Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Kloki.x86_64.elf

Overview

General Information

Sample name:Kloki.x86_64.elf
Analysis ID:1586172
MD5:87a674a1cd303c58d819270cddd7fc63
SHA1:c3d59d459d603e8affd3450090e2b1a9619ace5a
SHA256:192dc6e6726aaa9cce13eaaf812b070d7aa9b4824c2b1dee17e680e3d75284f7
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586172
Start date and time:2025-01-08 19:50:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.x86_64.elf
Detection:MAL
Classification:mal64.spre.linELF@0/0@1/0
  • VT rate limit hit for: Kloki.x86_64.elf
Command:/tmp/Kloki.x86_64.elf
PID:5514
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5518, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 5518, Parent: 1383, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • sh (PID: 5538, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5538, Parent: 1383, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5540, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5540, Parent: 1383, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • sh (PID: 5541, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5541, Parent: 1383, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • gdm3 New Fork (PID: 5542, Parent: 1289)
  • Default (PID: 5542, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5545, Parent: 1289)
  • Default (PID: 5545, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5551, Parent: 1)
  • systemd-user-runtime-dir (PID: 5551, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
SourceRuleDescriptionAuthorStrings
5516.1.0000000000400000.000000000040f000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
  • 0x9654:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
5516.1.0000000000400000.000000000040f000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
  • 0x9e43:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
5516.1.0000000000400000.000000000040f000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
  • 0x779e:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x78d4:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
5516.1.0000000000400000.000000000040f000.r-x.sdmpLinux_Trojan_Gafgyt_d996d335unknownunknown
  • 0xc74e:$a: D0 EB 0F 40 38 37 75 04 48 89 F8 C3 49 FF C8 48 FF C7 4D 85 C0
5516.1.0000000000400000.000000000040f000.r-x.sdmpLinux_Trojan_Gafgyt_620087b9unknownunknown
  • 0x9a03:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
Click to see the 13 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-08T19:51:05.258590+010025000362Misc Attack83.222.191.9013566192.168.2.1456566TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.x86_64.elfReversingLabs: Detection: 18%
Source: Kloki.x86_64.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.14:54890 -> 83.222.176.215:13566
Source: global trafficTCP traffic: 192.168.2.14:40004 -> 83.222.142.119:13566
Source: global trafficTCP traffic: 192.168.2.14:54804 -> 83.222.168.232:13566
Source: global trafficTCP traffic: 192.168.2.14:57106 -> 83.222.84.153:13566
Source: global trafficTCP traffic: 192.168.2.14:49962 -> 83.222.207.35:13566
Source: global trafficTCP traffic: 192.168.2.14:32964 -> 83.222.137.76:13566
Source: global trafficTCP traffic: 192.168.2.14:56292 -> 83.222.180.208:13566
Source: global trafficTCP traffic: 192.168.2.14:33584 -> 83.222.72.118:13566
Source: global trafficTCP traffic: 192.168.2.14:57460 -> 83.222.77.71:13566
Source: global trafficTCP traffic: 192.168.2.14:57814 -> 83.222.30.102:13566
Source: global trafficTCP traffic: 192.168.2.14:51144 -> 83.222.253.191:13566
Source: global trafficTCP traffic: 192.168.2.14:40460 -> 83.222.247.99:13566
Source: global trafficTCP traffic: 192.168.2.14:33462 -> 83.222.78.255:13566
Source: global trafficTCP traffic: 192.168.2.14:59430 -> 83.222.183.191:13566
Source: global trafficTCP traffic: 192.168.2.14:47846 -> 83.222.20.159:13566
Source: global trafficTCP traffic: 192.168.2.14:59784 -> 83.222.102.197:13566
Source: global trafficTCP traffic: 192.168.2.14:46378 -> 83.222.119.244:13566
Source: global trafficTCP traffic: 192.168.2.14:33394 -> 83.222.60.31:13566
Source: global trafficTCP traffic: 192.168.2.14:38040 -> 83.222.220.144:13566
Source: global trafficTCP traffic: 192.168.2.14:53294 -> 83.222.185.171:13566
Source: global trafficTCP traffic: 192.168.2.14:40246 -> 83.222.180.66:13566
Source: global trafficTCP traffic: 192.168.2.14:39430 -> 83.222.248.104:13566
Source: global trafficTCP traffic: 192.168.2.14:33800 -> 83.222.18.64:13566
Source: global trafficTCP traffic: 192.168.2.14:38118 -> 83.222.222.96:13566
Source: global trafficTCP traffic: 192.168.2.14:39634 -> 83.222.135.253:13566
Source: global trafficTCP traffic: 192.168.2.14:55108 -> 83.222.198.133:13566
Source: global trafficTCP traffic: 192.168.2.14:42466 -> 83.222.188.189:13566
Source: global trafficTCP traffic: 192.168.2.14:54044 -> 83.222.232.11:13566
Source: global trafficTCP traffic: 192.168.2.14:56670 -> 83.222.188.159:13566
Source: global trafficTCP traffic: 192.168.2.14:59214 -> 83.222.202.209:13566
Source: global trafficTCP traffic: 192.168.2.14:58820 -> 83.222.63.48:13566
Source: global trafficTCP traffic: 192.168.2.14:33604 -> 83.222.150.182:13566
Source: global trafficTCP traffic: 192.168.2.14:51704 -> 83.222.36.210:13566
Source: global trafficTCP traffic: 192.168.2.14:44798 -> 83.222.213.1:13566
Source: global trafficTCP traffic: 192.168.2.14:49278 -> 83.222.99.142:13566
Source: global trafficTCP traffic: 192.168.2.14:53028 -> 83.222.172.23:13566
Source: global trafficTCP traffic: 192.168.2.14:53876 -> 83.222.209.164:13566
Source: global trafficTCP traffic: 192.168.2.14:41084 -> 83.222.127.227:13566
Source: global trafficTCP traffic: 192.168.2.14:46988 -> 83.222.229.93:13566
Source: global trafficTCP traffic: 192.168.2.14:57528 -> 83.222.67.108:13566
Source: global trafficTCP traffic: 192.168.2.14:58522 -> 83.222.90.10:13566
Source: global trafficTCP traffic: 192.168.2.14:42706 -> 83.222.241.23:13566
Source: global trafficTCP traffic: 192.168.2.14:42270 -> 83.222.199.217:13566
Source: global trafficTCP traffic: 192.168.2.14:39462 -> 83.222.34.132:13566
Source: global trafficTCP traffic: 192.168.2.14:42200 -> 83.222.121.236:13566
Source: global trafficTCP traffic: 192.168.2.14:52510 -> 83.222.85.184:13566
Source: global trafficTCP traffic: 192.168.2.14:55604 -> 83.222.28.235:13566
Source: global trafficTCP traffic: 192.168.2.14:40516 -> 83.222.110.64:13566
Source: global trafficTCP traffic: 192.168.2.14:32918 -> 83.222.189.67:13566
Source: global trafficTCP traffic: 192.168.2.14:34592 -> 83.222.65.32:13566
Source: global trafficTCP traffic: 192.168.2.14:36596 -> 83.222.210.238:13566
Source: global trafficTCP traffic: 192.168.2.14:59904 -> 83.222.55.163:13566
Source: global trafficTCP traffic: 192.168.2.14:37258 -> 83.222.146.182:13566
Source: global trafficTCP traffic: 192.168.2.14:53268 -> 83.222.134.119:13566
Source: global trafficTCP traffic: 192.168.2.14:56346 -> 83.222.20.202:13566
Source: global trafficTCP traffic: 192.168.2.14:34406 -> 83.222.228.110:13566
Source: global trafficTCP traffic: 192.168.2.14:48978 -> 83.222.212.213:13566
Source: global trafficTCP traffic: 192.168.2.14:59128 -> 83.222.133.155:13566
Source: global trafficTCP traffic: 192.168.2.14:37866 -> 83.222.175.167:13566
Source: global trafficTCP traffic: 192.168.2.14:60352 -> 83.222.31.40:13566
Source: global trafficTCP traffic: 192.168.2.14:41908 -> 83.222.147.116:13566
Source: global trafficTCP traffic: 192.168.2.14:47650 -> 83.222.224.175:13566
Source: global trafficTCP traffic: 192.168.2.14:52666 -> 83.222.95.78:13566
Source: global trafficTCP traffic: 192.168.2.14:50818 -> 83.222.240.29:13566
Source: global trafficTCP traffic: 192.168.2.14:57928 -> 83.222.145.49:13566
Source: global trafficTCP traffic: 192.168.2.14:35086 -> 83.222.61.99:13566
Source: global trafficTCP traffic: 192.168.2.14:58042 -> 83.222.31.117:13566
Source: global trafficTCP traffic: 192.168.2.14:44840 -> 83.222.6.178:13566
Source: global trafficTCP traffic: 192.168.2.14:52878 -> 83.222.43.141:13566
Source: global trafficTCP traffic: 192.168.2.14:43902 -> 83.222.41.63:13566
Source: global trafficTCP traffic: 192.168.2.14:42048 -> 83.222.87.13:13566
Source: global trafficTCP traffic: 192.168.2.14:49316 -> 83.222.174.43:13566
Source: global trafficTCP traffic: 192.168.2.14:32838 -> 83.222.227.51:13566
Source: global trafficTCP traffic: 192.168.2.14:34144 -> 83.222.198.146:13566
Source: global trafficTCP traffic: 192.168.2.14:53264 -> 83.222.219.230:13566
Source: global trafficTCP traffic: 192.168.2.14:38748 -> 83.222.186.110:13566
Source: global trafficTCP traffic: 192.168.2.14:33400 -> 83.222.90.154:13566
Source: global trafficTCP traffic: 192.168.2.14:34148 -> 83.222.30.186:13566
Source: global trafficTCP traffic: 192.168.2.14:49190 -> 83.222.232.14:13566
Source: global trafficTCP traffic: 192.168.2.14:54802 -> 83.222.215.121:13566
Source: global trafficTCP traffic: 192.168.2.14:34810 -> 83.222.63.20:13566
Source: global trafficTCP traffic: 192.168.2.14:59696 -> 83.222.221.95:13566
Source: global trafficTCP traffic: 192.168.2.14:42594 -> 83.222.137.227:13566
Source: global trafficTCP traffic: 192.168.2.14:33550 -> 83.222.17.181:13566
Source: global trafficTCP traffic: 192.168.2.14:42884 -> 83.222.112.58:13566
Source: global trafficTCP traffic: 192.168.2.14:47794 -> 83.222.244.199:13566
Source: global trafficTCP traffic: 192.168.2.14:56782 -> 83.222.72.162:13566
Source: global trafficTCP traffic: 192.168.2.14:56666 -> 83.222.242.43:13566
Source: global trafficTCP traffic: 192.168.2.14:56518 -> 83.222.214.185:13566
Source: global trafficTCP traffic: 192.168.2.14:44704 -> 83.222.189.177:13566
Source: global trafficTCP traffic: 192.168.2.14:35712 -> 83.222.159.119:13566
Source: global trafficTCP traffic: 192.168.2.14:36058 -> 83.222.31.249:13566
Source: global trafficTCP traffic: 192.168.2.14:33866 -> 83.222.17.61:13566
Source: global trafficTCP traffic: 192.168.2.14:39108 -> 83.222.179.249:13566
Source: global trafficTCP traffic: 192.168.2.14:53216 -> 83.222.75.138:13566
Source: global trafficTCP traffic: 192.168.2.14:42374 -> 83.222.114.139:13566
Source: global trafficTCP traffic: 192.168.2.14:44078 -> 83.222.159.79:13566
Source: global trafficTCP traffic: 192.168.2.14:37048 -> 83.222.234.40:13566
Source: global trafficTCP traffic: 192.168.2.14:48842 -> 83.222.51.251:13566
Source: global trafficTCP traffic: 192.168.2.14:51414 -> 83.222.221.163:13566
Source: global trafficTCP traffic: 192.168.2.14:55770 -> 83.222.53.210:13566
Source: global trafficTCP traffic: 192.168.2.14:52344 -> 83.222.107.125:13566
Source: global trafficTCP traffic: 192.168.2.14:53166 -> 83.222.116.93:13566
Source: global trafficTCP traffic: 192.168.2.14:46856 -> 83.222.168.74:13566
Source: global trafficTCP traffic: 192.168.2.14:36084 -> 83.222.22.101:13566
Source: global trafficTCP traffic: 192.168.2.14:32890 -> 83.222.251.181:13566
Source: global trafficTCP traffic: 192.168.2.14:59122 -> 83.222.220.27:13566
