Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Kloki.arm5.elf

Overview

General Information

Sample name:Kloki.arm5.elf
Analysis ID:1590979
MD5:5bc43e48f0901f8bd983d197c88b0566
SHA1:0997c945242c542c58964a574e42f6c8c75562a7
SHA256:717575d440f1759e2fa0360ba5454170225aed438e78f45deff748ffbb73c5c2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1590979
Start date and time:2025-01-14 16:56:49 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 8s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.arm5.elf
Detection:MAL
Classification:mal52.spre.linELF@0/0@1/0
Command:/tmp/Kloki.arm5.elf
PID:5597
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5605, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • sh (PID: 5627, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5627, Parent: 1588, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5629, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5629, Parent: 1588, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • sh (PID: 5630, Parent: 1588, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5630, Parent: 1588, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • gdm3 New Fork (PID: 5631, Parent: 1400)
  • Default (PID: 5631, Parent: 1400, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5632, Parent: 1400)
  • Default (PID: 5632, Parent: 1400, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-14T16:58:01.651229+010025000342Misc Attack83.222.191.9013566192.168.2.1342860TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.arm5.elfVirustotal: Detection: 27%Perma Link
Source: Kloki.arm5.elfReversingLabs: Detection: 21%
Source: global trafficTCP traffic: 192.168.2.13:33840 -> 83.222.147.62:13566
Source: global trafficTCP traffic: 192.168.2.13:34240 -> 83.222.98.18:13566
Source: global trafficTCP traffic: 192.168.2.13:34076 -> 83.222.168.12:13566
Source: global trafficTCP traffic: 192.168.2.13:42008 -> 83.222.62.2:13566
Source: global trafficTCP traffic: 192.168.2.13:49032 -> 83.222.139.172:13566
Source: global trafficTCP traffic: 192.168.2.13:55016 -> 83.222.52.191:13566
Source: global trafficTCP traffic: 192.168.2.13:46838 -> 83.222.136.147:13566
Source: global trafficTCP traffic: 192.168.2.13:59670 -> 83.222.49.43:13566
Source: global trafficTCP traffic: 192.168.2.13:57902 -> 83.222.52.94:13566
Source: global trafficTCP traffic: 192.168.2.13:50654 -> 83.222.11.140:13566
Source: global trafficTCP traffic: 192.168.2.13:42068 -> 83.222.124.118:13566
Source: global trafficTCP traffic: 192.168.2.13:33174 -> 83.222.42.95:13566
Source: global trafficTCP traffic: 192.168.2.13:48410 -> 83.222.253.56:13566
Source: global trafficTCP traffic: 192.168.2.13:43710 -> 83.222.15.126:13566
Source: global trafficTCP traffic: 192.168.2.13:43558 -> 83.222.48.82:13566
Source: global trafficTCP traffic: 192.168.2.13:37976 -> 83.222.62.195:13566
Source: global trafficTCP traffic: 192.168.2.13:48526 -> 83.222.144.160:13566
Source: global trafficTCP traffic: 192.168.2.13:44670 -> 83.222.213.56:13566
Source: global trafficTCP traffic: 192.168.2.13:54826 -> 83.222.172.19:13566
Source: global trafficTCP traffic: 192.168.2.13:35504 -> 83.222.58.55:13566
Source: global trafficTCP traffic: 192.168.2.13:45084 -> 83.222.192.110:13566
Source: global trafficTCP traffic: 192.168.2.13:59024 -> 83.222.247.72:13566
Source: global trafficTCP traffic: 192.168.2.13:55910 -> 83.222.1.40:13566
Source: global trafficTCP traffic: 192.168.2.13:54388 -> 83.222.115.53:13566
Source: global trafficTCP traffic: 192.168.2.13:45926 -> 83.222.134.127:13566
Source: global trafficTCP traffic: 192.168.2.13:36096 -> 83.222.194.3:13566
Source: global trafficTCP traffic: 192.168.2.13:56870 -> 83.222.245.236:13566
Source: global trafficTCP traffic: 192.168.2.13:57114 -> 83.222.98.243:13566
Source: global trafficTCP traffic: 192.168.2.13:52276 -> 83.222.36.113:13566
Source: global trafficTCP traffic: 192.168.2.13:59460 -> 83.222.113.84:13566
Source: global trafficTCP traffic: 192.168.2.13:47782 -> 83.222.196.175:13566
Source: global trafficTCP traffic: 192.168.2.13:40052 -> 83.222.24.84:13566
Source: global trafficTCP traffic: 192.168.2.13:58258 -> 83.222.79.237:13566
Source: global trafficTCP traffic: 192.168.2.13:47908 -> 83.222.141.251:13566
Source: global trafficTCP traffic: 192.168.2.13:60466 -> 83.222.1.199:13566
Source: global trafficTCP traffic: 192.168.2.13:54460 -> 83.222.50.193:13566
Source: global trafficTCP traffic: 192.168.2.13:46050 -> 83.222.54.41:13566
Source: global trafficTCP traffic: 192.168.2.13:42506 -> 83.222.9.55:13566
Source: global trafficTCP traffic: 192.168.2.13:52200 -> 83.222.81.125:13566
Source: global trafficTCP traffic: 192.168.2.13:35160 -> 83.222.109.216:13566
Source: global trafficTCP traffic: 192.168.2.13:39340 -> 83.222.252.47:13566
Source: global trafficTCP traffic: 192.168.2.13:33342 -> 83.222.219.241:13566
Source: global trafficTCP traffic: 192.168.2.13:44084 -> 83.222.27.61:13566
Source: global trafficTCP traffic: 192.168.2.13:41800 -> 83.222.228.63:13566
Source: global trafficTCP traffic: 192.168.2.13:53180 -> 83.222.174.85:13566
Source: global trafficTCP traffic: 192.168.2.13:44728 -> 83.222.147.114:13566
Source: global trafficTCP traffic: 192.168.2.13:49008 -> 83.222.4.171:13566
Source: global trafficTCP traffic: 192.168.2.13:36746 -> 83.222.199.83:13566
Source: global trafficTCP traffic: 192.168.2.13:32964 -> 83.222.153.84:13566
Source: global trafficTCP traffic: 192.168.2.13:44678 -> 83.222.78.154:13566
Source: global trafficTCP traffic: 192.168.2.13:52588 -> 83.222.27.129:13566
Source: global trafficTCP traffic: 192.168.2.13:40824 -> 83.222.91.81:13566
Source: global trafficTCP traffic: 192.168.2.13:41698 -> 83.222.170.100:13566
Source: global trafficTCP traffic: 192.168.2.13:35490 -> 83.222.137.252:13566
Source: global trafficTCP traffic: 192.168.2.13:37776 -> 83.222.225.246:13566
Source: global trafficTCP traffic: 192.168.2.13:35810 -> 83.222.212.221:13566
Source: global trafficTCP traffic: 192.168.2.13:57606 -> 83.222.37.175:13566
Source: global trafficTCP traffic: 192.168.2.13:43484 -> 83.222.207.64:13566
Source: global trafficTCP traffic: 192.168.2.13:50192 -> 83.222.236.179:13566
Source: global trafficTCP traffic: 192.168.2.13:54552 -> 83.222.127.154:13566
Source: global trafficTCP traffic: 192.168.2.13:60216 -> 83.222.9.18:13566
Source: global trafficTCP traffic: 192.168.2.13:45148 -> 83.222.13.13:13566
Source: global trafficTCP traffic: 192.168.2.13:40532 -> 83.222.190.212:13566
Source: global trafficTCP traffic: 192.168.2.13:49096 -> 83.222.97.87:13566
Source: global trafficTCP traffic: 192.168.2.13:37112 -> 83.222.40.175:13566
Source: global trafficTCP traffic: 192.168.2.13:42342 -> 83.222.241.67:13566
Source: global trafficTCP traffic: 192.168.2.13:37570 -> 83.222.48.76:13566
Source: global trafficTCP traffic: 192.168.2.13:55936 -> 83.222.149.219:13566
Source: global trafficTCP traffic: 192.168.2.13:59500 -> 83.222.176.30:13566
Source: global trafficTCP traffic: 192.168.2.13:35660 -> 83.222.215.146:13566
Source: global trafficTCP traffic: 192.168.2.13:44668 -> 83.222.20.171:13566
Source: global trafficTCP traffic: 192.168.2.13:50430 -> 83.222.111.57:13566
Source: global trafficTCP traffic: 192.168.2.13:49740 -> 83.222.90.62:13566
Source: global trafficTCP traffic: 192.168.2.13:55086 -> 83.222.121.70:13566
Source: global trafficTCP traffic: 192.168.2.13:37398 -> 83.222.242.248:13566
Source: global trafficTCP traffic: 192.168.2.13:60060 -> 83.222.224.251:13566
Source: global trafficTCP traffic: 192.168.2.13:55782 -> 83.222.10.237:13566
Source: global trafficTCP traffic: 192.168.2.13:50610 -> 83.222.8.200:13566
Source: global trafficTCP traffic: 192.168.2.13:48998 -> 83.222.193.105:13566
Source: global trafficTCP traffic: 192.168.2.13:57322 -> 83.222.31.233:13566
Source: global trafficTCP traffic: 192.168.2.13:49970 -> 83.222.25.16:13566
Source: global trafficTCP traffic: 192.168.2.13:42366 -> 83.222.45.73:13566
Source: global trafficTCP traffic: 192.168.2.13:58902 -> 83.222.92.194:13566
Source: global trafficTCP traffic: 192.168.2.13:47794 -> 83.222.36.13:13566
Source: global trafficTCP traffic: 192.168.2.13:47758 -> 83.222.159.244:13566
Source: global trafficTCP traffic: 192.168.2.13:37218 -> 83.222.166.14:13566
Source: global trafficTCP traffic: 192.168.2.13:34300 -> 83.222.45.0:13566
Source: global trafficTCP traffic: 192.168.2.13:58730 -> 83.222.77.166:13566
Source: global trafficTCP traffic: 192.168.2.13:55190 -> 83.222.70.63:13566
