Edit tour
Linux
Analysis Report
Kloki.m68k.elf
Overview
General Information
Sample name: | Kloki.m68k.elf |
Analysis ID: | 1586173 |
MD5: | 8d5063d215ab0a7795f2511b80e7310a |
SHA1: | 0d70fcd78fe042a9b06896d30c02615a9e7236ee |
SHA256: | 98eb4c8c5edf1ea00cbf075b2845b28f8746c93844a03e01f6ba5d9255f932ff |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1586173 |
Start date and time: | 2025-01-08 19:50:11 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | Kloki.m68k.elf |
Detection: | MAL |
Classification: | mal52.spre.linELF@0/0@1/0 |
- VT rate limit hit for: Kloki.m68k.elf
Command: | /tmp/Kloki.m68k.elf |
PID: | 5433 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | suka |
Standard Error: |
- system is lnxubuntu20
- Kloki.m68k.elf New Fork (PID: 5436, Parent: 5433)
- Kloki.m68k.elf New Fork (PID: 5438, Parent: 5436)
- Kloki.m68k.elf New Fork (PID: 5439, Parent: 5436)
- gnome-session-binary New Fork (PID: 5442, Parent: 1588)
- gnome-session-binary New Fork (PID: 5463, Parent: 1588)
- gnome-session-binary New Fork (PID: 5465, Parent: 1588)
- gnome-session-binary New Fork (PID: 5466, Parent: 1588)
- gdm3 New Fork (PID: 5467, Parent: 1400)
- gdm3 New Fork (PID: 5469, Parent: 1400)
- systemd New Fork (PID: 5480, Parent: 1)
- cleanup
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-08T19:51:03.618216+0100 | 2500036 | 2 | Misc Attack | 83.222.191.90 | 13566 | 192.168.2.13 | 42766 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.90 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.127.16 | unknown | Russian Federation | 47328 | TRI-ASTrueRecordsIncES | false | |
83.222.131.252 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.238.177 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.8.109 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.168.148 | unknown | Bulgaria | 12615 | GCN-ASGCNAD-SofiaBulgariaBG | false | |
83.222.59.255 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.186.190 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.46.196 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.109.22 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.17.188 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.114.3 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.23.60 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.199.27 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.84.171 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.214.28 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.32.222 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.59.109 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.34.9 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.13.199 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.139.117 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.59.144 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.52.214 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.145.145 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.238.5 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.106.249 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.69.33 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.10.243 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.126.23 | unknown | Russian Federation | 47328 | TRI-ASTrueRecordsIncES | false | |