Source: global trafficTCP traffic: 192.168.2.14:56576 -> 83.222.175.237:13566
Source: global trafficTCP traffic: 192.168.2.14:53052 -> 83.222.88.98:13566
Source: global trafficTCP traffic: 192.168.2.14:35754 -> 83.222.230.164:13566
Source: global trafficTCP traffic: 192.168.2.14:40390 -> 83.222.237.89:13566
Source: global trafficTCP traffic: 192.168.2.14:57058 -> 83.222.47.140:13566
Source: global trafficTCP traffic: 192.168.2.14:47924 -> 83.222.168.25:13566
Source: global trafficTCP traffic: 192.168.2.14:56566 -> 83.222.191.90:13566
Source: /tmp/Kloki.x86_64.elf (PID: 5514)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500036 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 19 : 83.222.191.90:13566 -> 192.168.2.14:56566
Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.176.215
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.176.215
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.142.119
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.142.119
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.232
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.84.153
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.207.35
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.232
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.137.76
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.84.153
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.208
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.207.35
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.72.118
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.137.76
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.77.71
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.208
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.30.102
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.72.118
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.253.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.77.71
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.247.99
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.30.102
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.78.255
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.253.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.247.99
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.183.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.20.159
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.78.255
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.183.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.20.159
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.20.159
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.102.197
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.119.244
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.20.159
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.102.197
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.119.244
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.60.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.220.144
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.185.171
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.60.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.220.144
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.248.104
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.185.171
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.64
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.248.104
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.64
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.64
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.64
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

System Summary

barindex
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5491, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5518, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5538, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5540, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5541, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5542, result: successfulJump to behavior
Source: LOAD without section mappingsProgram segment: 0x400000
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5491, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5518, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5538, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5540, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5541, result: successfulJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5517)SIGKILL sent: pid: 5542, result: successfulJump to behavior
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
Source: 5514.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
Source: 5516.1.0000000000400000.000000000040f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.spre.linELF@0/0@1/0
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5543/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3244/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3120/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3361/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3239/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/1299/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3235/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5533/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5534/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5535/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5536/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2946/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3134/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/1593/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3011/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3094/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3406/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2955/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3129/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3402/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3125/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3246/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3245/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/767/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/800/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/888/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5544/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/801/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/769/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/803/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/806/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/807/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2956/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/490/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3142/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3139/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3412/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3398/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3392/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/780/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/661/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/782/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3304/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3425/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/785/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/940/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3147/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3701/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2991/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/791/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2986/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/794/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/795/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/797/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2983/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3159/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3157/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3319/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5351/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3178/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3172/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3171/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3329/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2999/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3847/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3207/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/2997/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/1300/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/725/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/726/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/1309/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5520/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5521/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3189/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3188/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3187/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3341/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3184/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3183/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/1712/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5519/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3218/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3337/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3215/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/853/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3213/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3212/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5492/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3190/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5530/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5531/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5532/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3353/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/3193/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/1289/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5522/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5523/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5524/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5525/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5526/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5527/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5528/statusJump to behavior
Source: /tmp/Kloki.x86_64.elf (PID: 5516)File opened: /proc/5529/statusJump to behavior
Source: Kloki.x86_64.elfSubmission file: segment LOAD with 7.8108 entropy (max. 8.0)