Source: global trafficTCP traffic: 192.168.2.13:37474 -> 83.222.158.39:13566
Source: global trafficTCP traffic: 192.168.2.13:42860 -> 83.222.191.90:13566
Source: /tmp/Kloki.arm5.elf (PID: 5597)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.13:42860
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.147.62
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.147.62
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.98.18
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.98.18
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.12
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.12
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.62.2
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.62.2
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.139.172
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.139.172
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.136.147
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.43
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.94
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.136.147
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.43
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.94
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.94
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.11.140
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.124.118
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.94
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.42.95
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.11.140
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.253.56
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.124.118
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.15.126
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.42.95
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.253.56
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.48.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.15.126
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.62.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.48.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.144.160
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.62.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.56
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.144.160
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.19
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.56
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.58.55
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.19
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.192.110
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.58.55
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.247.72
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.192.110
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.1.40
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.247.72
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.115.53
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru

System Summary

barindex
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 914, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1691, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1866, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1881, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1884, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 3069, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 3246, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 3442, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5579, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5605, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5627, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5629, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5630, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5632, result: successfulJump to behavior
Source: LOAD without section mappingsProgram segment: 0x8000
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 914, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1691, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1866, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1881, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 1884, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 3069, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 3246, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 3442, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5579, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5605, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5627, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5629, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5630, result: successfulJump to behavior
Source: /tmp/Kloki.arm5.elf (PID: 5603)SIGKILL sent: pid: 5632, result: successfulJump to behavior
Source: classification engineClassification label: mal52.spre.linELF@0/0@1/0
Source: Kloki.arm5.elfSubmission file: segment LOAD with 7.889 entropy (max. 8.0)
Source: Kloki.arm5.elfSubmission file: segment LOAD with 7.9801 entropy (max. 8.0)
Source: /tmp/Kloki.arm5.elf (PID: 5597)Queries kernel information via 'uname': Jump to behavior
Source: Kloki.arm5.elf, 5597.1.000055d3fd3ca000.000055d3fd543000.rw-.sdmp, Kloki.arm5.elf, 5601.1.000055d3fd3ca000.000055d3fd543000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: Kloki.arm5.elf, 5597.1.00007ffc61688000.00007ffc616a9000.rw-.sdmp, Kloki.arm5.elf, 5601.1.00007ffc61688000.00007ffc616a9000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/Kloki.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Kloki.arm5.elf
Source: Kloki.arm5.elf, 5597.1.000055d3fd3ca000.000055d3fd543000.rw-.sdmp, Kloki.arm5.elf, 5601.1.000055d3fd3ca000.000055d3fd543000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: Kloki.arm5.elf, 5597.1.00007ffc61688000.00007ffc616a9000.rw-.sdmp, Kloki.arm5.elf, 5601.1.00007ffc61688000.00007ffc616a9000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1590979 Sample: Kloki.arm5.elf Startdate: 14/01/2025 Architecture: LINUX Score: 52 23 83.222.124.118, 13566, 42068 TRI-ASTrueRecordsIncES Russian Federation 2->23 25 83.222.127.154, 13566, 54552 TRI-ASTrueRecordsIncES Russian Federation 2->25 27 89 other IPs or domains 2->27 31 Multi AV Scanner detection for submitted file 2->31 8 Kloki.arm5.elf 2->8         started        10 gnome-session-binary sh gnome-shell 2->10         started        12 gnome-session-binary sh gsd-print-notifications 2->12         started        14 4 other processes 2->14 signatures3 process4 process5 16 Kloki.arm5.elf 8->16         started        process6 18 Kloki.arm5.elf 16->18         started        21 Kloki.arm5.elf 16->21         started        signatures7 29 Sample tries to kill multiple processes (SIGKILL) 18->29
SourceDetectionScannerLabelLink
Kloki.arm5.elf27%VirustotalBrowse
Kloki.arm5.elf21%ReversingLabsLinux.Trojan.Svirtu
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.81.125
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.219.241
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.40.175
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.127.154
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.13.13
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.97.87
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.36.13
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.147.62
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.98.18
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.54.41
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.190.212
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.121.70
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.1.199
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.79.237
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.98.243
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.27.61
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.149.219
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.48.82
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.194.3
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.158.39
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.62.195
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.113.84
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.215.146
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.10.237
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.213.56
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.36.113