83.222.65.71 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.196.94 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.65.220 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.14.193 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.87.0 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.184.26 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.87.171 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.151.246 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.238.93 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.247.1 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.237.91 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.111.1 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.242.76 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.66.234 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.169.127 | unknown | Bulgaria | 12615 | GCN-ASGCNAD-SofiaBulgariaBG | false | |
83.222.62.33 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.232.205 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.18.36 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.191.90 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.46.246 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.94.23 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.239.50 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.96.107 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.224.11 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.86.170 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.111.94 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.83.69 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false |
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TRI-ASTrueRecordsIncES | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
COGECO-PEER1CA | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
SENSELAN-ASsenseLANGmbHCH | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 6.237062527888886 |
TrID: |
|
File name: | Kloki.m68k.elf |
File size: | 67'600 bytes |
MD5: | 8d5063d215ab0a7795f2511b80e7310a |
SHA1: | 0d70fcd78fe042a9b06896d30c02615a9e7236ee |
SHA256: | 98eb4c8c5edf1ea00cbf075b2845b28f8746c93844a03e01f6ba5d9255f932ff |
SHA512: | 3939ccb5a0147d38f84f0fbe3af7b779f08d1bcca18654fa495d92323eccd489154516cd90fc26190d35eb74bcaac8aa5485b3b52457a9891f119f2be1b459cb |
SSDEEP: | 1536:Nv5GAR311AhG/BC9sM28uMW69tISPhZHuuUTLilgoEAxn:NhGARXx/BOsMBWUDhVu3E9xn |
TLSH: | 8B6329DAF810DD7DF81FE77F8463050AB671A35601820F36679BB963BD321A44962F82 |
File Content Preview: | .ELF.......................D...4.........4. ...(.................................. ..........."...".......4....... .dt.Q............................NV..a....da....xN^NuNV..J9..&@f>"y..". QJ.g.X.#...".N."y..". QJ.f.A.....J.g.Hy....N.X.......&@N^NuNV..N^NuN |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 67200 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80000094 | 0x94 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.text | PROGBITS | 0x800000a8 | 0xa8 | 0xefa2 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x8000f04a | 0xf04a | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.rodata | PROGBITS | 0x8000f058 | 0xf058 | 0x125c | 0x0 | 0x2 | A | 0 | 0 | 2 |
