Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Kloki.x86.elf

Overview

General Information

Sample name:Kloki.x86.elf
Analysis ID:1586171
MD5:180781bb607ae6bde186929e3570ef0a
SHA1:542d17f62e3372e220c4ace15a4480d78b4f4126
SHA256:76f4346fd91acdf7b9c37ba5738afb215fcc793c02ef46df8a22355fedb91e01
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586171
Start date and time:2025-01-08 19:46:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 3s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.x86.elf
Detection:MAL
Classification:mal60.spre.linELF@0/0@1/0
  • VT rate limit hit for: Kloki.x86.elf
Command:/tmp/Kloki.x86.elf
PID:5828
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5832, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 5832, Parent: 1498, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • sh (PID: 5854, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5854, Parent: 1498, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5855, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5855, Parent: 1498, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • sh (PID: 5856, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5856, Parent: 1498, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • gdm3 New Fork (PID: 5859, Parent: 1333)
  • Default (PID: 5859, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5860, Parent: 1333)
  • Default (PID: 5860, Parent: 1333, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5866, Parent: 1)
  • systemd-user-runtime-dir (PID: 5866, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
SourceRuleDescriptionAuthorStrings
Kloki.x86.elfLinux_Trojan_Mirai_b548632dunknownunknown
  • 0x62b9:$a: 00 0B 01 00 00 0E 00 00 00 18 03 00 7F E9 38 32 C9 4D 04 9A
SourceRuleDescriptionAuthorStrings
5830.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4840:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5830.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6cb2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5828.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4840:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5828.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6cb2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5828.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x9cec:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
Click to see the 5 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-08T19:47:27.694222+010025000362Misc Attack83.222.191.9013566192.168.2.1558060TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.x86.elfReversingLabs: Detection: 21%
Source: global trafficTCP traffic: 192.168.2.15:33866 -> 83.222.248.238:13566
Source: global trafficTCP traffic: 192.168.2.15:48440 -> 83.222.233.251:13566
Source: global trafficTCP traffic: 192.168.2.15:34070 -> 83.222.181.63:13566
Source: global trafficTCP traffic: 192.168.2.15:52784 -> 83.222.153.88:13566
Source: global trafficTCP traffic: 192.168.2.15:45148 -> 83.222.68.210:13566
Source: global trafficTCP traffic: 192.168.2.15:47030 -> 83.222.250.174:13566
Source: global trafficTCP traffic: 192.168.2.15:40580 -> 83.222.98.204:13566
Source: global trafficTCP traffic: 192.168.2.15:44250 -> 83.222.46.229:13566
Source: global trafficTCP traffic: 192.168.2.15:43086 -> 83.222.164.65:13566
Source: global trafficTCP traffic: 192.168.2.15:53218 -> 83.222.133.159:13566
Source: global trafficTCP traffic: 192.168.2.15:34054 -> 83.222.234.152:13566
Source: global trafficTCP traffic: 192.168.2.15:38990 -> 83.222.231.59:13566
Source: global trafficTCP traffic: 192.168.2.15:33442 -> 83.222.165.88:13566
Source: global trafficTCP traffic: 192.168.2.15:56662 -> 83.222.190.214:13566
Source: global trafficTCP traffic: 192.168.2.15:59716 -> 83.222.6.47:13566
Source: global trafficTCP traffic: 192.168.2.15:53406 -> 83.222.171.254:13566
Source: global trafficTCP traffic: 192.168.2.15:35544 -> 83.222.29.148:13566
Source: global trafficTCP traffic: 192.168.2.15:41550 -> 83.222.250.210:13566
Source: global trafficTCP traffic: 192.168.2.15:48744 -> 83.222.212.147:13566
Source: global trafficTCP traffic: 192.168.2.15:40142 -> 83.222.43.24:13566
Source: global trafficTCP traffic: 192.168.2.15:54910 -> 83.222.101.37:13566
Source: global trafficTCP traffic: 192.168.2.15:52830 -> 83.222.199.199:13566
Source: global trafficTCP traffic: 192.168.2.15:32864 -> 83.222.241.245:13566
Source: global trafficTCP traffic: 192.168.2.15:47822 -> 83.222.172.149:13566
Source: global trafficTCP traffic: 192.168.2.15:46546 -> 83.222.55.50:13566
Source: global trafficTCP traffic: 192.168.2.15:47342 -> 83.222.52.33:13566
Source: global trafficTCP traffic: 192.168.2.15:55226 -> 83.222.202.242:13566
Source: global trafficTCP traffic: 192.168.2.15:51280 -> 83.222.247.177:13566
Source: global trafficTCP traffic: 192.168.2.15:59548 -> 83.222.46.156:13566
Source: global trafficTCP traffic: 192.168.2.15:41144 -> 83.222.9.52:13566
Source: global trafficTCP traffic: 192.168.2.15:46988 -> 83.222.203.181:13566
Source: global trafficTCP traffic: 192.168.2.15:59126 -> 83.222.50.232:13566
Source: global trafficTCP traffic: 192.168.2.15:35092 -> 83.222.73.44:13566
Source: global trafficTCP traffic: 192.168.2.15:60010 -> 83.222.191.230:13566
Source: global trafficTCP traffic: 192.168.2.15:39898 -> 83.222.187.29:13566
Source: global trafficTCP traffic: 192.168.2.15:57576 -> 83.222.11.253:13566
Source: global trafficTCP traffic: 192.168.2.15:44316 -> 83.222.54.36:13566
Source: global trafficTCP traffic: 192.168.2.15:54522 -> 83.222.236.252:13566
Source: global trafficTCP traffic: 192.168.2.15:45778 -> 83.222.242.152:13566
Source: global trafficTCP traffic: 192.168.2.15:35794 -> 83.222.145.41:13566
Source: global trafficTCP traffic: 192.168.2.15:41056 -> 83.222.202.198:13566
Source: global trafficTCP traffic: 192.168.2.15:54346 -> 83.222.74.148:13566
Source: global trafficTCP traffic: 192.168.2.15:43454 -> 83.222.184.66:13566
Source: global trafficTCP traffic: 192.168.2.15:49900 -> 83.222.70.230:13566
Source: global trafficTCP traffic: 192.168.2.15:45918 -> 83.222.222.79:13566
Source: global trafficTCP traffic: 192.168.2.15:41408 -> 83.222.26.170:13566