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.174.85
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.144.160
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.228.63
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.207.64
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.172.19
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.141.251
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.212.221
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.20.171
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.166.14
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.1.40
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.192.110
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.52.94
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.48.76
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.42.95
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.24.84
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.49.43
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.4.171
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.193.105
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.134.127
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.196.175
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.253.56
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.91.81
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.25.16
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.199.83
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.92.194
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.70.63
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.45.0
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.37.175
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.137.252
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.31.233
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.62.2
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.241.67
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.9.18
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.124.118
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.50.193
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.9.55
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.252.47
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.170.100
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.45.73
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.77.166
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.8.200
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.153.84
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.147.114
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.90.62
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.242.248
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.236.179
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.109.216
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.225.246
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.15.126
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.78.154
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.136.147
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.168.12
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.58.55
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.159.244
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.139.172
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.11.140
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.111.57
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.176.30
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.224.251
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.115.53
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.52.191
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.27.129
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.247.72
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.245.236
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    secure-network-rebirthltd.ruKloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    TRI-ASTrueRecordsIncESKloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.125.253
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.124.60
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.126.23
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.127.227
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.127.11
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.125.205
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.126.31
    https://sazi.online/91150/?utm_source=HueVu&utm_medium=AlluringAngels&utm_campaign=Girls&fbclid=IwAR0edkaxp99ZoQQmBnk5RzNjaLguZlK7xHWUVNwiZ8B5L1Dgxb2UluLI-6UGet hashmaliciousUnknownBrowse
    • 212.124.124.115
    https://sports.zaly.online/57724/Get hashmaliciousUnknownBrowse
    • 212.124.124.8
    skyljne.arm5.elfGet hashmaliciousMiraiBrowse
    • 212.124.111.159
    MASTERHOST-ASMoscowRussiaRUKloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.27.245
    rACq8Eaix6.exeGet hashmaliciousFormBookBrowse
    • 90.156.201.74
    frosty.x86.elfGet hashmaliciousMiraiBrowse
    • 90.156.234.102
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.6.30
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.18.36
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.30.186
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.26.170
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.4.239
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.13.30
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.6.146
    LOL-ASluLUKloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.57.125
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.49.221
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.46.246
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.47.140
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.41.18
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.38.250
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.39.173
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.34.98
    jew.x86.elfGet hashmaliciousUnknownBrowse
    • 85.10.122.249
    ppc.elfGet hashmaliciousMiraiBrowse
    • 85.10.122.239
    ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUKloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.82.17
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.70.81
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.83.69
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.87.13
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.68.210
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.73.212
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.89.90
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.64.159
    skid.x86.elfGet hashmaliciousMoobotBrowse
    • 83.222.64.191
    XfUkJyh9A3.elfGet hashmaliciousMiraiBrowse
    • 37.209.228.199
    SONICDUO-ASRUKloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.217.191
    3.elfGet hashmaliciousUnknownBrowse
    • 178.177.147.162
    res.mips.elfGet hashmaliciousUnknownBrowse
    • 178.178.101.43
    res.m68k.elfGet hashmaliciousUnknownBrowse
    • 109.188.108.84
    frosty.arm.elfGet hashmaliciousMiraiBrowse
    • 178.178.49.3
    Fantazy.mips.elfGet hashmaliciousUnknownBrowse
    • 178.176.79.118
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.223.206
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.214.28
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.221.95
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.222.79
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
    Entropy (8bit):7.9787009809833975
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:Kloki.arm5.elf
    File size:50'956 bytes
    MD5:5bc43e48f0901f8bd983d197c88b0566
    SHA1:0997c945242c542c58964a574e42f6c8c75562a7
    SHA256:717575d440f1759e2fa0360ba5454170225aed438e78f45deff748ffbb73c5c2
    SHA512:2efdde6336f36b16591e054b28f25e40469e959e5746e1d95d5cfc0dc566f503c06414c6ae67688b0517ac3fb8eb5c08a45f37e7fede0579b93b74a89c82e53d
    SSDEEP:768:bgTGTi/i0Uj9cHgZ+5CGEF8o6I4DQJpR5wcgjBz7FhM/oOLLZx9hPMUQDemdJwcN:yGCI9c35w3N48JP5wcwHhROLLZ5louoF
    TLSH:1533F262E45DCDF6C4A42CF2C430A7C511B379B9D9AB7923B4290D9A9D6084702FEFD2
    File Content Preview:.ELF...a..........(.....l4..4...........4. ...(.........................<...........................................Q.td............................\...sfga....................S..........?.E.h;.}...^..........e..(Ig........v................8....=...'!....

