2.14 | 83.222.188.55 |
Jan 8, 2025 19:47:01.678133965 CET | 13566 | 38646 | 83.222.226.122 | 192.168.2.14 |
Jan 8, 2025 19:47:01.678177118 CET | 38646 | 13566 | 192.168.2.14 | 83.222.226.122 |
Jan 8, 2025 19:47:01.679579020 CET | 45466 | 13566 | 192.168.2.14 | 83.222.78.178 |
Jan 8, 2025 19:47:01.681184053 CET | 13566 | 50828 | 83.222.188.55 | 192.168.2.14 |
Jan 8, 2025 19:47:01.681231976 CET | 50828 | 13566 | 192.168.2.14 | 83.222.188.55 |
Jan 8, 2025 19:47:01.682698011 CET | 54958 | 13566 | 192.168.2.14 | 83.222.127.11 |
Jan 8, 2025 19:47:01.684415102 CET | 13566 | 45466 | 83.222.78.178 | 192.168.2.14 |
Jan 8, 2025 19:47:01.684452057 CET | 45466 | 13566 | 192.168.2.14 | 83.222.78.178 |
Jan 8, 2025 19:47:01.685240984 CET | 57780 | 13566 | 192.168.2.14 | 83.222.9.15 |
Jan 8, 2025 19:47:01.687465906 CET | 13566 | 54958 | 83.222.127.11 | 192.168.2.14 |
Jan 8, 2025 19:47:01.687511921 CET | 54958 | 13566 | 192.168.2.14 | 83.222.127.11 |
Jan 8, 2025 19:47:01.688198090 CET | 51310 | 13566 | 192.168.2.14 | 83.222.159.40 |
Jan 8, 2025 19:47:01.690057993 CET | 13566 | 57780 | 83.222.9.15 | 192.168.2.14 |
Jan 8, 2025 19:47:01.690118074 CET | 57780 | 13566 | 192.168.2.14 | 83.222.9.15 |
Jan 8, 2025 19:47:01.691561937 CET | 47812 | 13566 | 192.168.2.14 | 83.222.97.202 |
Jan 8, 2025 19:47:01.693038940 CET | 13566 | 51310 | 83.222.159.40 | 192.168.2.14 |
Jan 8, 2025 19:47:01.693083048 CET | 51310 | 13566 | 192.168.2.14 | 83.222.159.40 |
Jan 8, 2025 19:47:01.694892883 CET | 57844 | 13566 | 192.168.2.14 | 83.222.118.135 |
Jan 8, 2025 19:47:01.696320057 CET | 13566 | 47812 | 83.222.97.202 | 192.168.2.14 |
Jan 8, 2025 19:47:01.696361065 CET | 47812 | 13566 | 192.168.2.14 | 83.222.97.202 |
Jan 8, 2025 19:47:01.697841883 CET | 38362 | 13566 | 192.168.2.14 | 83.222.211.165 |
Jan 8, 2025 19:47:01.699680090 CET | 13566 | 57844 | 83.222.118.135 | 192.168.2.14 |
Jan 8, 2025 19:47:01.699727058 CET | 57844 | 13566 | 192.168.2.14 | 83.222.118.135 |
Jan 8, 2025 19:47:01.701452017 CET | 39870 | 13566 | 192.168.2.14 | 83.222.154.225 |
Jan 8, 2025 19:47:01.702656984 CET | 13566 | 38362 | 83.222.211.165 | 192.168.2.14 |
Jan 8, 2025 19:47:01.702697992 CET | 38362 | 13566 | 192.168.2.14 | 83.222.211.165 |
Jan 8, 2025 19:47:01.702965975 CET | 38296 | 13566 | 192.168.2.14 | 83.222.46.234 |
Jan 8, 2025 19:47:01.704400063 CET | 60866 | 13566 | 192.168.2.14 | 83.222.253.28 |
Jan 8, 2025 19:47:01.706146955 CET | 47462 | 13566 | 192.168.2.14 | 83.222.230.31 |
Jan 8, 2025 19:47:01.706275940 CET | 13566 | 39870 | 83.222.154.225 | 192.168.2.14 |
Jan 8, 2025 19:47:01.706319094 CET | 39870 | 13566 | 192.168.2.14 | 83.222.154.225 |
Jan 8, 2025 19:47:01.707926035 CET | 13566 | 38296 | 83.222.46.234 | 192.168.2.14 |
Jan 8, 2025 19:47:01.707969904 CET | 38296 | 13566 | 192.168.2.14 | 83.222.46.234 |
Jan 8, 2025 19:47:01.708651066 CET | 43134 | 13566 | 192.168.2.14 | 83.222.31.41 |
Jan 8, 2025 19:47:01.709167957 CET | 13566 | 60866 | 83.222.253.28 | 192.168.2.14 |