Source: Kloki.x86_64.elfSubmission file: segment LOAD with 7.9518 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
Kloki.x86_64.elf18%ReversingLabsLinux.Backdoor.Mirai
Kloki.x86_64.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.232.11
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.172.23
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.232.14
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.88.98
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.202.209
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.212.213
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.55.163
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.28.235
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.114.139
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.220.27
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.214.185
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.85.184
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.176.215
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.20.202
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.102.197
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.145.49
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.43.141
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.229.93
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.174.43
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.227.51
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.168.232
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.119.244
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.51.251
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.188.189
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.213.1
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.240.29
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.78.255
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.110.64
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.72.118
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.127.227
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.186.110
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.242.43
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.99.142
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.207.35
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.175.237
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.237.89
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.168.25
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.251.181
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.253.191
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.133.155
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.53.210
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.84.153
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.63.48
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.189.177
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.185.171
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.36.210
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.215.121
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.220.144
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.121.236
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.134.119
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.147.116
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.95.78
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.17.61
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.20.159
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.61.99
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.180.208
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.183.191
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.228.110
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.90.10
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.188.159
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.150.182
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.72.162
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.189.67
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.18.64
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.31.40
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.6.178
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.75.138
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.63.20
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.60.31
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.17.181
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.219.230
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.168.74
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.210.238
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.179.249
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.142.119
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.221.163
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.247.99
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.222.96
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.107.125
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.90.154
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.34.132
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.146.182
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.135.253
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.65.32
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.30.102
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.198.146
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.180.66
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.159.119
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.22.101
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.112.58
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.241.23
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.31.117
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.221.95
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.30.186
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    185.125.190.26
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    83.222.87.13
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.116.93
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.47.140
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.137.76
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    secure-network-rebirthltd.ruKloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUKloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.68.210
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.73.212
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.89.90
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.64.159
    skid.x86.elfGet hashmaliciousMoobotBrowse
    • 83.222.64.191
    XfUkJyh9A3.elfGet hashmaliciousMiraiBrowse
    • 37.209.228.199
    nSQgTX0uEc.dllGet hashmaliciousWannacryBrowse
    • 213.141.249.89
    e7N7Kz9BarGet hashmaliciousUnknownBrowse
    • 37.209.226.155
    G2JJHi7jyhGet hashmaliciousMiraiBrowse
    • 212.75.151.147
    KiDRFl2BaNGet hashmaliciousMiraiBrowse
    • 212.75.129.46
    COGECO-PEER1CAKloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.231.59
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.253.28
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.225.208
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.237.30
    http://plnbl.io/review/VdCYQSoKp54zGet hashmaliciousHTMLPhisherBrowse
    • 66.33.60.194
    miori.sh4.elfGet hashmaliciousUnknownBrowse
    • 209.35.191.178
    https://bawarq.org/r.php?id=YoExsdlTj9ej3sIxs1X7aZn3DzYWS8OQ2Get hashmaliciousUnknownBrowse
    • 162.254.38.37
    Mes_Drivers_3.0.4.exeGet hashmaliciousUnknownBrowse
    • 69.90.254.78
    https://app.saner.ai/shared/notes/7353e5ae-dd5f-410b-92c3-210c9e88052aGet hashmaliciousHTMLPhisherBrowse
    • 66.33.60.194
    https://u43161309.ct.sendgrid.net/ls/click?upn=u001.L9-2FCbhkaoUACh7As3yZ8i4iABGphfl-2FJgS6Xiu1aw6I-3DgXpA_qO4VbBWAKg4gLfGs-2BfuSyZki3gKzG4I1DrYN15Q8fD7JV1twLeLo1AFs1GBSG3ZgA22dFJdXJloKc56aXDeV3olJKTBJd8NprednZ2LeXdX-2BkcSQE-2F2FRwgBng5RbUCLfjS8-2FI3mrpwyYu9lRatIB62qUwPSax-2Fhh2c7R-2B7pT3Kos0wK0SEJGj4ZMkgOGYhEniKYT7Kn7jN25xFz2sFdtPlVQkIdCFKwDNWmq-2BrAxerZE2GuKgfkuf3l1UY4J42sOOltybAAVyLhV-2BXfmbuQpN4NpshXRIuhta8ho3ChcTA5NtgjludQThyLtwhGns-2ByLqSbpO1Bhhc-2FCgdgP-2BAOxYrGHvKHjVYRr6-2BiryADxfM-3DGet hashmaliciousHTMLPhisherBrowse
    • 66.33.60.35
    COGECO-PEER1CAKloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.231.59
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.253.28
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.225.208
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.237.30
    http://plnbl.io/review/VdCYQSoKp54zGet hashmaliciousHTMLPhisherBrowse
    • 66.33.60.194
    miori.sh4.elfGet hashmaliciousUnknownBrowse
    • 209.35.191.178
    https://bawarq.org/r.php?id=YoExsdlTj9ej3sIxs1X7aZn3DzYWS8OQ2Get hashmaliciousUnknownBrowse
    • 162.254.38.37
    Mes_Drivers_3.0.4.exeGet hashmaliciousUnknownBrowse
    • 69.90.254.78
    https://app.saner.ai/shared/notes/7353e5ae-dd5f-410b-92c3-210c9e88052aGet hashmaliciousHTMLPhisherBrowse
    • 66.33.60.194
    https://u43161309.ct.sendgrid.net/ls/click?upn=u001.L9-2FCbhkaoUACh7As3yZ8i4iABGphfl-2FJgS6Xiu1aw6I-3DgXpA_qO4VbBWAKg4gLfGs-2BfuSyZki3gKzG4I1DrYN15Q8fD7JV1twLeLo1AFs1GBSG3ZgA22dFJdXJloKc56aXDeV3olJKTBJd8NprednZ2LeXdX-2BkcSQE-2F2FRwgBng5RbUCLfjS8-2FI3mrpwyYu9lRatIB62qUwPSax-2Fhh2c7R-2B7pT3Kos0wK0SEJGj4ZMkgOGYhEniKYT7Kn7jN25xFz2sFdtPlVQkIdCFKwDNWmq-2BrAxerZE2GuKgfkuf3l1UY4J42sOOltybAAVyLhV-2BXfmbuQpN4NpshXRIuhta8ho3ChcTA5NtgjludQThyLtwhGns-2ByLqSbpO1Bhhc-2FCgdgP-2BAOxYrGHvKHjVYRr6-2BiryADxfM-3DGet hashmaliciousHTMLPhisherBrowse
    • 66.33.60.35
    KIG-UNISAT-TVBGKloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.172.149
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.170.68
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.167.126
    z3hir.armGet hashmaliciousMiraiBrowse
    • 93.155.171.211
    wQANfs9EwkGet hashmaliciousGafgyt MiraiBrowse
    • 109.160.88.15
    No context
    No context
    No created / dropped files found
    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
    Entropy (8bit):7.949349022384545
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:Kloki.x86_64.elf
    File size:32'448 bytes
    MD5:87a674a1cd303c58d819270cddd7fc63
    SHA1:c3d59d459d603e8affd3450090e2b1a9619ace5a
    SHA256:192dc6e6726aaa9cce13eaaf812b070d7aa9b4824c2b1dee17e680e3d75284f7
    SHA512:7be9f913879aec7e28bd151501964b6c944abf02c797923988a835a33ff86e0d6c37908f1f83521c2b244c8515c9d18a6cd7b2cdb6adae4683422dbdeb773180
    SSDEEP:768:T4HhLfM7WvNg3biwzEki/pYrqMuBgKxzIRd:sHhfM7WK+kNOMWgK+Rd
    TLSH:09E2E1C3711BD1F8E5FB583B051D4B24F63220821A2B9B29096D6BAF4C75A9E1CD0B73
    File Content Preview:.ELF..............>......k`.....@...................@.8...@.......................@.......@.............h-................................`.......`......}.......}..............Q.td....................................................;..Vsfga........`......