Source: global trafficTCP traffic: 192.168.2.15:41158 -> 83.222.4.77:13566
Source: global trafficTCP traffic: 192.168.2.15:53764 -> 83.222.146.78:13566
Source: global trafficTCP traffic: 192.168.2.15:55242 -> 83.222.121.77:13566
Source: global trafficTCP traffic: 192.168.2.15:47552 -> 83.222.107.57:13566
Source: global trafficTCP traffic: 192.168.2.15:37706 -> 83.222.51.161:13566
Source: global trafficTCP traffic: 192.168.2.15:55974 -> 83.222.93.62:13566
Source: global trafficTCP traffic: 192.168.2.15:60770 -> 83.222.158.73:13566
Source: global trafficTCP traffic: 192.168.2.15:54220 -> 83.222.58.145:13566
Source: global trafficTCP traffic: 192.168.2.15:49172 -> 83.222.226.204:13566
Source: global trafficTCP traffic: 192.168.2.15:44004 -> 83.222.186.172:13566
Source: global trafficTCP traffic: 192.168.2.15:47718 -> 83.222.146.5:13566
Source: global trafficTCP traffic: 192.168.2.15:58000 -> 83.222.65.74:13566
Source: global trafficTCP traffic: 192.168.2.15:44186 -> 83.222.71.135:13566
Source: global trafficTCP traffic: 192.168.2.15:43358 -> 83.222.49.37:13566
Source: global trafficTCP traffic: 192.168.2.15:47042 -> 83.222.214.75:13566
Source: global trafficTCP traffic: 192.168.2.15:53540 -> 83.222.207.219:13566
Source: global trafficTCP traffic: 192.168.2.15:42426 -> 83.222.152.98:13566
Source: global trafficTCP traffic: 192.168.2.15:46994 -> 83.222.41.18:13566
Source: global trafficTCP traffic: 192.168.2.15:60286 -> 83.222.175.148:13566
Source: global trafficTCP traffic: 192.168.2.15:59196 -> 83.222.75.227:13566
Source: global trafficTCP traffic: 192.168.2.15:33894 -> 83.222.54.168:13566
Source: global trafficTCP traffic: 192.168.2.15:59212 -> 83.222.33.212:13566
Source: global trafficTCP traffic: 192.168.2.15:41816 -> 83.222.242.92:13566
Source: global trafficTCP traffic: 192.168.2.15:56660 -> 83.222.101.212:13566
Source: global trafficTCP traffic: 192.168.2.15:58060 -> 83.222.191.90:13566
Source: Network trafficSuricata IDS: 2500036 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 19 : 83.222.191.90:13566 -> 192.168.2.15:58060
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.248.238
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.233.251
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.181.63
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.88
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.68.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.250.174
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.98.204
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.46.229
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.164.65
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.133.159
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.234.152
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.231.59
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.88
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.190.214
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.6.47
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.254
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.29.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.250.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.212.147
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.43.24
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.101.37
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.199.199
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.241.245
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.149
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.55.50
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.33
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.202.242
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.247.177
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.46.156
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.9.52
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.203.181
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.50.232
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.44
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.230
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.29
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.11.253
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.54.36
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.236.252
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.242.152
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.145.41
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.202.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.74.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.70.230
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.222.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.26.170
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.4.77
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.146.78
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.121.77
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.107.57
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru

System Summary

barindex
Source: Kloki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b548632d Author: unknown
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 931, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 933, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1553, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1659, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1669, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1679, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 3157, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 3332, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 3483, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5813, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5832, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5854, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5855, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5856, result: successfulJump to behavior
Source: LOAD without section mappingsProgram segment: 0x8048000