Jan 8, 2025 19:47:01.709209919 CET | 60866 | 13566 | 192.168.2.14 | 83.222.253.28 |
Jan 8, 2025 19:47:01.711263895 CET | 13566 | 47462 | 83.222.230.31 | 192.168.2.14 |
Jan 8, 2025 19:47:01.711302996 CET | 47462 | 13566 | 192.168.2.14 | 83.222.230.31 |
Jan 8, 2025 19:47:01.711507082 CET | 37366 | 13566 | 192.168.2.14 | 83.222.185.195 |
Jan 8, 2025 19:47:01.713560104 CET | 13566 | 43134 | 83.222.31.41 | 192.168.2.14 |
Jan 8, 2025 19:47:01.714027882 CET | 43134 | 13566 | 192.168.2.14 | 83.222.31.41 |
Jan 8, 2025 19:47:01.715337992 CET | 36026 | 13566 | 192.168.2.14 | 83.222.212.155 |
Jan 8, 2025 19:47:01.716907024 CET | 13566 | 37366 | 83.222.185.195 | 192.168.2.14 |
Jan 8, 2025 19:47:01.717118979 CET | 37366 | 13566 | 192.168.2.14 | 83.222.185.195 |
Jan 8, 2025 19:47:01.718063116 CET | 49688 | 13566 | 192.168.2.14 | 83.222.62.144 |
Jan 8, 2025 19:47:01.722490072 CET | 13566 | 36026 | 83.222.212.155 | 192.168.2.14 |
Jan 8, 2025 19:47:01.722537041 CET | 36026 | 13566 | 192.168.2.14 | 83.222.212.155 |
Jan 8, 2025 19:47:01.722677946 CET | 39756 | 13566 | 192.168.2.14 | 83.222.210.140 |
Jan 8, 2025 19:47:01.724539042 CET | 13566 | 49688 | 83.222.62.144 | 192.168.2.14 |
Jan 8, 2025 19:47:01.724577904 CET | 49688 | 13566 | 192.168.2.14 | 83.222.62.144 |
Jan 8, 2025 19:47:01.726982117 CET | 43830 | 13566 | 192.168.2.14 | 83.222.66.82 |
Jan 8, 2025 19:47:01.727531910 CET | 13566 | 39756 | 83.222.210.140 | 192.168.2.14 |
Jan 8, 2025 19:47:01.727580070 CET | 39756 | 13566 | 192.168.2.14 | 83.222.210.140 |
Jan 8, 2025 19:47:01.729499102 CET | 37420 | 13566 | 192.168.2.14 | 83.222.151.76 |
Jan 8, 2025 19:47:01.731726885 CET | 13566 | 43830 | 83.222.66.82 | 192.168.2.14 |
Jan 8, 2025 19:47:01.731772900 CET | 43830 | 13566 | 192.168.2.14 | 83.222.66.82 |
Jan 8, 2025 19:47:01.734349012 CET | 13566 | 37420 | 83.222.151.76 | 192.168.2.14 |
Jan 8, 2025 19:47:01.734400034 CET | 37420 | 13566 | 192.168.2.14 | 83.222.151.76 |
Jan 8, 2025 19:47:01.754406929 CET | 37420 | 13566 | 192.168.2.14 | 83.222.151.76 |
Jan 8, 2025 19:47:01.755655050 CET | 40496 | 13566 | 192.168.2.14 | 83.222.97.55 |
Jan 8, 2025 19:47:01.758447886 CET | 53530 | 13566 | 192.168.2.14 | 83.222.116.194 |
Jan 8, 2025 19:47:01.759306908 CET | 13566 | 37420 | 83.222.151.76 | 192.168.2.14 |
Jan 8, 2025 19:47:01.759351015 CET | 37420 | 13566 | 192.168.2.14 | 83.222.151.76 |
Jan 8, 2025 19:47:01.760438919 CET | 13566 | 40496 | 83.222.97.55 | 192.168.2.14 |
Jan 8, 2025 19:47:01.760478020 CET | 40496 | 13566 | 192.168.2.14 | 83.222.97.55 |
Jan 8, 2025 19:47:01.761107922 CET | 50906 | 13566 | 192.168.2.14 | 83.222.1.234 |
Jan 8, 2025 19:47:01.763243914 CET | 13566 | 53530 | 83.222.116.194 | 192.168.2.14 |
Jan 8, 2025 19:47:01.763298988 CET | 53530 | 13566 | 192.168.2.14 | 83.222.116.194 |
Jan 8, 2025 19:47:01.765902996 CET | 13566 | 50906 | 83.222.1.234 | 192.168.2.14 |
Jan 8, 2025 19:47:01.765953064 CET | 50906 | 13566 | 192.168.2.14 | 83.222.1.234 |