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x606bc0
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:64
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x10000x112d687.81080x6RW 0x100000
    LOAD0x00x6000000x6000000x7dbb0x7dbb7.95180x5R E0x100000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
    2025-01-08T19:51:05.258590+01002500036ET COMPROMISED Known Compromised or Hostile Host Traffic group 19283.222.191.9013566192.168.2.1456566TCP
    TimestampSource PortDest PortSource IPDest IP
    Jan 8, 2025 19:51:04.963408947 CET5489013566192.168.2.1483.222.176.215
    Jan 8, 2025 19:51:04.968525887 CET135665489083.222.176.215192.168.2.14
    Jan 8, 2025 19:51:04.968590975 CET5489013566192.168.2.1483.222.176.215
    Jan 8, 2025 19:51:04.968699932 CET4000413566192.168.2.1483.222.142.119
    Jan 8, 2025 19:51:04.973532915 CET135664000483.222.142.119192.168.2.14
    Jan 8, 2025 19:51:04.973577976 CET4000413566192.168.2.1483.222.142.119
    Jan 8, 2025 19:51:04.973834991 CET5480413566192.168.2.1483.222.168.232
    Jan 8, 2025 19:51:04.975545883 CET5710613566192.168.2.1483.222.84.153
    Jan 8, 2025 19:51:04.977916002 CET4996213566192.168.2.1483.222.207.35
    Jan 8, 2025 19:51:04.978698015 CET135665480483.222.168.232192.168.2.14
    Jan 8, 2025 19:51:04.978773117 CET5480413566192.168.2.1483.222.168.232
    Jan 8, 2025 19:51:04.979614019 CET3296413566192.168.2.1483.222.137.76
    Jan 8, 2025 19:51:04.980309010 CET135665710683.222.84.153192.168.2.14
    Jan 8, 2025 19:51:04.980381966 CET5710613566192.168.2.1483.222.84.153
    Jan 8, 2025 19:51:04.981235027 CET5629213566192.168.2.1483.222.180.208
    Jan 8, 2025 19:51:04.982775927 CET135664996283.222.207.35192.168.2.14
    Jan 8, 2025 19:51:04.982819080 CET4996213566192.168.2.1483.222.207.35
    Jan 8, 2025 19:51:04.983191967 CET3358413566192.168.2.1483.222.72.118
    Jan 8, 2025 19:51:04.984486103 CET135663296483.222.137.76192.168.2.14
    Jan 8, 2025 19:51:04.984524012 CET3296413566192.168.2.1483.222.137.76
    Jan 8, 2025 19:51:04.985105991 CET5746013566192.168.2.1483.222.77.71
    Jan 8, 2025 19:51:04.986092091 CET135665629283.222.180.208192.168.2.14
    Jan 8, 2025 19:51:04.986124992 CET5629213566192.168.2.1483.222.180.208
    Jan 8, 2025 19:51:04.987008095 CET5781413566192.168.2.1483.222.30.102
    Jan 8, 2025 19:51:04.987956047 CET135663358483.222.72.118192.168.2.14
    Jan 8, 2025 19:51:04.988012075 CET3358413566192.168.2.1483.222.72.118
    Jan 8, 2025 19:51:04.988595009 CET5114413566192.168.2.1483.222.253.191
    Jan 8, 2025 19:51:04.989957094 CET135665746083.222.77.71192.168.2.14
    Jan 8, 2025 19:51:04.990004063 CET5746013566192.168.2.1483.222.77.71
    Jan 8, 2025 19:51:04.990868092 CET4046013566192.168.2.1483.222.247.99
    Jan 8, 2025 19:51:04.991780043 CET135665781483.222.30.102192.168.2.14
    Jan 8, 2025 19:51:04.991815090 CET5781413566192.168.2.1483.222.30.102
    Jan 8, 2025 19:51:04.993217945 CET3346213566192.168.2.1483.222.78.255
    Jan 8, 2025 19:51:04.993918896 CET135665114483.222.253.191192.168.2.14
    Jan 8, 2025 19:51:04.993966103 CET5114413566192.168.2.1483.222.253.191
    Jan 8, 2025 19:51:04.996232986 CET135664046083.222.247.99192.168.2.14
    Jan 8, 2025 19:51:04.996278048 CET4046013566192.168.2.1483.222.247.99
    Jan 8, 2025 19:51:04.996597052 CET5943013566192.168.2.1483.222.183.191
    Jan 8, 2025 19:51:04.998279095 CET4784613566192.168.2.1483.222.20.159
    Jan 8, 2025 19:51:04.998732090 CET135663346283.222.78.255192.168.2.14
    Jan 8, 2025 19:51:04.998780012 CET3346213566192.168.2.1483.222.78.255
    Jan 8, 2025 19:51:05.002181053 CET135665943083.222.183.191192.168.2.14
    Jan 8, 2025 19:51:05.002227068 CET5943013566192.168.2.1483.222.183.191
    Jan 8, 2025 19:51:05.003782034 CET135664784683.222.20.159192.168.2.14
    Jan 8, 2025 19:51:05.003834963 CET4784613566192.168.2.1483.222.20.159
    Jan 8, 2025 19:51:05.010998964 CET4784613566192.168.2.1483.222.20.159
    Jan 8, 2025 19:51:05.011894941 CET5978413566192.168.2.1483.222.102.197
    Jan 8, 2025 19:51:05.013322115 CET4637813566192.168.2.1483.222.119.244
    Jan 8, 2025 19:51:05.016064882 CET135664784683.222.20.159192.168.2.14
    Jan 8, 2025 19:51:05.016124010 CET4784613566192.168.2.1483.222.20.159
    Jan 8, 2025 19:51:05.016817093 CET135665978483.222.102.197192.168.2.14
    Jan 8, 2025 19:51:05.016911983 CET5978413566192.168.2.1483.222.102.197
    Jan 8, 2025 19:51:05.018098116 CET135664637883.222.119.244192.168.2.14
    Jan 8, 2025 19:51:05.018172979 CET4637813566192.168.2.1483.222.119.244
    Jan 8, 2025 19:51:05.018291950 CET3339413566192.168.2.1483.222.60.31
    Jan 8, 2025 19:51:05.020153999 CET3804013566192.168.2.1483.222.220.144
    Jan 8, 2025 19:51:05.022757053 CET5329413566192.168.2.1483.222.185.171
    Jan 8, 2025 19:51:05.023096085 CET135663339483.222.60.31192.168.2.14
    Jan 8, 2025 19:51:05.023143053 CET3339413566192.168.2.1483.222.60.31
    Jan 8, 2025 19:51:05.024785042 CET4024613566192.168.2.1483.222.180.66
    Jan 8, 2025 19:51:05.024975061 CET135663804083.222.220.144192.168.2.14
    Jan 8, 2025 19:51:05.025037050 CET3804013566192.168.2.1483.222.220.144
    Jan 8, 2025 19:51:05.027158976 CET3943013566192.168.2.1483.222.248.104
    Jan 8, 2025 19:51:05.027597904 CET135665329483.222.185.171192.168.2.14
    Jan 8, 2025 19:51:05.027642012 CET5329413566192.168.2.1483.222.185.171
    Jan 8, 2025 19:51:05.028984070 CET3380013566192.168.2.1483.222.18.64
    Jan 8, 2025 19:51:05.029644966 CET135664024683.222.180.66192.168.2.14
    Jan 8, 2025 19:51:05.029687881 CET4024613566192.168.2.1483.222.180.66
    Jan 8, 2025 19:51:05.032135010 CET135663943083.222.248.104192.168.2.14
    Jan 8, 2025 19:51:05.032175064 CET3943013566192.168.2.1483.222.248.104
    Jan 8, 2025 19:51:05.033786058 CET135663380083.222.18.64192.168.2.14
    Jan 8, 2025 19:51:05.033853054 CET3380013566192.168.2.1483.222.18.64
    Jan 8, 2025 19:51:05.034759998 CET3380013566192.168.2.1483.222.18.64