.ctors | PROGBITS | 0x800122b8 | 0x102b8 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x800122c0 | 0x102c0 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x800122cc | 0x102cc | 0x374 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.bss | NOBITS | 0x80012640 | 0x10640 | 0x3170 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x10640 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x80000000 | 0x80000000 | 0x102b4 | 0x102b4 | 6.2740 | 0x5 | R E | 0x2000 | .init .text .fini .rodata | |
LOAD | 0x102b8 | 0x800122b8 | 0x800122b8 | 0x388 | 0x34f8 | 2.9795 | 0x6 | RW | 0x2000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-08T19:51:03.618216+0100 | 2500036 | ET COMPROMISED Known Compromised or Hostile Host Traffic group 19 | 2 | 83.222.191.90 | 13566 | 192.168.2.13 | 42766 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 8, 2025 19:51:03.323247910 CET | 41608 | 13566 | 192.168.2.13 | 83.222.46.246 |
Jan 8, 2025 19:51:03.326924086 CET | 33332 | 13566 | 192.168.2.13 | 83.222.224.11 |
Jan 8, 2025 19:51:03.328465939 CET | 13566 | 41608 | 83.222.46.246 | 192.168.2.13 |
Jan 8, 2025 19:51:03.328519106 CET | 41608 | 13566 | 192.168.2.13 | 83.222.46.246 |
Jan 8, 2025 19:51:03.330964088 CET | 37878 | 13566 | 192.168.2.13 | 83.222.69.33 |
Jan 8, 2025 19:51:03.331795931 CET | 13566 | 33332 | 83.222.224.11 | 192.168.2.13 |
Jan 8, 2025 19:51:03.331835985 CET | 33332 | 13566 | 192.168.2.13 | 83.222.224.11 |
Jan 8, 2025 19:51:03.335957050 CET | 13566 | 37878 | 83.222.69.33 | 192.168.2.13 |
Jan 8, 2025 19:51:03.336009979 CET | 37878 | 13566 | 192.168.2.13 | 83.222.69.33 |
Jan 8, 2025 19:51:03.345248938 CET | 37878 | 13566 | 192.168.2.13 | 83.222.69.33 |
Jan 8, 2025 19:51:03.346779108 CET | 58148 | 13566 | 192.168.2.13 | 83.222.238.5 |
Jan 8, 2025 19:51:03.350234032 CET | 13566 | 37878 | 83.222.69.33 | 192.168.2.13 |
Jan 8, 2025 19:51:03.350325108 CET | 37878 | 13566 | 192.168.2.13 | 83.222.69.33 |
Jan 8, 2025 19:51:03.351617098 CET | 13566 | 58148 | 83.222.238.5 | 192.168.2.13 |
Jan 8, 2025 19:51:03.351702929 CET | 58148 | 13566 | 192.168.2.13 | 83.222.238.5 |
Jan 8, 2025 19:51:03.368352890 CET | 41736 | 13566 | 192.168.2.13 | 83.222.65.71 |
Jan 8, 2025 19:51:03.373246908 CET | 13566 | 41736 | 83.222.65.71 | 192.168.2.13 |
Jan 8, 2025 19:51:03.373295069 CET | 41736 | 13566 | 192.168.2.13 | 83.222.65.71 |
Jan 8, 2025 19:51:03.393440962 CET | 41736 | 13566 | 192.168.2.13 | 83.222.65.71 |
Jan 8, 2025 19:51:03.394606113 CET | 32890 | 13566 | 192.168.2.13 | 83.222.242.76 |
Jan 8, 2025 19:51:03.397625923 CET | 40364 | 13566 | 192.168.2.13 | 83.222.111.94 |
Jan 8, 2025 19:51:03.398332119 CET | 13566 | 41736 | 83.222.65.71 | 192.168.2.13 |
Jan 8, 2025 19:51:03.398406029 CET | 41736 | 13566 | 192.168.2.13 | 83.222.65.71 |
Jan 8, 2025 19:51:03.399393082 CET | 13566 | 32890 | 83.222.242.76 | 192.168.2.13 |
Jan 8, 2025 19:51:03.399441004 CET | 32890 | 13566 | 192.168.2.13 | 83.222.242.76 |
Jan 8, 2025 19:51:03.400353909 CET | 52810 | 13566 | 192.168.2.13 | 83.222.10.243 |