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 931, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 933, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1553, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1659, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1669, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 1679, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 3157, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 3332, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 3483, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5813, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5832, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5854, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5855, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5831)SIGKILL sent: pid: 5856, result: successfulJump to behavior
Source: Kloki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b548632d reference_sample = 639d9d6da22e84fb6b6fc676a1c4cfd74a8ed546ce8661500ab2ef971242df07, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8b355e9c1150d43f52e6e9e052eda87ba158041f7b645f4f67c32dd549c09f28, id = b548632d-7916-444a-aa68-4b3e38251905, last_modified = 2021-09-16
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5828.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5830.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal60.spre.linELF@0/0@1/0
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/4177/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3241/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1333/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3235/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3234/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1615/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5814/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5673/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3255/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3253/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3252/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3251/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3250/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1623/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3249/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/764/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3368/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3246/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3488/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/766/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/800/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/888/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/802/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/803/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/804/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1867/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3407/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5840/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/490/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5838/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5839/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3379/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/777/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/658/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/779/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/812/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/933/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5833/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5834/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5835/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3419/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5836/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5837/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5850/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5851/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3310/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3275/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3274/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3273/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3394/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3272/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5849/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/782/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3303/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3027/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/789/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5841/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5842/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5843/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5844/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5845/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5846/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5847/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5848/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/5861/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3044/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3440/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/793/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/794/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3316/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/796/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3157/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3278/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3399/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3711/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3210/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3298/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3055/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3052/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3292/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3205/