Jan 8, 2025 19:47:01.766227007 CET | 50906 | 13566 | 192.168.2.14 | 83.222.1.234 |
Jan 8, 2025 19:47:01.767014980 CET | 48248 | 13566 | 192.168.2.14 | 83.222.73.212 |
Jan 8, 2025 19:47:01.770339966 CET | 60668 | 13566 | 192.168.2.14 | 83.222.143.228 |
Jan 8, 2025 19:47:01.771224976 CET | 13566 | 50906 | 83.222.1.234 | 192.168.2.14 |
Jan 8, 2025 19:47:01.771275043 CET | 50906 | 13566 | 192.168.2.14 | 83.222.1.234 |
Jan 8, 2025 19:47:01.771892071 CET | 13566 | 48248 | 83.222.73.212 | 192.168.2.14 |
Jan 8, 2025 19:47:01.771931887 CET | 48248 | 13566 | 192.168.2.14 | 83.222.73.212 |
Jan 8, 2025 19:47:01.775170088 CET | 58744 | 13566 | 192.168.2.14 | 83.222.181.189 |
Jan 8, 2025 19:47:01.775201082 CET | 13566 | 60668 | 83.222.143.228 | 192.168.2.14 |
Jan 8, 2025 19:47:01.775250912 CET | 60668 | 13566 | 192.168.2.14 | 83.222.143.228 |
Jan 8, 2025 19:47:01.779546022 CET | 43608 | 13566 | 192.168.2.14 | 83.222.206.178 |
Jan 8, 2025 19:47:01.780035019 CET | 13566 | 58744 | 83.222.181.189 | 192.168.2.14 |
Jan 8, 2025 19:47:01.780070066 CET | 58744 | 13566 | 192.168.2.14 | 83.222.181.189 |
Jan 8, 2025 19:47:01.782449007 CET | 42050 | 13566 | 192.168.2.14 | 83.222.217.180 |
Jan 8, 2025 19:47:01.784363031 CET | 13566 | 43608 | 83.222.206.178 | 192.168.2.14 |
Jan 8, 2025 19:47:01.784423113 CET | 43608 | 13566 | 192.168.2.14 | 83.222.206.178 |
Jan 8, 2025 19:47:01.787271023 CET | 13566 | 42050 | 83.222.217.180 | 192.168.2.14 |
Jan 8, 2025 19:47:01.787399054 CET | 42050 | 13566 | 192.168.2.14 | 83.222.217.180 |
Jan 8, 2025 19:47:01.788239002 CET | 49176 | 13566 | 192.168.2.14 | 83.222.209.249 |
Jan 8, 2025 19:47:01.791266918 CET | 42548 | 13566 | 192.168.2.14 | 83.222.221.139 |
Jan 8, 2025 19:47:01.793082952 CET | 13566 | 49176 | 83.222.209.249 | 192.168.2.14 |
Jan 8, 2025 19:47:01.793123007 CET | 49176 | 13566 | 192.168.2.14 | 83.222.209.249 |
Jan 8, 2025 19:47:01.793575048 CET | 51828 | 13566 | 192.168.2.14 | 83.222.188.177 |
Jan 8, 2025 19:47:01.795984983 CET | 40664 | 13566 | 192.168.2.14 | 83.222.38.250 |
Jan 8, 2025 19:47:01.795994043 CET | 13566 | 42548 | 83.222.221.139 | 192.168.2.14 |
Jan 8, 2025 19:47:01.796066999 CET | 42548 | 13566 | 192.168.2.14 | 83.222.221.139 |
Jan 8, 2025 19:47:01.797975063 CET | 45282 | 13566 | 192.168.2.14 | 83.222.66.249 |
Jan 8, 2025 19:47:01.798333883 CET | 13566 | 51828 | 83.222.188.177 | 192.168.2.14 |
Jan 8, 2025 19:47:01.798378944 CET | 51828 | 13566 | 192.168.2.14 | 83.222.188.177 |
Jan 8, 2025 19:47:01.800221920 CET | 43432 | 13566 | 192.168.2.14 | 83.222.135.132 |
Jan 8, 2025 19:47:01.800842047 CET | 13566 | 40664 | 83.222.38.250 | 192.168.2.14 |
Jan 8, 2025 19:47:01.800899029 CET | 40664 | 13566 | 192.168.2.14 | 83.222.38.250 |
Jan 8, 2025 19:47:01.802809000 CET | 13566 | 45282 | 83.222.66.249 | 192.168.2.14 |
Jan 8, 2025 19:47:01.802865028 CET | 45282 | 13566 | 192.168.2.14 | 83.222.66.249 |
Jan 8, 2025 19:47:01.803281069 CET | 49476 | 13566 | 192.168.2.14 | 83.222.75.30 |