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:ARM
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:ARM - ABI
    ABI Version:0
    Entry Point Address:0x4346c
    Flags:0x2
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:40
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80000x80000x10000x2df3c7.88900x6RW 0x8000
    LOAD0x00x380000x380000xc61b0xc61b7.98010x5R E0x8000
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
    2025-01-14T16:58:01.651229+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1342860TCP
    TimestampSource PortDest PortSource IPDest IP
    Jan 14, 2025 16:58:01.275298119 CET3384013566192.168.2.1383.222.147.62
    Jan 14, 2025 16:58:01.280265093 CET135663384083.222.147.62192.168.2.13
    Jan 14, 2025 16:58:01.280317068 CET3384013566192.168.2.1383.222.147.62
    Jan 14, 2025 16:58:01.288315058 CET3424013566192.168.2.1383.222.98.18
    Jan 14, 2025 16:58:01.293297052 CET135663424083.222.98.18192.168.2.13
    Jan 14, 2025 16:58:01.293338060 CET3424013566192.168.2.1383.222.98.18
    Jan 14, 2025 16:58:01.310156107 CET3407613566192.168.2.1383.222.168.12
    Jan 14, 2025 16:58:01.315462112 CET135663407683.222.168.12192.168.2.13
    Jan 14, 2025 16:58:01.315546036 CET3407613566192.168.2.1383.222.168.12
    Jan 14, 2025 16:58:01.316504955 CET4200813566192.168.2.1383.222.62.2
    Jan 14, 2025 16:58:01.321475983 CET135664200883.222.62.2192.168.2.13
    Jan 14, 2025 16:58:01.321531057 CET4200813566192.168.2.1383.222.62.2
    Jan 14, 2025 16:58:01.321875095 CET4903213566192.168.2.1383.222.139.172
    Jan 14, 2025 16:58:01.323667049 CET5501613566192.168.2.1383.222.52.191
    Jan 14, 2025 16:58:01.326694965 CET135664903283.222.139.172192.168.2.13
    Jan 14, 2025 16:58:01.326750040 CET4903213566192.168.2.1383.222.139.172
    Jan 14, 2025 16:58:01.328557014 CET135665501683.222.52.191192.168.2.13
    Jan 14, 2025 16:58:01.328619957 CET5501613566192.168.2.1383.222.52.191
    Jan 14, 2025 16:58:01.331384897 CET5501613566192.168.2.1383.222.52.191
    Jan 14, 2025 16:58:01.336781979 CET135665501683.222.52.191192.168.2.13
    Jan 14, 2025 16:58:01.336844921 CET5501613566192.168.2.1383.222.52.191
    Jan 14, 2025 16:58:01.339750051 CET4683813566192.168.2.1383.222.136.147
    Jan 14, 2025 16:58:01.342329979 CET5967013566192.168.2.1383.222.49.43
    Jan 14, 2025 16:58:01.343575954 CET5790213566192.168.2.1383.222.52.94
    Jan 14, 2025 16:58:01.344618082 CET135664683883.222.136.147192.168.2.13
    Jan 14, 2025 16:58:01.344666958 CET4683813566192.168.2.1383.222.136.147
    Jan 14, 2025 16:58:01.347183943 CET135665967083.222.49.43192.168.2.13
    Jan 14, 2025 16:58:01.347240925 CET5967013566192.168.2.1383.222.49.43
    Jan 14, 2025 16:58:01.348395109 CET135665790283.222.52.94192.168.2.13
    Jan 14, 2025 16:58:01.348448038 CET5790213566192.168.2.1383.222.52.94
    Jan 14, 2025 16:58:01.357784986 CET5790213566192.168.2.1383.222.52.94
    Jan 14, 2025 16:58:01.358966112 CET5065413566192.168.2.1383.222.11.140
    Jan 14, 2025 16:58:01.361913919 CET4206813566192.168.2.1383.222.124.118
    Jan 14, 2025 16:58:01.362721920 CET135665790283.222.52.94192.168.2.13
    Jan 14, 2025 16:58:01.362770081 CET5790213566192.168.2.1383.222.52.94
    Jan 14, 2025 16:58:01.363786936 CET135665065483.222.11.140192.168.2.13
    Jan 14, 2025 16:58:01.363790989 CET3317413566192.168.2.1383.222.42.95
    Jan 14, 2025 16:58:01.363851070 CET5065413566192.168.2.1383.222.11.140
    Jan 14, 2025 16:58:01.366122007 CET4841013566192.168.2.1383.222.253.56
    Jan 14, 2025 16:58:01.366727114 CET135664206883.222.124.118192.168.2.13
    Jan 14, 2025 16:58:01.366774082 CET4206813566192.168.2.1383.222.124.118
    Jan 14, 2025 16:58:01.367706060 CET4371013566192.168.2.1383.222.15.126
    Jan 14, 2025 16:58:01.368637085 CET135663317483.222.42.95192.168.2.13
    Jan 14, 2025 16:58:01.368688107 CET3317413566192.168.2.1383.222.42.95
    Jan 14, 2025 16:58:01.370971918 CET135664841083.222.253.56192.168.2.13
    Jan 14, 2025 16:58:01.371018887 CET4841013566192.168.2.1383.222.253.56