    Jan 8, 2025 19:51:05.039959908 CET135663380083.222.18.64192.168.2.14
    Jan 8, 2025 19:51:05.040015936 CET3380013566192.168.2.1483.222.18.64
    Jan 8, 2025 19:51:05.042875051 CET3811813566192.168.2.1483.222.222.96
    Jan 8, 2025 19:51:05.047656059 CET135663811883.222.222.96192.168.2.14
    Jan 8, 2025 19:51:05.047722101 CET3811813566192.168.2.1483.222.222.96
    Jan 8, 2025 19:51:05.048573971 CET3963413566192.168.2.1483.222.135.253
    Jan 8, 2025 19:51:05.050379992 CET5510813566192.168.2.1483.222.198.133
    Jan 8, 2025 19:51:05.052577972 CET4246613566192.168.2.1483.222.188.189
    Jan 8, 2025 19:51:05.053383112 CET135663963483.222.135.253192.168.2.14
    Jan 8, 2025 19:51:05.053427935 CET3963413566192.168.2.1483.222.135.253
    Jan 8, 2025 19:51:05.054126024 CET5404413566192.168.2.1483.222.232.11
    Jan 8, 2025 19:51:05.055150986 CET135665510883.222.198.133192.168.2.14
    Jan 8, 2025 19:51:05.055210114 CET5510813566192.168.2.1483.222.198.133
    Jan 8, 2025 19:51:05.056369066 CET5667013566192.168.2.1483.222.188.159
    Jan 8, 2025 19:51:05.057413101 CET135664246683.222.188.189192.168.2.14
    Jan 8, 2025 19:51:05.057450056 CET4246613566192.168.2.1483.222.188.189
    Jan 8, 2025 19:51:05.058917046 CET135665404483.222.232.11192.168.2.14
    Jan 8, 2025 19:51:05.058954954 CET5404413566192.168.2.1483.222.232.11
    Jan 8, 2025 19:51:05.059607029 CET5921413566192.168.2.1483.222.202.209
    Jan 8, 2025 19:51:05.061131954 CET135665667083.222.188.159192.168.2.14
    Jan 8, 2025 19:51:05.061172962 CET5667013566192.168.2.1483.222.188.159
    Jan 8, 2025 19:51:05.061606884 CET5882013566192.168.2.1483.222.63.48
    Jan 8, 2025 19:51:05.063703060 CET3360413566192.168.2.1483.222.150.182
    Jan 8, 2025 19:51:05.064340115 CET135665921483.222.202.209192.168.2.14
    Jan 8, 2025 19:51:05.064378977 CET5921413566192.168.2.1483.222.202.209
    Jan 8, 2025 19:51:05.065793037 CET5170413566192.168.2.1483.222.36.210
    Jan 8, 2025 19:51:05.066381931 CET135665882083.222.63.48192.168.2.14
    Jan 8, 2025 19:51:05.066435099 CET5882013566192.168.2.1483.222.63.48
    Jan 8, 2025 19:51:05.067461967 CET4479813566192.168.2.1483.222.213.1
    Jan 8, 2025 19:51:05.068460941 CET135663360483.222.150.182192.168.2.14
    Jan 8, 2025 19:51:05.068497896 CET3360413566192.168.2.1483.222.150.182
    Jan 8, 2025 19:51:05.069509029 CET4927813566192.168.2.1483.222.99.142
    Jan 8, 2025 19:51:05.070601940 CET135665170483.222.36.210192.168.2.14
    Jan 8, 2025 19:51:05.070647001 CET5170413566192.168.2.1483.222.36.210
    Jan 8, 2025 19:51:05.071274042 CET5302813566192.168.2.1483.222.172.23
    Jan 8, 2025 19:51:05.072232962 CET135664479883.222.213.1192.168.2.14
    Jan 8, 2025 19:51:05.072263002 CET4479813566192.168.2.1483.222.213.1
    Jan 8, 2025 19:51:05.072896957 CET5387613566192.168.2.1483.222.209.164
    Jan 8, 2025 19:51:05.074336052 CET135664927883.222.99.142192.168.2.14
    Jan 8, 2025 19:51:05.074378967 CET4927813566192.168.2.1483.222.99.142
    Jan 8, 2025 19:51:05.076018095 CET135665302883.222.172.23192.168.2.14
    Jan 8, 2025 19:51:05.076066971 CET5302813566192.168.2.1483.222.172.23
    Jan 8, 2025 19:51:05.077198029 CET4108413566192.168.2.1483.222.127.227
    Jan 8, 2025 19:51:05.077745914 CET135665387683.222.209.164192.168.2.14
    Jan 8, 2025 19:51:05.077797890 CET5387613566192.168.2.1483.222.209.164
    Jan 8, 2025 19:51:05.082835913 CET135664108483.222.127.227192.168.2.14
    Jan 8, 2025 19:51:05.082870960 CET4108413566192.168.2.1483.222.127.227
    Jan 8, 2025 19:51:05.083033085 CET4698813566192.168.2.1483.222.229.93
    Jan 8, 2025 19:51:05.084438086 CET5752813566192.168.2.1483.222.67.108
    Jan 8, 2025 19:51:05.086170912 CET5852213566192.168.2.1483.222.90.10
    Jan 8, 2025 19:51:05.087573051 CET4270613566192.168.2.1483.222.241.23
    Jan 8, 2025 19:51:05.089040995 CET135664698883.222.229.93192.168.2.14
    Jan 8, 2025 19:51:05.089092016 CET4698813566192.168.2.1483.222.229.93
    Jan 8, 2025 19:51:05.089293003 CET4227013566192.168.2.1483.222.199.217
    Jan 8, 2025 19:51:05.090186119 CET135665752883.222.67.108192.168.2.14
    Jan 8, 2025 19:51:05.090240955 CET5752813566192.168.2.1483.222.67.108
    Jan 8, 2025 19:51:05.090754986 CET3946213566192.168.2.1483.222.34.132
    Jan 8, 2025 19:51:05.091815948 CET135665852283.222.90.10192.168.2.14
    Jan 8, 2025 19:51:05.091851950 CET5852213566192.168.2.1483.222.90.10
    Jan 8, 2025 19:51:05.092449903 CET4220013566192.168.2.1483.222.121.236
    Jan 8, 2025 19:51:05.093444109 CET135664270683.222.241.23192.168.2.14
    Jan 8, 2025 19:51:05.093488932 CET4270613566192.168.2.1483.222.241.23
    Jan 8, 2025 19:51:05.093579054 CET5251013566192.168.2.1483.222.85.184
    Jan 8, 2025 19:51:05.094810009 CET5560413566192.168.2.1483.222.28.235
    Jan 8, 2025 19:51:05.095094919 CET135664227083.222.199.217192.168.2.14
    Jan 8, 2025 19:51:05.095144033 CET4227013566192.168.2.1483.222.199.217
    Jan 8, 2025 19:51:05.095858097 CET4051613566192.168.2.1483.222.110.64
    Jan 8, 2025 19:51:05.096263885 CET135663946283.222.34.132192.168.2.14
    Jan 8, 2025 19:51:05.096332073 CET3946213566192.168.2.1483.222.34.132
    Jan 8, 2025 19:51:05.096987009 CET3291813566192.168.2.1483.222.189.67
    Jan 8, 2025 19:51:05.097964048 CET135664220083.222.121.236192.168.2.14
    Jan 8, 2025 19:51:05.098001957 CET4220013566192.168.2.1483.222.121.236
    Jan 8, 2025 19:51:05.098289967 CET3459213566192.168.2.1483.222.65.32
    Jan 8, 2025 19:51:05.099558115 CET135665251083.222.85.184192.168.2.14
    Jan 8, 2025 19:51:05.099627972 CET5251013566192.168.2.1483.222.85.184
    Jan 8, 2025 19:51:05.099837065 CET3659613566192.168.2.1483.222.210.238
    Jan 8, 2025 19:51:05.100704908 CET135665560483.222.28.235192.168.2.14
    Jan 8, 2025 19:51:05.100744963 CET5560413566192.168.2.1483.222.28.235
    Jan 8, 2025 19:51:05.101365089 CET5990413566192.168.2.1483.222.55.163
    Jan 8, 2025 19:51:05.101816893 CET135664051683.222.110.64192.168.2.14
    Jan 8, 2025 19:51:05.101864100 CET4051613566192.168.2.1483.222.110.64