Jan 8, 2025 19:47:01.805005074 CET | 13566 | 43432 | 83.222.135.132 | 192.168.2.14 |
Jan 8, 2025 19:47:01.805048943 CET | 43432 | 13566 | 192.168.2.14 | 83.222.135.132 |
Jan 8, 2025 19:47:01.805871010 CET | 54086 | 13566 | 192.168.2.14 | 83.222.208.172 |
Jan 8, 2025 19:47:01.808068991 CET | 13566 | 49476 | 83.222.75.30 | 192.168.2.14 |
Jan 8, 2025 19:47:01.808114052 CET | 49476 | 13566 | 192.168.2.14 | 83.222.75.30 |
Jan 8, 2025 19:47:01.808764935 CET | 37972 | 13566 | 192.168.2.14 | 83.222.85.68 |
Jan 8, 2025 19:47:01.810619116 CET | 13566 | 54086 | 83.222.208.172 | 192.168.2.14 |
Jan 8, 2025 19:47:01.810664892 CET | 54086 | 13566 | 192.168.2.14 | 83.222.208.172 |
Jan 8, 2025 19:47:01.811774969 CET | 52894 | 13566 | 192.168.2.14 | 83.222.110.86 |
Jan 8, 2025 19:47:01.813508034 CET | 13566 | 37972 | 83.222.85.68 | 192.168.2.14 |
Jan 8, 2025 19:47:01.813535929 CET | 37972 | 13566 | 192.168.2.14 | 83.222.85.68 |
Jan 8, 2025 19:47:01.814941883 CET | 40260 | 13566 | 192.168.2.14 | 83.222.46.184 |
Jan 8, 2025 19:47:01.816586018 CET | 13566 | 52894 | 83.222.110.86 | 192.168.2.14 |
Jan 8, 2025 19:47:01.816618919 CET | 52894 | 13566 | 192.168.2.14 | 83.222.110.86 |
Jan 8, 2025 19:47:01.817548990 CET | 41360 | 13566 | 192.168.2.14 | 83.222.42.189 |
Jan 8, 2025 19:47:01.819720984 CET | 13566 | 40260 | 83.222.46.184 | 192.168.2.14 |
Jan 8, 2025 19:47:01.819760084 CET | 40260 | 13566 | 192.168.2.14 | 83.222.46.184 |
Jan 8, 2025 19:47:01.820147991 CET | 47846 | 13566 | 192.168.2.14 | 83.222.156.223 |
Jan 8, 2025 19:47:01.822422028 CET | 51100 | 13566 | 192.168.2.14 | 83.222.123.106 |
Jan 8, 2025 19:47:01.822455883 CET | 13566 | 41360 | 83.222.42.189 | 192.168.2.14 |
Jan 8, 2025 19:47:01.822487116 CET | 41360 | 13566 | 192.168.2.14 | 83.222.42.189 |
Jan 8, 2025 19:47:01.824779987 CET | 46388 | 13566 | 192.168.2.14 | 83.222.146.84 |
Jan 8, 2025 19:47:01.824938059 CET | 13566 | 47846 | 83.222.156.223 | 192.168.2.14 |
Jan 8, 2025 19:47:01.824971914 CET | 47846 | 13566 | 192.168.2.14 | 83.222.156.223 |
Jan 8, 2025 19:47:01.827224016 CET | 50058 | 13566 | 192.168.2.14 | 83.222.30.99 |
Jan 8, 2025 19:47:01.827357054 CET | 13566 | 51100 | 83.222.123.106 | 192.168.2.14 |
Jan 8, 2025 19:47:01.827398062 CET | 51100 | 13566 | 192.168.2.14 | 83.222.123.106 |
Jan 8, 2025 19:47:01.829555035 CET | 13566 | 46388 | 83.222.146.84 | 192.168.2.14 |
Jan 8, 2025 19:47:01.829588890 CET | 46388 | 13566 | 192.168.2.14 | 83.222.146.84 |
Jan 8, 2025 19:47:01.831559896 CET | 39276 | 13566 | 192.168.2.14 | 83.222.77.251 |
Jan 8, 2025 19:47:01.832073927 CET | 13566 | 50058 | 83.222.30.99 | 192.168.2.14 |
Jan 8, 2025 19:47:01.832134008 CET | 50058 | 13566 | 192.168.2.14 | 83.222.30.99 |
Jan 8, 2025 19:47:01.835927010 CET | 56444 | 13566 | 192.168.2.14 | 83.222.238.10 |
Jan 8, 2025 19:47:01.836345911 CET | 13566 | 39276 | 83.222.77.251 | 192.168.2.14 |
Jan 8, 2025 19:47:01.836384058 CET | 39276 | 13566 | 192.168.2.14 | 83.222.77.251 |