    Jan 14, 2025 16:58:01.371032000 CET4355813566192.168.2.1383.222.48.82
    Jan 14, 2025 16:58:01.372517109 CET135664371083.222.15.126192.168.2.13
    Jan 14, 2025 16:58:01.372562885 CET4371013566192.168.2.1383.222.15.126
    Jan 14, 2025 16:58:01.373651981 CET3797613566192.168.2.1383.222.62.195
    Jan 14, 2025 16:58:01.375858068 CET135664355883.222.48.82192.168.2.13
    Jan 14, 2025 16:58:01.375909090 CET4355813566192.168.2.1383.222.48.82
    Jan 14, 2025 16:58:01.376508951 CET4852613566192.168.2.1383.222.144.160
    Jan 14, 2025 16:58:01.378458023 CET135663797683.222.62.195192.168.2.13
    Jan 14, 2025 16:58:01.378521919 CET3797613566192.168.2.1383.222.62.195
    Jan 14, 2025 16:58:01.379607916 CET4467013566192.168.2.1383.222.213.56
    Jan 14, 2025 16:58:01.381325006 CET135664852683.222.144.160192.168.2.13
    Jan 14, 2025 16:58:01.381370068 CET4852613566192.168.2.1383.222.144.160
    Jan 14, 2025 16:58:01.382770061 CET5482613566192.168.2.1383.222.172.19
    Jan 14, 2025 16:58:01.384392977 CET135664467083.222.213.56192.168.2.13
    Jan 14, 2025 16:58:01.384434938 CET4467013566192.168.2.1383.222.213.56
    Jan 14, 2025 16:58:01.385257006 CET3550413566192.168.2.1383.222.58.55
    Jan 14, 2025 16:58:01.387597084 CET135665482683.222.172.19192.168.2.13
    Jan 14, 2025 16:58:01.387639046 CET5482613566192.168.2.1383.222.172.19
    Jan 14, 2025 16:58:01.388716936 CET4508413566192.168.2.1383.222.192.110
    Jan 14, 2025 16:58:01.390223026 CET135663550483.222.58.55192.168.2.13
    Jan 14, 2025 16:58:01.390279055 CET3550413566192.168.2.1383.222.58.55
    Jan 14, 2025 16:58:01.393058062 CET5902413566192.168.2.1383.222.247.72
    Jan 14, 2025 16:58:01.393465996 CET135664508483.222.192.110192.168.2.13
    Jan 14, 2025 16:58:01.393520117 CET4508413566192.168.2.1383.222.192.110
    Jan 14, 2025 16:58:01.396871090 CET5591013566192.168.2.1383.222.1.40
    Jan 14, 2025 16:58:01.397989035 CET135665902483.222.247.72192.168.2.13
    Jan 14, 2025 16:58:01.398040056 CET5902413566192.168.2.1383.222.247.72
    Jan 14, 2025 16:58:01.398917913 CET5438813566192.168.2.1383.222.115.53
    Jan 14, 2025 16:58:01.400681973 CET4592613566192.168.2.1383.222.134.127
    Jan 14, 2025 16:58:01.401643038 CET135665591083.222.1.40192.168.2.13
    Jan 14, 2025 16:58:01.401681900 CET5591013566192.168.2.1383.222.1.40
    Jan 14, 2025 16:58:01.402014971 CET3609613566192.168.2.1383.222.194.3
    Jan 14, 2025 16:58:01.403395891 CET5687013566192.168.2.1383.222.245.236
    Jan 14, 2025 16:58:01.403701067 CET135665438883.222.115.53192.168.2.13
    Jan 14, 2025 16:58:01.403743029 CET5438813566192.168.2.1383.222.115.53
    Jan 14, 2025 16:58:01.404885054 CET5711413566192.168.2.1383.222.98.243
    Jan 14, 2025 16:58:01.405428886 CET135664592683.222.134.127192.168.2.13
    Jan 14, 2025 16:58:01.405464888 CET4592613566192.168.2.1383.222.134.127
    Jan 14, 2025 16:58:01.406295061 CET5227613566192.168.2.1383.222.36.113
    Jan 14, 2025 16:58:01.406842947 CET135663609683.222.194.3192.168.2.13
    Jan 14, 2025 16:58:01.406887054 CET3609613566192.168.2.1383.222.194.3
    Jan 14, 2025 16:58:01.407339096 CET5946013566192.168.2.1383.222.113.84
    Jan 14, 2025 16:58:01.408166885 CET135665687083.222.245.236192.168.2.13
    Jan 14, 2025 16:58:01.408220053 CET5687013566192.168.2.1383.222.245.236
    Jan 14, 2025 16:58:01.409634113 CET135665711483.222.98.243192.168.2.13
    Jan 14, 2025 16:58:01.409683943 CET5711413566192.168.2.1383.222.98.243
    Jan 14, 2025 16:58:01.410444975 CET4778213566192.168.2.1383.222.196.175
    Jan 14, 2025 16:58:01.411027908 CET135665227683.222.36.113192.168.2.13
    Jan 14, 2025 16:58:01.411068916 CET5227613566192.168.2.1383.222.36.113
    Jan 14, 2025 16:58:01.411740065 CET4005213566192.168.2.1383.222.24.84
    Jan 14, 2025 16:58:01.412118912 CET135665946083.222.113.84192.168.2.13
    Jan 14, 2025 16:58:01.412148952 CET5946013566192.168.2.1383.222.113.84
    Jan 14, 2025 16:58:01.414931059 CET5825813566192.168.2.1383.222.79.237
    Jan 14, 2025 16:58:01.415190935 CET135664778283.222.196.175192.168.2.13