    Jan 8, 2025 19:51:05.102996111 CET135663291883.222.189.67192.168.2.14
    Jan 8, 2025 19:51:05.103044987 CET3291813566192.168.2.1483.222.189.67
    Jan 8, 2025 19:51:05.104026079 CET135663459283.222.65.32192.168.2.14
    Jan 8, 2025 19:51:05.104079962 CET3459213566192.168.2.1483.222.65.32
    Jan 8, 2025 19:51:05.104226112 CET3725813566192.168.2.1483.222.146.182
    Jan 8, 2025 19:51:05.105026960 CET135663659683.222.210.238192.168.2.14
    Jan 8, 2025 19:51:05.105083942 CET3659613566192.168.2.1483.222.210.238
    Jan 8, 2025 19:51:05.106149912 CET135665990483.222.55.163192.168.2.14
    Jan 8, 2025 19:51:05.106198072 CET5990413566192.168.2.1483.222.55.163
    Jan 8, 2025 19:51:05.106256962 CET5326813566192.168.2.1483.222.134.119
    Jan 8, 2025 19:51:05.109051943 CET135663725883.222.146.182192.168.2.14
    Jan 8, 2025 19:51:05.109090090 CET3725813566192.168.2.1483.222.146.182
    Jan 8, 2025 19:51:05.109271049 CET5634613566192.168.2.1483.222.20.202
    Jan 8, 2025 19:51:05.111033916 CET135665326883.222.134.119192.168.2.14
    Jan 8, 2025 19:51:05.111068964 CET5326813566192.168.2.1483.222.134.119
    Jan 8, 2025 19:51:05.111087084 CET3440613566192.168.2.1483.222.228.110
    Jan 8, 2025 19:51:05.113440037 CET4897813566192.168.2.1483.222.212.213
    Jan 8, 2025 19:51:05.114031076 CET135665634683.222.20.202192.168.2.14
    Jan 8, 2025 19:51:05.114078045 CET5634613566192.168.2.1483.222.20.202
    Jan 8, 2025 19:51:05.115159035 CET5912813566192.168.2.1483.222.133.155
    Jan 8, 2025 19:51:05.115912914 CET135663440683.222.228.110192.168.2.14
    Jan 8, 2025 19:51:05.115947008 CET3440613566192.168.2.1483.222.228.110
    Jan 8, 2025 19:51:05.117101908 CET3786613566192.168.2.1483.222.175.167
    Jan 8, 2025 19:51:05.118236065 CET135664897883.222.212.213192.168.2.14
    Jan 8, 2025 19:51:05.118283987 CET4897813566192.168.2.1483.222.212.213
    Jan 8, 2025 19:51:05.118516922 CET6035213566192.168.2.1483.222.31.40
    Jan 8, 2025 19:51:05.120018959 CET135665912883.222.133.155192.168.2.14
    Jan 8, 2025 19:51:05.120071888 CET5912813566192.168.2.1483.222.133.155
    Jan 8, 2025 19:51:05.120698929 CET4190813566192.168.2.1483.222.147.116
    Jan 8, 2025 19:51:05.121947050 CET135663786683.222.175.167192.168.2.14
    Jan 8, 2025 19:51:05.121985912 CET3786613566192.168.2.1483.222.175.167
    Jan 8, 2025 19:51:05.122174025 CET4765013566192.168.2.1483.222.224.175
    Jan 8, 2025 19:51:05.123327017 CET135666035283.222.31.40192.168.2.14
    Jan 8, 2025 19:51:05.123336077 CET5266613566192.168.2.1483.222.95.78
    Jan 8, 2025 19:51:05.123357058 CET6035213566192.168.2.1483.222.31.40
    Jan 8, 2025 19:51:05.125490904 CET135664190883.222.147.116192.168.2.14
    Jan 8, 2025 19:51:05.125523090 CET4190813566192.168.2.1483.222.147.116
    Jan 8, 2025 19:51:05.125523090 CET5081813566192.168.2.1483.222.240.29
    Jan 8, 2025 19:51:05.126974106 CET135664765083.222.224.175192.168.2.14
    Jan 8, 2025 19:51:05.127017021 CET4765013566192.168.2.1483.222.224.175
    Jan 8, 2025 19:51:05.127207994 CET5792813566192.168.2.1483.222.145.49
    Jan 8, 2025 19:51:05.128149986 CET135665266683.222.95.78192.168.2.14
    Jan 8, 2025 19:51:05.128175974 CET5266613566192.168.2.1483.222.95.78
    Jan 8, 2025 19:51:05.129190922 CET3508613566192.168.2.1483.222.61.99
    Jan 8, 2025 19:51:05.130311012 CET135665081883.222.240.29192.168.2.14
    Jan 8, 2025 19:51:05.130379915 CET5081813566192.168.2.1483.222.240.29
    Jan 8, 2025 19:51:05.130867958 CET5804213566192.168.2.1483.222.31.117
    Jan 8, 2025 19:51:05.132056952 CET135665792883.222.145.49192.168.2.14
    Jan 8, 2025 19:51:05.132086039 CET5792813566192.168.2.1483.222.145.49
    Jan 8, 2025 19:51:05.132889986 CET4484013566192.168.2.1483.222.6.178
    Jan 8, 2025 19:51:05.133994102 CET135663508683.222.61.99192.168.2.14
    Jan 8, 2025 19:51:05.134037971 CET3508613566192.168.2.1483.222.61.99
    Jan 8, 2025 19:51:05.134556055 CET5287813566192.168.2.1483.222.43.141
    Jan 8, 2025 19:51:05.135706902 CET135665804283.222.31.117192.168.2.14
    Jan 8, 2025 19:51:05.135755062 CET5804213566192.168.2.1483.222.31.117
    Jan 8, 2025 19:51:05.137268066 CET4390213566192.168.2.1483.222.41.63
    Jan 8, 2025 19:51:05.137674093 CET135664484083.222.6.178192.168.2.14
    Jan 8, 2025 19:51:05.137703896 CET4484013566192.168.2.1483.222.6.178
    Jan 8, 2025 19:51:05.138715029 CET4204813566192.168.2.1483.222.87.13
    Jan 8, 2025 19:51:05.139339924 CET135665287883.222.43.141192.168.2.14
    Jan 8, 2025 19:51:05.139379025 CET5287813566192.168.2.1483.222.43.141
    Jan 8, 2025 19:51:05.139746904 CET4931613566192.168.2.1483.222.174.43
    Jan 8, 2025 19:51:05.140198946 CET3283813566192.168.2.1483.222.227.51
    Jan 8, 2025 19:51:05.141777039 CET3414413566192.168.2.1483.222.198.146
    Jan 8, 2025 19:51:05.142061949 CET135664390283.222.41.63192.168.2.14
    Jan 8, 2025 19:51:05.142097950 CET4390213566192.168.2.1483.222.41.63
    Jan 8, 2025 19:51:05.143498898 CET135664204883.222.87.13192.168.2.14
    Jan 8, 2025 19:51:05.143532991 CET4204813566192.168.2.1483.222.87.13
    Jan 8, 2025 19:51:05.144517899 CET5326413566192.168.2.1483.222.219.230
    Jan 8, 2025 19:51:05.144567966 CET135664931683.222.174.43192.168.2.14
    Jan 8, 2025 19:51:05.144602060 CET4931613566192.168.2.1483.222.174.43
    Jan 8, 2025 19:51:05.145047903 CET135663283883.222.227.51192.168.2.14
    Jan 8, 2025 19:51:05.145081997 CET3283813566192.168.2.1483.222.227.51
    Jan 8, 2025 19:51:05.146604061 CET135663414483.222.198.146192.168.2.14
    Jan 8, 2025 19:51:05.146631956 CET3414413566192.168.2.1483.222.198.146
    Jan 8, 2025 19:51:05.147407055 CET3874813566192.168.2.1483.222.186.110
    Jan 8, 2025 19:51:05.149374962 CET135665326483.222.219.230192.168.2.14
    Jan 8, 2025 19:51:05.149405956 CET5326413566192.168.2.1483.222.219.230
    Jan 8, 2025 19:51:05.149872065 CET3340013566192.168.2.1483.222.90.154
    Jan 8, 2025 19:51:05.152206898 CET135663874883.222.186.110192.168.2.14