Jan 8, 2025 19:51:03.402519941 CET | 13566 | 40364 | 83.222.111.94 | 192.168.2.13 |
Jan 8, 2025 19:51:03.402559996 CET | 40364 | 13566 | 192.168.2.13 | 83.222.111.94 |
Jan 8, 2025 19:51:03.403892040 CET | 50176 | 13566 | 192.168.2.13 | 83.222.96.107 |
Jan 8, 2025 19:51:03.405102968 CET | 13566 | 52810 | 83.222.10.243 | 192.168.2.13 |
Jan 8, 2025 19:51:03.405138016 CET | 52810 | 13566 | 192.168.2.13 | 83.222.10.243 |
Jan 8, 2025 19:51:03.406533957 CET | 36946 | 13566 | 192.168.2.13 | 83.222.66.234 |
Jan 8, 2025 19:51:03.408687115 CET | 13566 | 50176 | 83.222.96.107 | 192.168.2.13 |
Jan 8, 2025 19:51:03.408737898 CET | 50176 | 13566 | 192.168.2.13 | 83.222.96.107 |
Jan 8, 2025 19:51:03.410737038 CET | 53918 | 13566 | 192.168.2.13 | 83.222.17.188 |
Jan 8, 2025 19:51:03.411303043 CET | 13566 | 36946 | 83.222.66.234 | 192.168.2.13 |
Jan 8, 2025 19:51:03.411355019 CET | 36946 | 13566 | 192.168.2.13 | 83.222.66.234 |
Jan 8, 2025 19:51:03.414897919 CET | 48816 | 13566 | 192.168.2.13 | 83.222.114.3 |
Jan 8, 2025 19:51:03.415522099 CET | 13566 | 53918 | 83.222.17.188 | 192.168.2.13 |
Jan 8, 2025 19:51:03.415565014 CET | 53918 | 13566 | 192.168.2.13 | 83.222.17.188 |
Jan 8, 2025 19:51:03.419742107 CET | 13566 | 48816 | 83.222.114.3 | 192.168.2.13 |
Jan 8, 2025 19:51:03.419783115 CET | 48816 | 13566 | 192.168.2.13 | 83.222.114.3 |
Jan 8, 2025 19:51:03.420008898 CET | 56114 | 13566 | 192.168.2.13 | 83.222.62.33 |
Jan 8, 2025 19:51:03.424761057 CET | 13566 | 56114 | 83.222.62.33 | 192.168.2.13 |
Jan 8, 2025 19:51:03.424807072 CET | 56114 | 13566 | 192.168.2.13 | 83.222.62.33 |
Jan 8, 2025 19:51:03.425242901 CET | 43002 | 13566 | 192.168.2.13 | 83.222.214.28 |
Jan 8, 2025 19:51:03.428277016 CET | 53344 | 13566 | 192.168.2.13 | 83.222.232.205 |
Jan 8, 2025 19:51:03.430031061 CET | 13566 | 43002 | 83.222.214.28 | 192.168.2.13 |
Jan 8, 2025 19:51:03.430072069 CET | 43002 | 13566 | 192.168.2.13 | 83.222.214.28 |
Jan 8, 2025 19:51:03.431241989 CET | 42126 | 13566 | 192.168.2.13 | 83.222.126.23 |
Jan 8, 2025 19:51:03.433044910 CET | 13566 | 53344 | 83.222.232.205 | 192.168.2.13 |
Jan 8, 2025 19:51:03.433082104 CET | 53344 | 13566 | 192.168.2.13 | 83.222.232.205 |
Jan 8, 2025 19:51:03.435547113 CET | 41072 | 13566 | 192.168.2.13 | 83.222.196.94 |
Jan 8, 2025 19:51:03.436033010 CET | 13566 | 42126 | 83.222.126.23 | 192.168.2.13 |
Jan 8, 2025 19:51:03.436079025 CET | 42126 | 13566 | 192.168.2.13 | 83.222.126.23 |
Jan 8, 2025 19:51:03.437784910 CET | 36086 | 13566 | 192.168.2.13 | 83.222.34.9 |
Jan 8, 2025 19:51:03.440336943 CET | 36256 | 13566 | 192.168.2.13 | 83.222.127.16 |
Jan 8, 2025 19:51:03.440356016 CET | 13566 | 41072 | 83.222.196.94 | 192.168.2.13 |
Jan 8, 2025 19:51:03.440397024 CET | 41072 | 13566 | 192.168.2.13 | 83.222.196.94 |
Jan 8, 2025 19:51:03.442661047 CET | 13566 | 36086 | 83.222.34.9 | 192.168.2.13 |
Jan 8, 2025 19:51:03.442702055 CET | 36086 | 13566 | 192.168.2.13 | 83.222.34.9 |
Jan 8, 2025 19:51:03.443918943 CET | 49458 | 13566 | 192.168.2.13 | 83.222.14.193 |
Jan 8, 2025 19:51:03.445184946 CET | 13566 | 36256 | 83.222.127.16 | 192.168.2.13 |
Jan 8, 2025 19:51:03.445225000 CET | 36256 | 13566 | 192.168.2.13 | 83.222.127.16 |