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3047/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3201/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/723/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/724/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3060/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1440/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3222/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3188/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3220/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3461/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3064/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3062/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3183/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/850/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1432/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3456/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1431/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3192/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3475/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3197/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3074/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/1445/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3469/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5830)File opened: /proc/3465/statusJump to behavior
Source: Kloki.x86.elfSubmission file: segment LOAD with 7.8815 entropy (max. 8.0)
Source: Kloki.x86.elfSubmission file: segment LOAD with 7.9483 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1586171 Sample: Kloki.x86.elf Startdate: 08/01/2025 Architecture: LINUX Score: 60 23 83.222.164.65, 13566, 43086 WAVENETLB Bulgaria 2->23 25 83.222.165.88, 13566, 33442 WAVENETLB Bulgaria 2->25 27 69 other IPs or domains 2->27 31 Malicious sample detected (through community Yara rule) 2->31 33 Multi AV Scanner detection for submitted file 2->33 8 Kloki.x86.elf 2->8         started        10 gnome-session-binary sh gsd-sharing 2->10         started        12 gnome-session-binary sh gnome-shell 2->12         started        14 5 other processes 2->14 signatures3 process4 process5 16 Kloki.x86.elf 8->16         started        process6 18 Kloki.x86.elf 16->18         started        21 Kloki.x86.elf 16->21         started        signatures7 29 Sample tries to kill multiple processes (SIGKILL) 18->29
SourceDetectionScannerLabelLink
Kloki.x86.elf21%ReversingLabsWin32.Trojan.Generic
Kloki.x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.70.230
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.43.24
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.121.77
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.55.50
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.46.156
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.242.152
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.145.41
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.6.47
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.202.242
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.158.73
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.54.36
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.98.204
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.234.152
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.247.177
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.152.98
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.242.92
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.29.148
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.101.37
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.46.229
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.54.168
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.212.147
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.58.145
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.73.44
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.199.199
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.175.148
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.171.254
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.165.88
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.4.77
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.74.148
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.33.212
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.107.57
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.214.75
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.75.227
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.250.174
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.233.251
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.250.210
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.146.78
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.65.74
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.51.161
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.191.230
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.172.149
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.93.62
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.101.212
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.11.253
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.52.33
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.164.65
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.186.172
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.248.238
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.184.66
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.50.232
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.133.159
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.187.29
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.241.245
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.71.135
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.153.88
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.49.37
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.9.52
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.203.181
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.236.252