    Jan 8, 2025 19:51:05.152244091 CET3874813566192.168.2.1483.222.186.110
    Jan 8, 2025 19:51:05.152718067 CET3414813566192.168.2.1483.222.30.186
    Jan 8, 2025 19:51:05.154654980 CET135663340083.222.90.154192.168.2.14
    Jan 8, 2025 19:51:05.154685020 CET3340013566192.168.2.1483.222.90.154
    Jan 8, 2025 19:51:05.154918909 CET4919013566192.168.2.1483.222.232.14
    Jan 8, 2025 19:51:05.157500029 CET135663414883.222.30.186192.168.2.14
    Jan 8, 2025 19:51:05.157536030 CET3414813566192.168.2.1483.222.30.186
    Jan 8, 2025 19:51:05.157784939 CET5480213566192.168.2.1483.222.215.121
    Jan 8, 2025 19:51:05.159694910 CET135664919083.222.232.14192.168.2.14
    Jan 8, 2025 19:51:05.159723997 CET4919013566192.168.2.1483.222.232.14
    Jan 8, 2025 19:51:05.159949064 CET3481013566192.168.2.1483.222.63.20
    Jan 8, 2025 19:51:05.162482977 CET5969613566192.168.2.1483.222.221.95
    Jan 8, 2025 19:51:05.162540913 CET135665480283.222.215.121192.168.2.14
    Jan 8, 2025 19:51:05.162578106 CET5480213566192.168.2.1483.222.215.121
    Jan 8, 2025 19:51:05.164608955 CET4259413566192.168.2.1483.222.137.227
    Jan 8, 2025 19:51:05.164721966 CET135663481083.222.63.20192.168.2.14
    Jan 8, 2025 19:51:05.164752960 CET3481013566192.168.2.1483.222.63.20
    Jan 8, 2025 19:51:05.167246103 CET3355013566192.168.2.1483.222.17.181
    Jan 8, 2025 19:51:05.167282104 CET135665969683.222.221.95192.168.2.14
    Jan 8, 2025 19:51:05.167320013 CET5969613566192.168.2.1483.222.221.95
    Jan 8, 2025 19:51:05.169418097 CET135664259483.222.137.227192.168.2.14
    Jan 8, 2025 19:51:05.169456959 CET4259413566192.168.2.1483.222.137.227
    Jan 8, 2025 19:51:05.169882059 CET4288413566192.168.2.1483.222.112.58
    Jan 8, 2025 19:51:05.172456026 CET4779413566192.168.2.1483.222.244.199
    Jan 8, 2025 19:51:05.173341036 CET135663355083.222.17.181192.168.2.14
    Jan 8, 2025 19:51:05.173386097 CET3355013566192.168.2.1483.222.17.181
    Jan 8, 2025 19:51:05.174499035 CET5678213566192.168.2.1483.222.72.162
    Jan 8, 2025 19:51:05.174736977 CET135664288483.222.112.58192.168.2.14
    Jan 8, 2025 19:51:05.174773932 CET4288413566192.168.2.1483.222.112.58
    Jan 8, 2025 19:51:05.177103043 CET5666613566192.168.2.1483.222.242.43
    Jan 8, 2025 19:51:05.178607941 CET135664779483.222.244.199192.168.2.14
    Jan 8, 2025 19:51:05.178647995 CET4779413566192.168.2.1483.222.244.199
    Jan 8, 2025 19:51:05.179306030 CET5651813566192.168.2.1483.222.214.185
    Jan 8, 2025 19:51:05.180166006 CET135665678283.222.72.162192.168.2.14
    Jan 8, 2025 19:51:05.180202007 CET5678213566192.168.2.1483.222.72.162
    Jan 8, 2025 19:51:05.182634115 CET4470413566192.168.2.1483.222.189.177
    Jan 8, 2025 19:51:05.182934999 CET135665666683.222.242.43192.168.2.14
    Jan 8, 2025 19:51:05.182981014 CET5666613566192.168.2.1483.222.242.43
    Jan 8, 2025 19:51:05.184695959 CET3571213566192.168.2.1483.222.159.119
    Jan 8, 2025 19:51:05.185178995 CET135665651883.222.214.185192.168.2.14
    Jan 8, 2025 19:51:05.185262918 CET5651813566192.168.2.1483.222.214.185
    Jan 8, 2025 19:51:05.187422037 CET3605813566192.168.2.1483.222.31.249
    Jan 8, 2025 19:51:05.188473940 CET135664470483.222.189.177192.168.2.14
    Jan 8, 2025 19:51:05.188508987 CET4470413566192.168.2.1483.222.189.177
    Jan 8, 2025 19:51:05.189450026 CET3386613566192.168.2.1483.222.17.61
    Jan 8, 2025 19:51:05.190114021 CET135663571283.222.159.119192.168.2.14
    Jan 8, 2025 19:51:05.190149069 CET3571213566192.168.2.1483.222.159.119
    Jan 8, 2025 19:51:05.192244053 CET3910813566192.168.2.1483.222.179.249
    Jan 8, 2025 19:51:05.192928076 CET135663605883.222.31.249192.168.2.14
    Jan 8, 2025 19:51:05.192965984 CET3605813566192.168.2.1483.222.31.249
    Jan 8, 2025 19:51:05.194384098 CET5321613566192.168.2.1483.222.75.138
    Jan 8, 2025 19:51:05.195194006 CET135663386683.222.17.61192.168.2.14
    Jan 8, 2025 19:51:05.195226908 CET3386613566192.168.2.1483.222.17.61
    Jan 8, 2025 19:51:05.197012901 CET135663910883.222.179.249192.168.2.14
    Jan 8, 2025 19:51:05.197046995 CET3910813566192.168.2.1483.222.179.249
    Jan 8, 2025 19:51:05.197113991 CET4237413566192.168.2.1483.222.114.139
    Jan 8, 2025 19:51:05.199131966 CET135665321683.222.75.138192.168.2.14
    Jan 8, 2025 19:51:05.199174881 CET5321613566192.168.2.1483.222.75.138
    Jan 8, 2025 19:51:05.199182034 CET4407813566192.168.2.1483.222.159.79
    Jan 8, 2025 19:51:05.201740980 CET3704813566192.168.2.1483.222.234.40
    Jan 8, 2025 19:51:05.201891899 CET135664237483.222.114.139192.168.2.14
    Jan 8, 2025 19:51:05.201930046 CET4237413566192.168.2.1483.222.114.139
    Jan 8, 2025 19:51:05.203768015 CET4884213566192.168.2.1483.222.51.251
    Jan 8, 2025 19:51:05.204083920 CET135664407883.222.159.79192.168.2.14
    Jan 8, 2025 19:51:05.204118013 CET4407813566192.168.2.1483.222.159.79
    Jan 8, 2025 19:51:05.206366062 CET5141413566192.168.2.1483.222.221.163
    Jan 8, 2025 19:51:05.206528902 CET135663704883.222.234.40192.168.2.14
    Jan 8, 2025 19:51:05.206564903 CET3704813566192.168.2.1483.222.234.40
    Jan 8, 2025 19:51:05.208458900 CET5577013566192.168.2.1483.222.53.210
    Jan 8, 2025 19:51:05.208597898 CET135664884283.222.51.251192.168.2.14
    Jan 8, 2025 19:51:05.208633900 CET4884213566192.168.2.1483.222.51.251
    Jan 8, 2025 19:51:05.211110115 CET5234413566192.168.2.1483.222.107.125
    Jan 8, 2025 19:51:05.211129904 CET135665141483.222.221.163192.168.2.14
    Jan 8, 2025 19:51:05.211167097 CET5141413566192.168.2.1483.222.221.163
    Jan 8, 2025 19:51:05.213144064 CET5316613566192.168.2.1483.222.116.93
    Jan 8, 2025 19:51:05.213212013 CET135665577083.222.53.210192.168.2.14
    Jan 8, 2025 19:51:05.213248968 CET5577013566192.168.2.1483.222.53.210
    Jan 8, 2025 19:51:05.215919018 CET135665234483.222.107.125192.168.2.14
    Jan 8, 2025 19:51:05.215979099 CET5234413566192.168.2.1483.222.107.125
    Jan 8, 2025 19:51:05.216320038 CET4685613566192.168.2.1483.222.168.74
    Jan 8, 2025 19:51:05.218046904 CET135665316683.222.116.93192.168.2.14