Jan 8, 2025 19:51:03.448748112 CET | 13566 | 49458 | 83.222.14.193 | 192.168.2.13 |
Jan 8, 2025 19:51:03.448795080 CET | 49458 | 13566 | 192.168.2.13 | 83.222.14.193 |
Jan 8, 2025 19:51:03.450150967 CET | 37556 | 13566 | 192.168.2.13 | 83.222.87.0 |
Jan 8, 2025 19:51:03.453911066 CET | 60788 | 13566 | 192.168.2.13 | 83.222.13.199 |
Jan 8, 2025 19:51:03.454962015 CET | 13566 | 37556 | 83.222.87.0 | 192.168.2.13 |
Jan 8, 2025 19:51:03.455003023 CET | 37556 | 13566 | 192.168.2.13 | 83.222.87.0 |
Jan 8, 2025 19:51:03.458816051 CET | 13566 | 60788 | 83.222.13.199 | 192.168.2.13 |
Jan 8, 2025 19:51:03.458885908 CET | 60788 | 13566 | 192.168.2.13 | 83.222.13.199 |
Jan 8, 2025 19:51:03.472816944 CET | 60788 | 13566 | 192.168.2.13 | 83.222.13.199 |
Jan 8, 2025 19:51:03.475192070 CET | 53438 | 13566 | 192.168.2.13 | 83.222.94.23 |
Jan 8, 2025 19:51:03.477677107 CET | 13566 | 60788 | 83.222.13.199 | 192.168.2.13 |
Jan 8, 2025 19:51:03.477724075 CET | 60788 | 13566 | 192.168.2.13 | 83.222.13.199 |
Jan 8, 2025 19:51:03.479998112 CET | 13566 | 53438 | 83.222.94.23 | 192.168.2.13 |
Jan 8, 2025 19:51:03.480038881 CET | 53438 | 13566 | 192.168.2.13 | 83.222.94.23 |
Jan 8, 2025 19:51:03.480228901 CET | 58076 | 13566 | 192.168.2.13 | 83.222.186.190 |
Jan 8, 2025 19:51:03.484821081 CET | 39534 | 13566 | 192.168.2.13 | 83.222.131.252 |
Jan 8, 2025 19:51:03.484977961 CET | 13566 | 58076 | 83.222.186.190 | 192.168.2.13 |
Jan 8, 2025 19:51:03.485023975 CET | 58076 | 13566 | 192.168.2.13 | 83.222.186.190 |
Jan 8, 2025 19:51:03.487560034 CET | 47284 | 13566 | 192.168.2.13 | 83.222.168.148 |
Jan 8, 2025 19:51:03.489608049 CET | 13566 | 39534 | 83.222.131.252 | 192.168.2.13 |
Jan 8, 2025 19:51:03.489646912 CET | 39534 | 13566 | 192.168.2.13 | 83.222.131.252 |
Jan 8, 2025 19:51:03.490413904 CET | 33432 | 13566 | 192.168.2.13 | 83.222.184.26 |
Jan 8, 2025 19:51:03.492347002 CET | 13566 | 47284 | 83.222.168.148 | 192.168.2.13 |
Jan 8, 2025 19:51:03.492387056 CET | 47284 | 13566 | 192.168.2.13 | 83.222.168.148 |
Jan 8, 2025 19:51:03.493434906 CET | 53084 | 13566 | 192.168.2.13 | 83.222.151.246 |
Jan 8, 2025 19:51:03.495191097 CET | 13566 | 33432 | 83.222.184.26 | 192.168.2.13 |
Jan 8, 2025 19:51:03.495239019 CET | 33432 | 13566 | 192.168.2.13 | 83.222.184.26 |
Jan 8, 2025 19:51:03.497629881 CET | 58420 | 13566 | 192.168.2.13 | 83.222.59.109 |
Jan 8, 2025 19:51:03.498178005 CET | 13566 | 53084 | 83.222.151.246 | 192.168.2.13 |
Jan 8, 2025 19:51:03.498222113 CET | 53084 | 13566 | 192.168.2.13 | 83.222.151.246 |
Jan 8, 2025 19:51:03.500530005 CET | 34540 | 13566 | 192.168.2.13 | 83.222.18.36 |
Jan 8, 2025 19:51:03.502425909 CET | 13566 | 58420 | 83.222.59.109 | 192.168.2.13 |
Jan 8, 2025 19:51:03.502861977 CET | 58420 | 13566 | 192.168.2.13 | 83.222.59.109 |
Jan 8, 2025 19:51:03.505309105 CET | 13566 | 34540 | 83.222.18.36 | 192.168.2.13 |
Jan 8, 2025 19:51:03.505353928 CET | 34540 | 13566 | 192.168.2.13 | 83.222.18.36 |
Jan 8, 2025 19:51:03.505666018 CET | 34540 | 13566 | 192.168.2.13 | 83.222.18.36 |
Jan 8, 2025 19:51:03.507946014 CET | 52136 | 13566 | 192.168.2.13 | 83.222.59.144 |