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.41.18
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.207.219
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.181.63
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.190.214
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.202.198
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.68.210
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.222.79
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.146.5
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.226.204
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.26.170
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.231.59
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    secure-network-rebirthltd.ruKloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUKloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.64.159
    skid.x86.elfGet hashmaliciousMoobotBrowse
    • 83.222.64.191
    XfUkJyh9A3.elfGet hashmaliciousMiraiBrowse
    • 37.209.228.199
    nSQgTX0uEc.dllGet hashmaliciousWannacryBrowse
    • 213.141.249.89
    e7N7Kz9BarGet hashmaliciousUnknownBrowse
    • 37.209.226.155
    G2JJHi7jyhGet hashmaliciousMiraiBrowse
    • 212.75.151.147
    KiDRFl2BaNGet hashmaliciousMiraiBrowse
    • 212.75.129.46
    UbjnMZrdW8Get hashmaliciousMiraiBrowse
    • 37.209.228.197
    vEjGHdNRFjGet hashmaliciousGafgyt MiraiBrowse
    • 37.209.228.196
    6LmZoebUdAGet hashmaliciousMiraiBrowse
    • 37.209.236.25
    LOL-ASluLUKloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.38.250
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.39.173
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.34.98
    jew.x86.elfGet hashmaliciousUnknownBrowse
    • 85.10.122.249
    ppc.elfGet hashmaliciousMiraiBrowse
    • 85.10.122.239
    sh4.elfGet hashmaliciousMirai, MoobotBrowse
    • 85.10.122.206
    debug.dbg.elfGet hashmaliciousMirai, GafgytBrowse
    • 85.10.122.235
    sh4.elfGet hashmaliciousUnknownBrowse
    • 85.10.122.213
    wlcougQfbn.elfGet hashmaliciousUnknownBrowse
    • 85.10.122.243
    J8hytxrLBJ.elfGet hashmaliciousMiraiBrowse
    • 85.10.122.212
    MNOGOBYTE-ASMoscowRussiaRUKloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.110.86
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.112.137
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.121.44
    Hilix.m68k.elfGet hashmaliciousMiraiBrowse
    • 45.87.110.254
    arm6.elfGet hashmaliciousUnknownBrowse
    • 83.222.115.109
    https://santa-secret.ru/api/verify?a=NjgyODEwNCw1bWluOHE2MHpuX3J1LC9hY2NvdW50L2JveGVzLHZsYWRpbWlyLmdsdXNoZW5rb0Bob2NobGFuZC5ydSwyNDE0MTYzMg==Get hashmaliciousUnknownBrowse
    • 83.222.104.70
    mips.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 77.220.164.91
    i686.elfGet hashmaliciousUnknownBrowse
    • 83.222.115.100
    mpsl.elfGet hashmaliciousMiraiBrowse
    • 146.255.196.1
    sh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
    • 146.255.202.89
    LOL-ASluLUKloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.34.98
    jew.x86.elfGet hashmaliciousUnknownBrowse
    • 85.10.122.249
    ppc.elfGet hashmaliciousMiraiBrowse
    • 85.10.122.239
    sh4.elfGet hashmaliciousMirai, MoobotBrowse
    • 85.10.122.206
    debug.dbg.elfGet hashmaliciousMirai, GafgytBrowse
    • 85.10.122.235
    sh4.elfGet hashmaliciousUnknownBrowse
    • 85.10.122.213
    wlcougQfbn.elfGet hashmaliciousUnknownBrowse
    • 85.10.122.243
    J8hytxrLBJ.elfGet hashmaliciousMiraiBrowse
    • 85.10.122.212
    u3FxQf1X9v.elfGet hashmaliciousMiraiBrowse
    • 85.10.122.211
    9BrsO1bmfY.elfGet hashmaliciousMiraiBrowse
    • 185.6.235.73
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
    Entropy (8bit):7.945227559697287
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:Kloki.x86.elf
    File size:30'472 bytes
    MD5:180781bb607ae6bde186929e3570ef0a
    SHA1:542d17f62e3372e220c4ace15a4480d78b4f4126
    SHA256:76f4346fd91acdf7b9c37ba5738afb215fcc793c02ef46df8a22355fedb91e01
    SHA512:93734013ec6bbc30abc663cb49f8d5f617346984c93e73c0b418795d701977a476a6835d375493034db0e634ce956c8ab6f83be438923ef316ef27c3347683aa
    SSDEEP:768:F/DkhFYywTBFgoTCJCHjJ2WlfxSkbZnbcuyD7UoURb:Fr8YzdFjxj9fRZnouy8J
    TLSH:44D2F15CA1D86864D05F917B261EB40A89A0B90DE6E8C9BBCDFC343782D07E4792961F
    File Content Preview:.ELF........................4...........4. ...(......................................................v...v..........Q.td.............................j=.sfgaD...................S..........?..k.I/.j....\.d*nlz.g...S.......c.J...RE..V.r.V.}.=.&.d..j.jQ......

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Intel 80386
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - Linux
    ABI Version:0
    Entry Point Address:0x805f3d8
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:40
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80480000x80480000x10000x107c07.88150x6RW 0x1000
    LOAD0x00x80590000x80590000x76110x76117.94830x5R E0x1000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
    2025-01-08T19:47:27.694222+01002500036ET COMPROMISED Known Compromised or Hostile Host Traffic group 19283.222.191.9013566192.168.2.1558060TCP
    TimestampSource PortDest PortSource IPDest IP
    Jan 8, 2025 19:47:27.663212061 CET3386613566192.168.2.1583.222.248.238
    Jan 8, 2025 19:47:27.663217068 CET4844013566192.168.2.1583.222.233.251
    Jan 8, 2025 19:47:27.663228035 CET3407013566192.168.2.1583.222.181.63
    Jan 8, 2025 19:47:27.663233042 CET5278413566192.168.2.1583.222.153.88
    Jan 8, 2025 19:47:27.663299084 CET4514813566192.168.2.1583.222.68.210
    Jan 8, 2025 19:47:27.663309097 CET4703013566192.168.2.1583.222.250.174
    Jan 8, 2025 19:47:27.663325071 CET4058013566192.168.2.1583.222.98.204
    Jan 8, 2025 19:47:27.663330078 CET4425013566192.168.2.1583.222.46.229
    Jan 8, 2025 19:47:27.663343906 CET4308613566192.168.2.1583.222.164.65
    Jan 8, 2025 19:47:27.663361073 CET5321813566192.168.2.1583.222.133.159
    Jan 8, 2025 19:47:27.663366079 CET3405413566192.168.2.1583.222.234.152
    Jan 8, 2025 19:47:27.663419008 CET3899013566192.168.2.1583.222.231.59