    Jan 14, 2025 16:58:01.415235996 CET4778213566192.168.2.1383.222.196.175
    Jan 14, 2025 16:58:01.416225910 CET4790813566192.168.2.1383.222.141.251
    Jan 14, 2025 16:58:01.416476965 CET135664005283.222.24.84192.168.2.13
    Jan 14, 2025 16:58:01.416512966 CET4005213566192.168.2.1383.222.24.84
    Jan 14, 2025 16:58:01.419713020 CET135665825883.222.79.237192.168.2.13
    Jan 14, 2025 16:58:01.419750929 CET5825813566192.168.2.1383.222.79.237
    Jan 14, 2025 16:58:01.420245886 CET6046613566192.168.2.1383.222.1.199
    Jan 14, 2025 16:58:01.421087027 CET135664790883.222.141.251192.168.2.13
    Jan 14, 2025 16:58:01.421122074 CET4790813566192.168.2.1383.222.141.251
    Jan 14, 2025 16:58:01.422770977 CET5446013566192.168.2.1383.222.50.193
    Jan 14, 2025 16:58:01.425004959 CET135666046683.222.1.199192.168.2.13
    Jan 14, 2025 16:58:01.425035954 CET6046613566192.168.2.1383.222.1.199
    Jan 14, 2025 16:58:01.425214052 CET4605013566192.168.2.1383.222.54.41
    Jan 14, 2025 16:58:01.427586079 CET135665446083.222.50.193192.168.2.13
    Jan 14, 2025 16:58:01.427629948 CET5446013566192.168.2.1383.222.50.193
    Jan 14, 2025 16:58:01.428050995 CET4250613566192.168.2.1383.222.9.55
    Jan 14, 2025 16:58:01.429975033 CET135664605083.222.54.41192.168.2.13
    Jan 14, 2025 16:58:01.430005074 CET4605013566192.168.2.1383.222.54.41
    Jan 14, 2025 16:58:01.432904959 CET135664250683.222.9.55192.168.2.13
    Jan 14, 2025 16:58:01.432957888 CET4250613566192.168.2.1383.222.9.55
    Jan 14, 2025 16:58:01.452266932 CET5220013566192.168.2.1383.222.81.125
    Jan 14, 2025 16:58:01.457176924 CET135665220083.222.81.125192.168.2.13
    Jan 14, 2025 16:58:01.457216024 CET5220013566192.168.2.1383.222.81.125
    Jan 14, 2025 16:58:01.460225105 CET3516013566192.168.2.1383.222.109.216
    Jan 14, 2025 16:58:01.464565992 CET3934013566192.168.2.1383.222.252.47
    Jan 14, 2025 16:58:01.464996099 CET135663516083.222.109.216192.168.2.13
    Jan 14, 2025 16:58:01.465033054 CET3516013566192.168.2.1383.222.109.216
    Jan 14, 2025 16:58:01.467757940 CET3334213566192.168.2.1383.222.219.241
    Jan 14, 2025 16:58:01.469357967 CET135663934083.222.252.47192.168.2.13
    Jan 14, 2025 16:58:01.469400883 CET3934013566192.168.2.1383.222.252.47
    Jan 14, 2025 16:58:01.470982075 CET4408413566192.168.2.1383.222.27.61
    Jan 14, 2025 16:58:01.472556114 CET135663334283.222.219.241192.168.2.13
    Jan 14, 2025 16:58:01.472599030 CET3334213566192.168.2.1383.222.219.241
    Jan 14, 2025 16:58:01.474720955 CET4180013566192.168.2.1383.222.228.63
    Jan 14, 2025 16:58:01.475737095 CET135664408483.222.27.61192.168.2.13
    Jan 14, 2025 16:58:01.475766897 CET4408413566192.168.2.1383.222.27.61
    Jan 14, 2025 16:58:01.478493929 CET5318013566192.168.2.1383.222.174.85
    Jan 14, 2025 16:58:01.479511023 CET135664180083.222.228.63192.168.2.13
    Jan 14, 2025 16:58:01.479558945 CET4180013566192.168.2.1383.222.228.63
    Jan 14, 2025 16:58:01.480946064 CET4472813566192.168.2.1383.222.147.114
    Jan 14, 2025 16:58:01.482969046 CET4900813566192.168.2.1383.222.4.171
    Jan 14, 2025 16:58:01.483259916 CET135665318083.222.174.85192.168.2.13
    Jan 14, 2025 16:58:01.483310938 CET5318013566192.168.2.1383.222.174.85
    Jan 14, 2025 16:58:01.485048056 CET3674613566192.168.2.1383.222.199.83
    Jan 14, 2025 16:58:01.485709906 CET135664472883.222.147.114192.168.2.13
    Jan 14, 2025 16:58:01.485745907 CET4472813566192.168.2.1383.222.147.114
    Jan 14, 2025 16:58:01.487745047 CET135664900883.222.4.171192.168.2.13
    Jan 14, 2025 16:58:01.487787962 CET4900813566192.168.2.1383.222.4.171
    Jan 14, 2025 16:58:01.488053083 CET3296413566192.168.2.1383.222.153.84
    Jan 14, 2025 16:58:01.489805937 CET135663674683.222.199.83192.168.2.13
    Jan 14, 2025 16:58:01.489849091 CET3674613566192.168.2.1383.222.199.83
    Jan 14, 2025 16:58:01.490782976 CET4467813566192.168.2.1383.222.78.154
    Jan 14, 2025 16:58:01.492830038 CET135663296483.222.153.84192.168.2.13
    Jan 14, 2025 16:58:01.492876053 CET3296413566192.168.2.1383.222.153.84