Jan 8, 2025 19:51:03.510432959 CET | 13566 | 34540 | 83.222.18.36 | 192.168.2.13 |
Jan 8, 2025 19:51:03.510482073 CET | 34540 | 13566 | 192.168.2.13 | 83.222.18.36 |
Jan 8, 2025 19:51:03.511795044 CET | 51030 | 13566 | 192.168.2.13 | 83.222.59.255 |
Jan 8, 2025 19:51:03.512737989 CET | 13566 | 52136 | 83.222.59.144 | 192.168.2.13 |
Jan 8, 2025 19:51:03.512782097 CET | 52136 | 13566 | 192.168.2.13 | 83.222.59.144 |
Jan 8, 2025 19:51:03.516638041 CET | 13566 | 51030 | 83.222.59.255 | 192.168.2.13 |
Jan 8, 2025 19:51:03.516678095 CET | 51030 | 13566 | 192.168.2.13 | 83.222.59.255 |
Jan 8, 2025 19:51:03.520247936 CET | 51030 | 13566 | 192.168.2.13 | 83.222.59.255 |
Jan 8, 2025 19:51:03.521771908 CET | 58874 | 13566 | 192.168.2.13 | 83.222.238.93 |
Jan 8, 2025 19:51:03.524491072 CET | 36732 | 13566 | 192.168.2.13 | 83.222.8.109 |
Jan 8, 2025 19:51:03.525062084 CET | 13566 | 51030 | 83.222.59.255 | 192.168.2.13 |
Jan 8, 2025 19:51:03.525103092 CET | 51030 | 13566 | 192.168.2.13 | 83.222.59.255 |
Jan 8, 2025 19:51:03.526644945 CET | 13566 | 58874 | 83.222.238.93 | 192.168.2.13 |
Jan 8, 2025 19:51:03.526689053 CET | 58874 | 13566 | 192.168.2.13 | 83.222.238.93 |
Jan 8, 2025 19:51:03.527192116 CET | 38432 | 13566 | 192.168.2.13 | 83.222.109.22 |
Jan 8, 2025 19:51:03.529268980 CET | 13566 | 36732 | 83.222.8.109 | 192.168.2.13 |
Jan 8, 2025 19:51:03.529309988 CET | 36732 | 13566 | 192.168.2.13 | 83.222.8.109 |
Jan 8, 2025 19:51:03.529957056 CET | 41550 | 13566 | 192.168.2.13 | 83.222.46.196 |
Jan 8, 2025 19:51:03.531975031 CET | 55124 | 13566 | 192.168.2.13 | 83.222.23.60 |
Jan 8, 2025 19:51:03.532007933 CET | 13566 | 38432 | 83.222.109.22 | 192.168.2.13 |
Jan 8, 2025 19:51:03.532042980 CET | 38432 | 13566 | 192.168.2.13 | 83.222.109.22 |
Jan 8, 2025 19:51:03.534816027 CET | 13566 | 41550 | 83.222.46.196 | 192.168.2.13 |
Jan 8, 2025 19:51:03.534859896 CET | 41550 | 13566 | 192.168.2.13 | 83.222.46.196 |
Jan 8, 2025 19:51:03.536837101 CET | 13566 | 55124 | 83.222.23.60 | 192.168.2.13 |
Jan 8, 2025 19:51:03.536878109 CET | 55124 | 13566 | 192.168.2.13 | 83.222.23.60 |
Jan 8, 2025 19:51:03.537427902 CET | 48464 | 13566 | 192.168.2.13 | 83.222.139.117 |
Jan 8, 2025 19:51:03.540668011 CET | 51318 | 13566 | 192.168.2.13 | 83.222.83.69 |
Jan 8, 2025 19:51:03.542201042 CET | 13566 | 48464 | 83.222.139.117 | 192.168.2.13 |
Jan 8, 2025 19:51:03.542237997 CET | 48464 | 13566 | 192.168.2.13 | 83.222.139.117 |
Jan 8, 2025 19:51:03.543342113 CET | 36466 | 13566 | 192.168.2.13 | 83.222.52.214 |
Jan 8, 2025 19:51:03.545506954 CET | 13566 | 51318 | 83.222.83.69 | 192.168.2.13 |
Jan 8, 2025 19:51:03.545542955 CET | 51318 | 13566 | 192.168.2.13 | 83.222.83.69 |
Jan 8, 2025 19:51:03.546061993 CET | 56584 | 13566 | 192.168.2.13 | 83.222.65.220 |
Jan 8, 2025 19:51:03.548234940 CET | 37308 | 13566 | 192.168.2.13 | 83.222.106.249 |
Jan 8, 2025 19:51:03.548293114 CET | 13566 | 36466 | 83.222.52.214 | 192.168.2.13 |
Jan 8, 2025 19:51:03.548340082 CET | 36466 | 13566 | 192.168.2.13 | 83.222.52.214 |
Jan 8, 2025 19:51:03.550899029 CET | 13566 | 56584 | 83.222.65.220 | 192.168.2.13 |
Jan 8, 2025 19:51:03.550955057 CET | 56584 | 13566 | 192.168.2.13 | 83.222.65.220 |