    Jan 8, 2025 19:47:27.663423061 CET3344213566192.168.2.1583.222.165.88
    Jan 8, 2025 19:47:27.663429022 CET5666213566192.168.2.1583.222.190.214
    Jan 8, 2025 19:47:27.663435936 CET5971613566192.168.2.1583.222.6.47
    Jan 8, 2025 19:47:27.663446903 CET5340613566192.168.2.1583.222.171.254
    Jan 8, 2025 19:47:27.663460016 CET3554413566192.168.2.1583.222.29.148
    Jan 8, 2025 19:47:27.663479090 CET4155013566192.168.2.1583.222.250.210
    Jan 8, 2025 19:47:27.663506985 CET4874413566192.168.2.1583.222.212.147
    Jan 8, 2025 19:47:27.663522005 CET4014213566192.168.2.1583.222.43.24
    Jan 8, 2025 19:47:27.663930893 CET5491013566192.168.2.1583.222.101.37
    Jan 8, 2025 19:47:27.663939953 CET5283013566192.168.2.1583.222.199.199
    Jan 8, 2025 19:47:27.663960934 CET3286413566192.168.2.1583.222.241.245
    Jan 8, 2025 19:47:27.663964987 CET4782213566192.168.2.1583.222.172.149
    Jan 8, 2025 19:47:27.663975954 CET4654613566192.168.2.1583.222.55.50
    Jan 8, 2025 19:47:27.663986921 CET4734213566192.168.2.1583.222.52.33
    Jan 8, 2025 19:47:27.664005041 CET5522613566192.168.2.1583.222.202.242
    Jan 8, 2025 19:47:27.664020061 CET5128013566192.168.2.1583.222.247.177
    Jan 8, 2025 19:47:27.664021969 CET5954813566192.168.2.1583.222.46.156
    Jan 8, 2025 19:47:27.664038897 CET4114413566192.168.2.1583.222.9.52
    Jan 8, 2025 19:47:27.664042950 CET4698813566192.168.2.1583.222.203.181
    Jan 8, 2025 19:47:27.664057016 CET5912613566192.168.2.1583.222.50.232
    Jan 8, 2025 19:47:27.664072037 CET3509213566192.168.2.1583.222.73.44
    Jan 8, 2025 19:47:27.664139986 CET6001013566192.168.2.1583.222.191.230
    Jan 8, 2025 19:47:27.664139986 CET3989813566192.168.2.1583.222.187.29
    Jan 8, 2025 19:47:27.664139986 CET5757613566192.168.2.1583.222.11.253
    Jan 8, 2025 19:47:27.664144039 CET4431613566192.168.2.1583.222.54.36
    Jan 8, 2025 19:47:27.664158106 CET5452213566192.168.2.1583.222.236.252
    Jan 8, 2025 19:47:27.664176941 CET4577813566192.168.2.1583.222.242.152
    Jan 8, 2025 19:47:27.664181948 CET3579413566192.168.2.1583.222.145.41
    Jan 8, 2025 19:47:27.664236069 CET4105613566192.168.2.1583.222.202.198
    Jan 8, 2025 19:47:27.664243937 CET5434613566192.168.2.1583.222.74.148
    Jan 8, 2025 19:47:27.664259911 CET4345413566192.168.2.1583.222.184.66
    Jan 8, 2025 19:47:27.664264917 CET4990013566192.168.2.1583.222.70.230
    Jan 8, 2025 19:47:27.664283991 CET4591813566192.168.2.1583.222.222.79
    Jan 8, 2025 19:47:27.664294004 CET4140813566192.168.2.1583.222.26.170
    Jan 8, 2025 19:47:27.664308071 CET4115813566192.168.2.1583.222.4.77
    Jan 8, 2025 19:47:27.664316893 CET5376413566192.168.2.1583.222.146.78
    Jan 8, 2025 19:47:27.664351940 CET5524213566192.168.2.1583.222.121.77
    Jan 8, 2025 19:47:27.664361954 CET4755213566192.168.2.1583.222.107.57
    Jan 8, 2025 19:47:27.664374113 CET3770613566192.168.2.1583.222.51.161
    Jan 8, 2025 19:47:27.664385080 CET5597413566192.168.2.1583.222.93.62
    Jan 8, 2025 19:47:27.664403915 CET6077013566192.168.2.1583.222.158.73
    Jan 8, 2025 19:47:27.664414883 CET5422013566192.168.2.1583.222.58.145
    Jan 8, 2025 19:47:27.664427996 CET4917213566192.168.2.1583.222.226.204
    Jan 8, 2025 19:47:27.664468050 CET4400413566192.168.2.1583.222.186.172
    Jan 8, 2025 19:47:27.664473057 CET4771813566192.168.2.1583.222.146.5
    Jan 8, 2025 19:47:27.664488077 CET5800013566192.168.2.1583.222.65.74
    Jan 8, 2025 19:47:27.664498091 CET4418613566192.168.2.1583.222.71.135
    Jan 8, 2025 19:47:27.664518118 CET4335813566192.168.2.1583.222.49.37
    Jan 8, 2025 19:47:27.664532900 CET4704213566192.168.2.1583.222.214.75
    Jan 8, 2025 19:47:27.664545059 CET5354013566192.168.2.1583.222.207.219
    Jan 8, 2025 19:47:27.664760113 CET4242613566192.168.2.1583.222.152.98
    Jan 8, 2025 19:47:27.664777040 CET4699413566192.168.2.1583.222.41.18
    Jan 8, 2025 19:47:27.664788008 CET6028613566192.168.2.1583.222.175.148
    Jan 8, 2025 19:47:27.664804935 CET5919613566192.168.2.1583.222.75.227
    Jan 8, 2025 19:47:27.664820910 CET3389413566192.168.2.1583.222.54.168
    Jan 8, 2025 19:47:27.664824963 CET5921213566192.168.2.1583.222.33.212
    Jan 8, 2025 19:47:27.664839029 CET4181613566192.168.2.1583.222.242.92
    Jan 8, 2025 19:47:27.664853096 CET5666013566192.168.2.1583.222.101.212
    Jan 8, 2025 19:47:27.668056965 CET135664844083.222.233.251192.168.2.15
    Jan 8, 2025 19:47:27.668112040 CET4844013566192.168.2.1583.222.233.251
    Jan 8, 2025 19:47:27.668275118 CET135665278483.222.153.88192.168.2.15
    Jan 8, 2025 19:47:27.668287039 CET135663407083.222.181.63192.168.2.15
    Jan 8, 2025 19:47:27.668297052 CET135663386683.222.248.238192.168.2.15
    Jan 8, 2025 19:47:27.668304920 CET5278413566192.168.2.1583.222.153.88
    Jan 8, 2025 19:47:27.668308020 CET135664514883.222.68.210192.168.2.15
    Jan 8, 2025 19:47:27.668318033 CET3407013566192.168.2.1583.222.181.63
    Jan 8, 2025 19:47:27.668319941 CET135664703083.222.250.174192.168.2.15
    Jan 8, 2025 19:47:27.668327093 CET3386613566192.168.2.1583.222.248.238
    Jan 8, 2025 19:47:27.668330908 CET135664058083.222.98.204192.168.2.15
    Jan 8, 2025 19:47:27.668339014 CET4514813566192.168.2.1583.222.68.210
    Jan 8, 2025 19:47:27.668342113 CET135664425083.222.46.229192.168.2.15
    Jan 8, 2025 19:47:27.668344021 CET4703013566192.168.2.1583.222.250.174
    Jan 8, 2025 19:47:27.668353081 CET135664308683.222.164.65192.168.2.15
    Jan 8, 2025 19:47:27.668356895 CET4058013566192.168.2.1583.222.98.204
    Jan 8, 2025 19:47:27.668361902 CET135663405483.222.234.152192.168.2.15
    Jan 8, 2025 19:47:27.668365955 CET4425013566192.168.2.1583.222.46.229
    Jan 8, 2025 19:47:27.668373108 CET135665321883.222.133.159192.168.2.15
    Jan 8, 2025 19:47:27.668375015 CET4308613566192.168.2.1583.222.164.65
    Jan 8, 2025 19:47:27.668387890 CET3405413566192.168.2.1583.222.234.152
    Jan 8, 2025 19:47:27.668401003 CET5321813566192.168.2.1583.222.133.159
    Jan 8, 2025 19:47:27.673073053 CET135663344283.222.165.88192.168.2.15
    Jan 8, 2025 19:47:27.673083067 CET135663899083.222.231.59192.168.2.15
    Jan 8, 2025 19:47:27.673094034 CET135665666283.222.190.214192.168.2.15