Jan 8, 2025 19:47:01.839811087 CET | 45230 | 13566 | 192.168.2.14 | 83.222.173.21 |
Jan 8, 2025 19:47:01.840678930 CET | 13566 | 56444 | 83.222.238.10 | 192.168.2.14 |
Jan 8, 2025 19:47:01.840720892 CET | 56444 | 13566 | 192.168.2.14 | 83.222.238.10 |
Jan 8, 2025 19:47:01.843869925 CET | 52168 | 13566 | 192.168.2.14 | 83.222.4.239 |
Jan 8, 2025 19:47:01.844619989 CET | 13566 | 45230 | 83.222.173.21 | 192.168.2.14 |
Jan 8, 2025 19:47:01.844660997 CET | 45230 | 13566 | 192.168.2.14 | 83.222.173.21 |
Jan 8, 2025 19:47:01.848526955 CET | 54590 | 13566 | 192.168.2.14 | 83.222.14.139 |
Jan 8, 2025 19:47:01.848630905 CET | 13566 | 52168 | 83.222.4.239 | 192.168.2.14 |
Jan 8, 2025 19:47:01.848706961 CET | 52168 | 13566 | 192.168.2.14 | 83.222.4.239 |
Jan 8, 2025 19:47:01.852154016 CET | 32804 | 13566 | 192.168.2.14 | 83.222.115.89 |
Jan 8, 2025 19:47:01.853360891 CET | 13566 | 54590 | 83.222.14.139 | 192.168.2.14 |
Jan 8, 2025 19:47:01.853406906 CET | 54590 | 13566 | 192.168.2.14 | 83.222.14.139 |
Jan 8, 2025 19:47:01.855957985 CET | 48966 | 13566 | 192.168.2.14 | 83.222.170.68 |
Jan 8, 2025 19:47:01.856926918 CET | 13566 | 32804 | 83.222.115.89 | 192.168.2.14 |
Jan 8, 2025 19:47:01.856967926 CET | 32804 | 13566 | 192.168.2.14 | 83.222.115.89 |
Jan 8, 2025 19:47:01.859514952 CET | 47918 | 13566 | 192.168.2.14 | 83.222.5.255 |
Jan 8, 2025 19:47:01.860733986 CET | 13566 | 48966 | 83.222.170.68 | 192.168.2.14 |
Jan 8, 2025 19:47:01.860775948 CET | 48966 | 13566 | 192.168.2.14 | 83.222.170.68 |
Jan 8, 2025 19:47:01.863090038 CET | 34934 | 13566 | 192.168.2.14 | 83.222.136.115 |
Jan 8, 2025 19:47:01.864327908 CET | 13566 | 47918 | 83.222.5.255 | 192.168.2.14 |
Jan 8, 2025 19:47:01.864367008 CET | 47918 | 13566 | 192.168.2.14 | 83.222.5.255 |
Jan 8, 2025 19:47:01.866894960 CET | 45460 | 13566 | 192.168.2.14 | 83.222.86.183 |
Jan 8, 2025 19:47:01.867935896 CET | 13566 | 34934 | 83.222.136.115 | 192.168.2.14 |
Jan 8, 2025 19:47:01.867976904 CET | 34934 | 13566 | 192.168.2.14 | 83.222.136.115 |
Jan 8, 2025 19:47:01.870301962 CET | 51634 | 13566 | 192.168.2.14 | 83.222.43.128 |
Jan 8, 2025 19:47:01.871705055 CET | 13566 | 45460 | 83.222.86.183 | 192.168.2.14 |
Jan 8, 2025 19:47:01.871751070 CET | 45460 | 13566 | 192.168.2.14 | 83.222.86.183 |
Jan 8, 2025 19:47:01.874130011 CET | 47110 | 13566 | 192.168.2.14 | 83.222.116.199 |
Jan 8, 2025 19:47:01.875102043 CET | 13566 | 51634 | 83.222.43.128 | 192.168.2.14 |
Jan 8, 2025 19:47:01.875138044 CET | 51634 | 13566 | 192.168.2.14 | 83.222.43.128 |
Jan 8, 2025 19:47:01.878962040 CET | 13566 | 47110 | 83.222.116.199 | 192.168.2.14 |
Jan 8, 2025 19:47:01.879010916 CET | 47110 | 13566 | 192.168.2.14 | 83.222.116.199 |