    Jan 14, 2025 16:58:01.495542049 CET135664467883.222.78.154192.168.2.13
    Jan 14, 2025 16:58:01.495579958 CET4467813566192.168.2.1383.222.78.154
    Jan 14, 2025 16:58:01.496887922 CET5258813566192.168.2.1383.222.27.129
    Jan 14, 2025 16:58:01.499506950 CET4082413566192.168.2.1383.222.91.81
    Jan 14, 2025 16:58:01.501667976 CET135665258883.222.27.129192.168.2.13
    Jan 14, 2025 16:58:01.501703024 CET5258813566192.168.2.1383.222.27.129
    Jan 14, 2025 16:58:01.502173901 CET4169813566192.168.2.1383.222.170.100
    Jan 14, 2025 16:58:01.504231930 CET135664082483.222.91.81192.168.2.13
    Jan 14, 2025 16:58:01.504264116 CET4082413566192.168.2.1383.222.91.81
    Jan 14, 2025 16:58:01.504812002 CET3549013566192.168.2.1383.222.137.252
    Jan 14, 2025 16:58:01.506911993 CET135664169883.222.170.100192.168.2.13
    Jan 14, 2025 16:58:01.506959915 CET4169813566192.168.2.1383.222.170.100
    Jan 14, 2025 16:58:01.507349014 CET3777613566192.168.2.1383.222.225.246
    Jan 14, 2025 16:58:01.509557009 CET135663549083.222.137.252192.168.2.13
    Jan 14, 2025 16:58:01.509597063 CET3549013566192.168.2.1383.222.137.252
    Jan 14, 2025 16:58:01.509896994 CET3581013566192.168.2.1383.222.212.221
    Jan 14, 2025 16:58:01.512092113 CET5760613566192.168.2.1383.222.37.175
    Jan 14, 2025 16:58:01.512099028 CET135663777683.222.225.246192.168.2.13
    Jan 14, 2025 16:58:01.512139082 CET3777613566192.168.2.1383.222.225.246
    Jan 14, 2025 16:58:01.514683008 CET135663581083.222.212.221192.168.2.13
    Jan 14, 2025 16:58:01.514729977 CET3581013566192.168.2.1383.222.212.221
    Jan 14, 2025 16:58:01.515903950 CET4348413566192.168.2.1383.222.207.64
    Jan 14, 2025 16:58:01.516839981 CET135665760683.222.37.175192.168.2.13
    Jan 14, 2025 16:58:01.516884089 CET5760613566192.168.2.1383.222.37.175
    Jan 14, 2025 16:58:01.519531012 CET5019213566192.168.2.1383.222.236.179
    Jan 14, 2025 16:58:01.520725965 CET135664348483.222.207.64192.168.2.13
    Jan 14, 2025 16:58:01.520773888 CET4348413566192.168.2.1383.222.207.64
    Jan 14, 2025 16:58:01.522753954 CET5455213566192.168.2.1383.222.127.154
    Jan 14, 2025 16:58:01.524388075 CET135665019283.222.236.179192.168.2.13
    Jan 14, 2025 16:58:01.524425983 CET5019213566192.168.2.1383.222.236.179
    Jan 14, 2025 16:58:01.525991917 CET6021613566192.168.2.1383.222.9.18
    Jan 14, 2025 16:58:01.527522087 CET135665455283.222.127.154192.168.2.13
    Jan 14, 2025 16:58:01.527570963 CET5455213566192.168.2.1383.222.127.154
    Jan 14, 2025 16:58:01.529282093 CET4514813566192.168.2.1383.222.13.13
    Jan 14, 2025 16:58:01.530733109 CET135666021683.222.9.18192.168.2.13
    Jan 14, 2025 16:58:01.530769110 CET6021613566192.168.2.1383.222.9.18
    Jan 14, 2025 16:58:01.532691002 CET4053213566192.168.2.1383.222.190.212
    Jan 14, 2025 16:58:01.534104109 CET135664514883.222.13.13192.168.2.13
    Jan 14, 2025 16:58:01.534137964 CET4514813566192.168.2.1383.222.13.13
    Jan 14, 2025 16:58:01.536066055 CET4909613566192.168.2.1383.222.97.87
    Jan 14, 2025 16:58:01.537435055 CET135664053283.222.190.212192.168.2.13
    Jan 14, 2025 16:58:01.537484884 CET4053213566192.168.2.1383.222.190.212
    Jan 14, 2025 16:58:01.539921999 CET3711213566192.168.2.1383.222.40.175
    Jan 14, 2025 16:58:01.540797949 CET135664909683.222.97.87192.168.2.13
    Jan 14, 2025 16:58:01.540828943 CET4909613566192.168.2.1383.222.97.87
    Jan 14, 2025 16:58:01.542530060 CET4234213566192.168.2.1383.222.241.67
    Jan 14, 2025 16:58:01.544701099 CET135663711283.222.40.175192.168.2.13
    Jan 14, 2025 16:58:01.544744015 CET3711213566192.168.2.1383.222.40.175
    Jan 14, 2025 16:58:01.545195103 CET3757013566192.168.2.1383.222.48.76
    Jan 14, 2025 16:58:01.547274113 CET135664234283.222.241.67192.168.2.13
    Jan 14, 2025 16:58:01.547321081 CET4234213566192.168.2.1383.222.241.67
    Jan 14, 2025 16:58:01.548789024 CET5593613566192.168.2.1383.222.149.219
    Jan 14, 2025 16:58:01.549949884 CET135663757083.222.48.76192.168.2.13
    Jan 14, 2025 16:58:01.549988985 CET3757013566192.168.2.1383.222.48.76