Jan 8, 2025 19:51:03.550970078 CET | 40136 | 13566 | 192.168.2.13 | 83.222.247.1 |
Jan 8, 2025 19:51:03.553088903 CET | 13566 | 37308 | 83.222.106.249 | 192.168.2.13 |
Jan 8, 2025 19:51:03.553147078 CET | 37308 | 13566 | 192.168.2.13 | 83.222.106.249 |
Jan 8, 2025 19:51:03.553641081 CET | 33924 | 13566 | 192.168.2.13 | 83.222.239.50 |
Jan 8, 2025 19:51:03.555811882 CET | 13566 | 40136 | 83.222.247.1 | 192.168.2.13 |
Jan 8, 2025 19:51:03.555855036 CET | 40136 | 13566 | 192.168.2.13 | 83.222.247.1 |
Jan 8, 2025 19:51:03.556226969 CET | 37524 | 13566 | 192.168.2.13 | 83.222.111.1 |
Jan 8, 2025 19:51:03.558491945 CET | 13566 | 33924 | 83.222.239.50 | 192.168.2.13 |
Jan 8, 2025 19:51:03.558537960 CET | 33924 | 13566 | 192.168.2.13 | 83.222.239.50 |
Jan 8, 2025 19:51:03.560991049 CET | 13566 | 37524 | 83.222.111.1 | 192.168.2.13 |
Jan 8, 2025 19:51:03.561029911 CET | 37524 | 13566 | 192.168.2.13 | 83.222.111.1 |
Jan 8, 2025 19:51:03.562737942 CET | 54196 | 13566 | 192.168.2.13 | 83.222.86.170 |
Jan 8, 2025 19:51:03.566485882 CET | 39804 | 13566 | 192.168.2.13 | 83.222.145.145 |
Jan 8, 2025 19:51:03.567559004 CET | 13566 | 54196 | 83.222.86.170 | 192.168.2.13 |
Jan 8, 2025 19:51:03.567603111 CET | 54196 | 13566 | 192.168.2.13 | 83.222.86.170 |
Jan 8, 2025 19:51:03.570373058 CET | 47238 | 13566 | 192.168.2.13 | 83.222.169.127 |
Jan 8, 2025 19:51:03.571259022 CET | 13566 | 39804 | 83.222.145.145 | 192.168.2.13 |
Jan 8, 2025 19:51:03.571297884 CET | 39804 | 13566 | 192.168.2.13 | 83.222.145.145 |
Jan 8, 2025 19:51:03.572700977 CET | 35142 | 13566 | 192.168.2.13 | 83.222.238.177 |
Jan 8, 2025 19:51:03.575161934 CET | 13566 | 47238 | 83.222.169.127 | 192.168.2.13 |
Jan 8, 2025 19:51:03.575201035 CET | 47238 | 13566 | 192.168.2.13 | 83.222.169.127 |
Jan 8, 2025 19:51:03.576704979 CET | 47496 | 13566 | 192.168.2.13 | 83.222.237.91 |
Jan 8, 2025 19:51:03.577532053 CET | 13566 | 35142 | 83.222.238.177 | 192.168.2.13 |
Jan 8, 2025 19:51:03.577574015 CET | 35142 | 13566 | 192.168.2.13 | 83.222.238.177 |
Jan 8, 2025 19:51:03.580671072 CET | 51658 | 13566 | 192.168.2.13 | 83.222.199.27 |
Jan 8, 2025 19:51:03.581459045 CET | 13566 | 47496 | 83.222.237.91 | 192.168.2.13 |
Jan 8, 2025 19:51:03.581520081 CET | 47496 | 13566 | 192.168.2.13 | 83.222.237.91 |
Jan 8, 2025 19:51:03.584388018 CET | 32960 | 13566 | 192.168.2.13 | 83.222.32.222 |
Jan 8, 2025 19:51:03.585526943 CET | 13566 | 51658 | 83.222.199.27 | 192.168.2.13 |
Jan 8, 2025 19:51:03.585557938 CET | 51658 | 13566 | 192.168.2.13 | 83.222.199.27 |
Jan 8, 2025 19:51:03.587739944 CET | 48938 | 13566 | 192.168.2.13 | 83.222.87.171 |
Jan 8, 2025 19:51:03.589174986 CET | 13566 | 32960 | 83.222.32.222 | 192.168.2.13 |
Jan 8, 2025 19:51:03.589220047 CET | 32960 | 13566 | 192.168.2.13 | 83.222.32.222 |
Jan 8, 2025 19:51:03.592524052 CET | 13566 | 48938 | 83.222.87.171 | 192.168.2.13 |
Jan 8, 2025 19:51:03.592560053 CET | 48938 | 13566 | 192.168.2.13 | 83.222.87.171 |
Jan 8, 2025 19:51:03.592847109 CET | 41910 | 13566 | 192.168.2.13 | 83.222.84.171 |
Jan 8, 2025 19:51:03.597606897 CET | 13566 | 41910 | 83.222.84.171 | 192.168.2.13 |
Jan 8, 2025 19:51:03.597652912 CET | 41910 | 13566 | 192.168.2.13 | 83.222.84.171 |