    Jan 8, 2025 19:47:27.673110962 CET3344213566192.168.2.1583.222.165.88
    Jan 8, 2025 19:47:27.673114061 CET3899013566192.168.2.1583.222.231.59
    Jan 8, 2025 19:47:27.673115015 CET135665971683.222.6.47192.168.2.15
    Jan 8, 2025 19:47:27.673125982 CET135665340683.222.171.254192.168.2.15
    Jan 8, 2025 19:47:27.673126936 CET5666213566192.168.2.1583.222.190.214
    Jan 8, 2025 19:47:27.673136950 CET135663554483.222.29.148192.168.2.15
    Jan 8, 2025 19:47:27.673144102 CET5971613566192.168.2.1583.222.6.47
    Jan 8, 2025 19:47:27.673147917 CET135664155083.222.250.210192.168.2.15
    Jan 8, 2025 19:47:27.673155069 CET5340613566192.168.2.1583.222.171.254
    Jan 8, 2025 19:47:27.673160076 CET135664874483.222.212.147192.168.2.15
    Jan 8, 2025 19:47:27.673162937 CET3554413566192.168.2.1583.222.29.148
    Jan 8, 2025 19:47:27.673168898 CET135664014283.222.43.24192.168.2.15
    Jan 8, 2025 19:47:27.673177958 CET4155013566192.168.2.1583.222.250.210
    Jan 8, 2025 19:47:27.673178911 CET135665491083.222.101.37192.168.2.15
    Jan 8, 2025 19:47:27.673187971 CET4874413566192.168.2.1583.222.212.147
    Jan 8, 2025 19:47:27.673187971 CET135665283083.222.199.199192.168.2.15
    Jan 8, 2025 19:47:27.673192024 CET4014213566192.168.2.1583.222.43.24
    Jan 8, 2025 19:47:27.673202038 CET5491013566192.168.2.1583.222.101.37
    Jan 8, 2025 19:47:27.673207045 CET135663286483.222.241.245192.168.2.15
    Jan 8, 2025 19:47:27.673213959 CET5283013566192.168.2.1583.222.199.199
    Jan 8, 2025 19:47:27.673216105 CET135664782283.222.172.149192.168.2.15
    Jan 8, 2025 19:47:27.673224926 CET135664654683.222.55.50192.168.2.15
    Jan 8, 2025 19:47:27.673233032 CET3286413566192.168.2.1583.222.241.245
    Jan 8, 2025 19:47:27.673233986 CET135664734283.222.52.33192.168.2.15
    Jan 8, 2025 19:47:27.673240900 CET4782213566192.168.2.1583.222.172.149
    Jan 8, 2025 19:47:27.673244953 CET135665522683.222.202.242192.168.2.15
    Jan 8, 2025 19:47:27.673249960 CET4654613566192.168.2.1583.222.55.50
    Jan 8, 2025 19:47:27.673254967 CET135665128083.222.247.177192.168.2.15
    Jan 8, 2025 19:47:27.673264027 CET135665954883.222.46.156192.168.2.15
    Jan 8, 2025 19:47:27.673264980 CET4734213566192.168.2.1583.222.52.33
    Jan 8, 2025 19:47:27.673274040 CET5522613566192.168.2.1583.222.202.242
    Jan 8, 2025 19:47:27.673274040 CET135664114483.222.9.52192.168.2.15
    Jan 8, 2025 19:47:27.673281908 CET5128013566192.168.2.1583.222.247.177
    Jan 8, 2025 19:47:27.673285007 CET135664698883.222.203.181192.168.2.15
    Jan 8, 2025 19:47:27.673289061 CET5954813566192.168.2.1583.222.46.156
    Jan 8, 2025 19:47:27.673295021 CET135665912683.222.50.232192.168.2.15
    Jan 8, 2025 19:47:27.673300028 CET4114413566192.168.2.1583.222.9.52
    Jan 8, 2025 19:47:27.673306942 CET135663509283.222.73.44192.168.2.15
    Jan 8, 2025 19:47:27.673309088 CET4698813566192.168.2.1583.222.203.181
    Jan 8, 2025 19:47:27.673316956 CET5912613566192.168.2.1583.222.50.232
    Jan 8, 2025 19:47:27.673331976 CET3509213566192.168.2.1583.222.73.44
    Jan 8, 2025 19:47:27.673557997 CET135666001083.222.191.230192.168.2.15
    Jan 8, 2025 19:47:27.673568010 CET135663989883.222.187.29192.168.2.15
    Jan 8, 2025 19:47:27.673578978 CET135664431683.222.54.36192.168.2.15
    Jan 8, 2025 19:47:27.673587084 CET6001013566192.168.2.1583.222.191.230
    Jan 8, 2025 19:47:27.673588991 CET135665757683.222.11.253192.168.2.15
    Jan 8, 2025 19:47:27.673593044 CET3989813566192.168.2.1583.222.187.29
    Jan 8, 2025 19:47:27.673599958 CET135665452283.222.236.252192.168.2.15
    Jan 8, 2025 19:47:27.673605919 CET4431613566192.168.2.1583.222.54.36
    Jan 8, 2025 19:47:27.673609972 CET135664577883.222.242.152192.168.2.15
    Jan 8, 2025 19:47:27.673610926 CET5757613566192.168.2.1583.222.11.253
    Jan 8, 2025 19:47:27.673619032 CET135663579483.222.145.41192.168.2.15
    Jan 8, 2025 19:47:27.673624039 CET5452213566192.168.2.1583.222.236.252
    Jan 8, 2025 19:47:27.673635960 CET4577813566192.168.2.1583.222.242.152
    Jan 8, 2025 19:47:27.673638105 CET135664105683.222.202.198192.168.2.15
    Jan 8, 2025 19:47:27.673640966 CET3579413566192.168.2.1583.222.145.41
    Jan 8, 2025 19:47:27.673648119 CET135665434683.222.74.148192.168.2.15
    Jan 8, 2025 19:47:27.673657894 CET135664345483.222.184.66192.168.2.15
    Jan 8, 2025 19:47:27.673665047 CET4105613566192.168.2.1583.222.202.198
    Jan 8, 2025 19:47:27.673667908 CET135664990083.222.70.230192.168.2.15
    Jan 8, 2025 19:47:27.673671961 CET5434613566192.168.2.1583.222.74.148
    Jan 8, 2025 19:47:27.673677921 CET135664591883.222.222.79192.168.2.15
    Jan 8, 2025 19:47:27.673688889 CET135664140883.222.26.170192.168.2.15
    Jan 8, 2025 19:47:27.673688889 CET4345413566192.168.2.1583.222.184.66
    Jan 8, 2025 19:47:27.673698902 CET135664115883.222.4.77192.168.2.15
    Jan 8, 2025 19:47:27.673708916 CET135665376483.222.146.78192.168.2.15
    Jan 8, 2025 19:47:27.673710108 CET4990013566192.168.2.1583.222.70.230
    Jan 8, 2025 19:47:27.673712969 CET4140813566192.168.2.1583.222.26.170
    Jan 8, 2025 19:47:27.673719883 CET135665524283.222.121.77192.168.2.15
    Jan 8, 2025 19:47:27.673722029 CET4591813566192.168.2.1583.222.222.79
    Jan 8, 2025 19:47:27.673728943 CET135664755283.222.107.57192.168.2.15
    Jan 8, 2025 19:47:27.673727036 CET4115813566192.168.2.1583.222.4.77
    Jan 8, 2025 19:47:27.673727036 CET5376413566192.168.2.1583.222.146.78
    Jan 8, 2025 19:47:27.673738956 CET135663770683.222.51.161192.168.2.15
    Jan 8, 2025 19:47:27.673741102 CET5524213566192.168.2.1583.222.121.77
    Jan 8, 2025 19:47:27.673747063 CET135665597483.222.93.62192.168.2.15
    Jan 8, 2025 19:47:27.673752069 CET4755213566192.168.2.1583.222.107.57
    Jan 8, 2025 19:47:27.673757076 CET135666077083.222.158.73192.168.2.15
    Jan 8, 2025 19:47:27.673760891 CET3770613566192.168.2.1583.222.51.161
    Jan 8, 2025 19:47:27.673765898 CET135665422083.222.58.145192.168.2.15
    Jan 8, 2025 19:47:27.673768044 CET5597413566192.168.2.1583.222.93.62
    Jan 8, 2025 19:47:27.673775911 CET135664917283.222.226.204192.168.2.15