    Jan 8, 2025 19:51:05.218089104 CET5316613566192.168.2.1483.222.116.93
    Jan 8, 2025 19:51:05.218354940 CET3608413566192.168.2.1483.222.22.101
    Jan 8, 2025 19:51:05.220949888 CET3289013566192.168.2.1483.222.251.181
    Jan 8, 2025 19:51:05.221046925 CET135664685683.222.168.74192.168.2.14
    Jan 8, 2025 19:51:05.221081972 CET4685613566192.168.2.1483.222.168.74
    Jan 8, 2025 19:51:05.222976923 CET5912213566192.168.2.1483.222.220.27
    Jan 8, 2025 19:51:05.223115921 CET135663608483.222.22.101192.168.2.14
    Jan 8, 2025 19:51:05.223149061 CET3608413566192.168.2.1483.222.22.101
    Jan 8, 2025 19:51:05.225538015 CET5657613566192.168.2.1483.222.175.237
    Jan 8, 2025 19:51:05.225754023 CET135663289083.222.251.181192.168.2.14
    Jan 8, 2025 19:51:05.225792885 CET3289013566192.168.2.1483.222.251.181
    Jan 8, 2025 19:51:05.227600098 CET5305213566192.168.2.1483.222.88.98
    Jan 8, 2025 19:51:05.227746964 CET135665912283.222.220.27192.168.2.14
    Jan 8, 2025 19:51:05.227783918 CET5912213566192.168.2.1483.222.220.27
    Jan 8, 2025 19:51:05.230312109 CET3575413566192.168.2.1483.222.230.164
    Jan 8, 2025 19:51:05.230418921 CET135665657683.222.175.237192.168.2.14
    Jan 8, 2025 19:51:05.230458021 CET5657613566192.168.2.1483.222.175.237
    Jan 8, 2025 19:51:05.232341051 CET135665305283.222.88.98192.168.2.14
    Jan 8, 2025 19:51:05.232383966 CET5305213566192.168.2.1483.222.88.98
    Jan 8, 2025 19:51:05.232470989 CET4039013566192.168.2.1483.222.237.89
    Jan 8, 2025 19:51:05.235064983 CET135663575483.222.230.164192.168.2.14
    Jan 8, 2025 19:51:05.235125065 CET3575413566192.168.2.1483.222.230.164
    Jan 8, 2025 19:51:05.235526085 CET5705813566192.168.2.1483.222.47.140
    Jan 8, 2025 19:51:05.237236977 CET135664039083.222.237.89192.168.2.14
    Jan 8, 2025 19:51:05.237276077 CET4039013566192.168.2.1483.222.237.89
    Jan 8, 2025 19:51:05.237742901 CET4792413566192.168.2.1483.222.168.25
    Jan 8, 2025 19:51:05.240298986 CET135665705883.222.47.140192.168.2.14
    Jan 8, 2025 19:51:05.240344048 CET5705813566192.168.2.1483.222.47.140
    Jan 8, 2025 19:51:05.242518902 CET135664792483.222.168.25192.168.2.14
    Jan 8, 2025 19:51:05.242569923 CET4792413566192.168.2.1483.222.168.25
    Jan 8, 2025 19:51:05.253806114 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:51:05.258589983 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:51:05.258646011 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:51:05.261270046 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:51:05.266165972 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:51:05.266202927 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:51:05.270956039 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:51:15.138111115 CET46540443192.168.2.14185.125.190.26
    Jan 8, 2025 19:51:15.270106077 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:51:15.275005102 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:51:15.475770950 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:51:15.475965023 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:51:15.881764889 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:51:15.881867886 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:51:45.600895882 CET46540443192.168.2.14185.125.190.26
    Jan 8, 2025 19:52:15.920268059 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:52:15.925240993 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:52:16.125797033 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:52:16.126039982 CET5656613566192.168.2.1483.222.191.90
    Jan 8, 2025 19:52:16.882232904 CET135665656683.222.191.90192.168.2.14
    Jan 8, 2025 19:52:16.882437944 CET5656613566192.168.2.1483.222.191.90
    TimestampSource PortDest PortSource IPDest IP
    Jan 8, 2025 19:51:05.242109060 CET3807953192.168.2.148.8.8.8
    Jan 8, 2025 19:51:05.252356052 CET53380798.8.8.8192.168.2.14
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jan 8, 2025 19:51:05.242109060 CET192.168.2.148.8.8.80x5aaaStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jan 8, 2025 19:51:05.252356052 CET8.8.8.8192.168.2.140x5aaaNo error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86_64.elf
    Arguments:/tmp/Kloki.x86_64.elf
    File size:32448 bytes
    MD5 hash:87a674a1cd303c58d819270cddd7fc63

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86_64.elf
    Arguments:-
    File size:32448 bytes
    MD5 hash:87a674a1cd303c58d819270cddd7fc63

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86_64.elf
    Arguments:-
    File size:32448 bytes
    MD5 hash:87a674a1cd303c58d819270cddd7fc63

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/tmp/Kloki.x86_64.elf
    Arguments:-
    File size:32448 bytes
    MD5 hash:87a674a1cd303c58d819270cddd7fc63

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-sharing
    Arguments:/usr/libexec/gsd-sharing
    File size:35424 bytes
    MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/bin/gnome-shell
    Arguments:/usr/bin/gnome-shell
    File size:23168 bytes
    MD5 hash:da7a257239677622fe4b3a65972c9e87

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-print-notifications
    Arguments:/usr/libexec/gsd-print-notifications
    File size:51840 bytes
    MD5 hash:71539698aa691718cee775d6b9450ae2

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/libexec/gsd-rfkill
    Arguments:/usr/libexec/gsd-rfkill
    File size:51808 bytes
    MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):18:51:04
    Start date (UTC):08/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):18:51:14
    Start date (UTC):08/01/2025
    Path:/usr/lib/systemd/systemd
    Arguments:-
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    Start time (UTC):18:51:14
    Start date (UTC):08/01/2025
    Path:/lib/systemd/systemd-user-runtime-dir
    Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
    File size:22672 bytes
    MD5 hash:d55f4b0847f88131dbcfb07435178e54