Jan 8, 2025 19:51:03.613388062 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:51:03.618216038 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:51:03.618263006 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:51:03.622767925 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:51:03.627615929 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:51:03.627661943 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:51:03.632438898 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:51:13.632946968 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:51:13.637836933 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:51:13.839699030 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:51:13.839813948 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:51:14.209110975 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:51:14.209156990 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:52:14.259937048 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:52:14.349162102 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:52:14.607983112 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:52:14.608068943 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 8, 2025 19:52:15.208873034 CET | 13566 | 42766 | 83.222.191.90 | 192.168.2.13 |
Jan 8, 2025 19:52:15.208986998 CET | 42766 | 13566 | 192.168.2.13 | 83.222.191.90 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 8, 2025 19:51:03.599761009 CET | 40404 | 53 | 192.168.2.13 | 8.8.8.8 |
Jan 8, 2025 19:51:03.611172915 CET | 53 | 40404 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 8, 2025 19:51:03.599761009 CET | 192.168.2.13 | 8.8.8.8 | 0xfb52 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 8, 2025 19:51:03.611172915 CET | 8.8.8.8 | 192.168.2.13 | 0xfb52 | No error (0) | 83.222.191.90 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 18:51:02 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | /tmp/Kloki.m68k.elf |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 18:51:02 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 18:51:02 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 18:51:02 |
Start date (UTC): | 08/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/bin/gnome-shell |
Arguments: | /usr/bin/gnome-shell |
File size: | 23168 bytes |
MD5 hash: | da7a257239677622fe4b3a65972c9e87 |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gsd-print-notifications |
Arguments: | /usr/libexec/gsd-print-notifications |
File size: | 51840 bytes |
MD5 hash: | 71539698aa691718cee775d6b9450ae2 |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/libexec/gsd-rfkill |
Arguments: | /usr/libexec/gsd-rfkill |
File size: | 51808 bytes |
MD5 hash: | 88a16a3c0aba1759358c06215ecfb5cc |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 18:51:03 |
Start date (UTC): | 08/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 18:51:13 |
Start date (UTC): | 08/01/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 18:51:13 |
Start date (UTC): | 08/01/2025 |
Path: | /lib/systemd/systemd-user-runtime-dir |
Arguments: | /lib/systemd/systemd-user-runtime-dir stop 127 |
File size: | 22672 bytes |
MD5 hash: | d55f4b0847f88131dbcfb07435178e54 |