    Jan 8, 2025 19:47:27.673777103 CET6077013566192.168.2.1583.222.158.73
    Jan 8, 2025 19:47:27.673784971 CET5422013566192.168.2.1583.222.58.145
    Jan 8, 2025 19:47:27.673811913 CET4917213566192.168.2.1583.222.226.204
    Jan 8, 2025 19:47:27.673928976 CET135664400483.222.186.172192.168.2.15
    Jan 8, 2025 19:47:27.673938990 CET135664771883.222.146.5192.168.2.15
    Jan 8, 2025 19:47:27.673948050 CET135665800083.222.65.74192.168.2.15
    Jan 8, 2025 19:47:27.673958063 CET135664418683.222.71.135192.168.2.15
    Jan 8, 2025 19:47:27.673960924 CET4771813566192.168.2.1583.222.146.5
    Jan 8, 2025 19:47:27.673966885 CET135664335883.222.49.37192.168.2.15
    Jan 8, 2025 19:47:27.673969030 CET4400413566192.168.2.1583.222.186.172
    Jan 8, 2025 19:47:27.673970938 CET5800013566192.168.2.1583.222.65.74
    Jan 8, 2025 19:47:27.673978090 CET135664704283.222.214.75192.168.2.15
    Jan 8, 2025 19:47:27.673989058 CET4418613566192.168.2.1583.222.71.135
    Jan 8, 2025 19:47:27.673991919 CET4335813566192.168.2.1583.222.49.37
    Jan 8, 2025 19:47:27.673995972 CET135665354083.222.207.219192.168.2.15
    Jan 8, 2025 19:47:27.674004078 CET4704213566192.168.2.1583.222.214.75
    Jan 8, 2025 19:47:27.674005985 CET135664242683.222.152.98192.168.2.15
    Jan 8, 2025 19:47:27.674015999 CET135664699483.222.41.18192.168.2.15
    Jan 8, 2025 19:47:27.674015999 CET5354013566192.168.2.1583.222.207.219
    Jan 8, 2025 19:47:27.674026012 CET135666028683.222.175.148192.168.2.15
    Jan 8, 2025 19:47:27.674030066 CET4242613566192.168.2.1583.222.152.98
    Jan 8, 2025 19:47:27.674036980 CET135665919683.222.75.227192.168.2.15
    Jan 8, 2025 19:47:27.674040079 CET4699413566192.168.2.1583.222.41.18
    Jan 8, 2025 19:47:27.674046040 CET135663389483.222.54.168192.168.2.15
    Jan 8, 2025 19:47:27.674052000 CET6028613566192.168.2.1583.222.175.148
    Jan 8, 2025 19:47:27.674057007 CET135665921283.222.33.212192.168.2.15
    Jan 8, 2025 19:47:27.674067020 CET5919613566192.168.2.1583.222.75.227
    Jan 8, 2025 19:47:27.674078941 CET3389413566192.168.2.1583.222.54.168
    Jan 8, 2025 19:47:27.674098969 CET135664181683.222.242.92192.168.2.15
    Jan 8, 2025 19:47:27.674109936 CET135665666083.222.101.212192.168.2.15
    Jan 8, 2025 19:47:27.674113035 CET5921213566192.168.2.1583.222.33.212
    Jan 8, 2025 19:47:27.674122095 CET4181613566192.168.2.1583.222.242.92
    Jan 8, 2025 19:47:27.674139023 CET5666013566192.168.2.1583.222.101.212
    Jan 8, 2025 19:47:27.689464092 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:47:27.694221973 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:47:27.694312096 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:47:27.694312096 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:47:27.699110031 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:47:27.699157000 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:47:27.703958988 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:47:37.704150915 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:47:37.709851027 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:47:37.908284903 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:47:37.908356905 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:47:38.271790028 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:47:38.271847010 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:48:38.322736979 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:48:38.327615976 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:48:38.524960041 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:48:38.525135040 CET5806013566192.168.2.1583.222.191.90
    Jan 8, 2025 19:48:39.272656918 CET135665806083.222.191.90192.168.2.15
    Jan 8, 2025 19:48:39.272800922 CET5806013566192.168.2.1583.222.191.90
    TimestampSource PortDest PortSource IPDest IP
    Jan 8, 2025 19:47:27.664890051 CET5583953192.168.2.158.8.8.8
    Jan 8, 2025 19:47:27.686042070 CET53558398.8.8.8192.168.2.15
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jan 8, 2025 19:47:27.664890051 CET192.168.2.158.8.8.80x6699Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jan 8, 2025 19:47:27.686042070 CET8.8.8.8192.168.2.150x6699No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:/tmp/Kloki.x86.elf
    File size:30472 bytes
    MD5 hash:180781bb607ae6bde186929e3570ef0a

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:-
    File size:30472 bytes
    MD5 hash:180781bb607ae6bde186929e3570ef0a

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:-
    File size:30472 bytes
    MD5 hash:180781bb607ae6bde186929e3570ef0a

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:-
    File size:30472 bytes
    MD5 hash:180781bb607ae6bde186929e3570ef0a

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-sharing
    Arguments:/usr/libexec/gsd-sharing
    File size:35424 bytes
    MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/bin/gnome-shell
    Arguments:/usr/bin/gnome-shell
    File size:23168 bytes
    MD5 hash:da7a257239677622fe4b3a65972c9e87

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-rfkill
    Arguments:/usr/libexec/gsd-rfkill
    File size:51808 bytes
    MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:47:26
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-print-notifications
    Arguments:/usr/libexec/gsd-print-notifications
    File size:51840 bytes
    MD5 hash:71539698aa691718cee775d6b9450ae2

    Start time (UTC):18:47:27
    Start date (UTC):08/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:47:27
    Start date (UTC):08/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:47:27
    Start date (UTC):08/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:47:27
    Start date (UTC):08/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:47:37
    Start date (UTC):08/01/2025
    Path:/usr/lib/systemd/systemd
    Arguments:-
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    Start time (UTC):18:47:37
    Start date (UTC):08/01/2025
    Path:/lib/systemd/systemd-user-runtime-dir
    Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
    File size:22672 bytes
    MD5 hash:d55f4b0847f88131dbcfb07435178e54