Jan 8, 2025 19:47:01.891962051 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:47:01.896811008 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:47:01.896862030 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:47:01.901194096 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:47:01.905982971 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:47:01.906019926 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:47:01.910811901 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:47:11.909723043 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:47:11.914663076 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:47:12.466519117 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:47:12.466588020 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:47:12.600337029 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:47:12.600394964 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:48:12.653641939 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:48:12.658710003 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:48:12.862343073 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:48:12.862483978 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Jan 8, 2025 19:48:13.508074999 CET | 13566 | 56486 | 83.222.191.90 | 192.168.2.14 |
Jan 8, 2025 19:48:13.508140087 CET | 56486 | 13566 | 192.168.2.14 | 83.222.191.90 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 8, 2025 19:47:01.880095005 CET | 44855 | 53 | 192.168.2.14 | 8.8.8.8 |
Jan 8, 2025 19:47:01.889650106 CET | 53 | 44855 | 8.8.8.8 | 192.168.2.14 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 8, 2025 19:47:01.880095005 CET | 192.168.2.14 | 8.8.8.8 | 0xdc33 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 8, 2025 19:47:01.889650106 CET | 8.8.8.8 | 192.168.2.14 | 0xdc33 | No error (0) | 83.222.191.90 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.arm4.elf |
Arguments: | /tmp/Kloki.arm4.elf |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.arm4.elf |
Arguments: | - |
File size: | 4956856 bytes |
MD5 hash: | 5ebfcae4fe2471fcc5695c2394773ff1 |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/bin/gnome-shell |
Arguments: | /usr/bin/gnome-shell |
File size: | 23168 bytes |
MD5 hash: | da7a257239677622fe4b3a65972c9e87 |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gsd-print-notifications |
Arguments: | /usr/libexec/gsd-print-notifications |
File size: | 51840 bytes |
MD5 hash: | 71539698aa691718cee775d6b9450ae2 |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gsd-rfkill |
Arguments: | /usr/libexec/gsd-rfkill |
File size: | 51808 bytes |
MD5 hash: | 88a16a3c0aba1759358c06215ecfb5cc |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:47:00 |
Start date (UTC): | 08/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:47:01 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:47:01 |
Start date (UTC): | 08/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:47:11 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:47:11 |
Start date (UTC): | 08/01/2025 |
Path: | /lib/systemd/systemd-user-runtime-dir |
Arguments: | /lib/systemd/systemd-user-runtime-dir stop 127 |
File size: | 22672 bytes |
MD5 hash: | d55f4b0847f88131dbcfb07435178e54 |