    Jan 14, 2025 16:58:01.551543951 CET5950013566192.168.2.1383.222.176.30
    Jan 14, 2025 16:58:01.553544044 CET135665593683.222.149.219192.168.2.13
    Jan 14, 2025 16:58:01.553587914 CET5593613566192.168.2.1383.222.149.219
    Jan 14, 2025 16:58:01.554363012 CET3566013566192.168.2.1383.222.215.146
    Jan 14, 2025 16:58:01.556354046 CET135665950083.222.176.30192.168.2.13
    Jan 14, 2025 16:58:01.556396961 CET5950013566192.168.2.1383.222.176.30
    Jan 14, 2025 16:58:01.559103012 CET135663566083.222.215.146192.168.2.13
    Jan 14, 2025 16:58:01.559154034 CET3566013566192.168.2.1383.222.215.146
    Jan 14, 2025 16:58:01.560158968 CET4466813566192.168.2.1383.222.20.171
    Jan 14, 2025 16:58:01.563308001 CET5043013566192.168.2.1383.222.111.57
    Jan 14, 2025 16:58:01.564901114 CET135664466883.222.20.171192.168.2.13
    Jan 14, 2025 16:58:01.564953089 CET4466813566192.168.2.1383.222.20.171
    Jan 14, 2025 16:58:01.566752911 CET4974013566192.168.2.1383.222.90.62
    Jan 14, 2025 16:58:01.568059921 CET135665043083.222.111.57192.168.2.13
    Jan 14, 2025 16:58:01.568109035 CET5043013566192.168.2.1383.222.111.57
    Jan 14, 2025 16:58:01.570786953 CET5508613566192.168.2.1383.222.121.70
    Jan 14, 2025 16:58:01.571585894 CET135664974083.222.90.62192.168.2.13
    Jan 14, 2025 16:58:01.571625948 CET4974013566192.168.2.1383.222.90.62
    Jan 14, 2025 16:58:01.574043036 CET3739813566192.168.2.1383.222.242.248
    Jan 14, 2025 16:58:01.575577021 CET135665508683.222.121.70192.168.2.13
    Jan 14, 2025 16:58:01.575619936 CET5508613566192.168.2.1383.222.121.70
    Jan 14, 2025 16:58:01.577176094 CET6006013566192.168.2.1383.222.224.251
    Jan 14, 2025 16:58:01.578766108 CET135663739883.222.242.248192.168.2.13
    Jan 14, 2025 16:58:01.578802109 CET3739813566192.168.2.1383.222.242.248
    Jan 14, 2025 16:58:01.580111980 CET5578213566192.168.2.1383.222.10.237
    Jan 14, 2025 16:58:01.581954002 CET135666006083.222.224.251192.168.2.13
    Jan 14, 2025 16:58:01.581991911 CET6006013566192.168.2.1383.222.224.251
    Jan 14, 2025 16:58:01.583527088 CET5061013566192.168.2.1383.222.8.200
    Jan 14, 2025 16:58:01.584906101 CET135665578283.222.10.237192.168.2.13
    Jan 14, 2025 16:58:01.584940910 CET5578213566192.168.2.1383.222.10.237
    Jan 14, 2025 16:58:01.587007046 CET4899813566192.168.2.1383.222.193.105
    Jan 14, 2025 16:58:01.588247061 CET135665061083.222.8.200192.168.2.13
    Jan 14, 2025 16:58:01.588289022 CET5061013566192.168.2.1383.222.8.200
    Jan 14, 2025 16:58:01.590442896 CET5732213566192.168.2.1383.222.31.233
    Jan 14, 2025 16:58:01.591738939 CET135664899883.222.193.105192.168.2.13
    Jan 14, 2025 16:58:01.591777086 CET4899813566192.168.2.1383.222.193.105
    Jan 14, 2025 16:58:01.594012976 CET4997013566192.168.2.1383.222.25.16
    Jan 14, 2025 16:58:01.595191002 CET135665732283.222.31.233192.168.2.13
    Jan 14, 2025 16:58:01.595235109 CET5732213566192.168.2.1383.222.31.233
    Jan 14, 2025 16:58:01.596965075 CET4236613566192.168.2.1383.222.45.73
    Jan 14, 2025 16:58:01.598810911 CET135664997083.222.25.16192.168.2.13
    Jan 14, 2025 16:58:01.599054098 CET4997013566192.168.2.1383.222.25.16
    Jan 14, 2025 16:58:01.600625038 CET5890213566192.168.2.1383.222.92.194
    Jan 14, 2025 16:58:01.601872921 CET135664236683.222.45.73192.168.2.13
    Jan 14, 2025 16:58:01.601911068 CET4236613566192.168.2.1383.222.45.73
    Jan 14, 2025 16:58:01.603611946 CET4779413566192.168.2.1383.222.36.13
    Jan 14, 2025 16:58:01.605437994 CET135665890283.222.92.194192.168.2.13
    Jan 14, 2025 16:58:01.605474949 CET5890213566192.168.2.1383.222.92.194
    Jan 14, 2025 16:58:01.607285976 CET6007813566192.168.2.1383.222.224.251
    Jan 14, 2025 16:58:01.608393908 CET135664779483.222.36.13192.168.2.13
    Jan 14, 2025 16:58:01.608443022 CET4779413566192.168.2.1383.222.36.13
    Jan 14, 2025 16:58:01.610219002 CET4775813566192.168.2.1383.222.159.244
    Jan 14, 2025 16:58:01.612071037 CET135666007883.222.224.251192.168.2.13
    Jan 14, 2025 16:58:01.612109900 CET6007813566192.168.2.1383.222.224.251
    Jan 14, 2025 16:58:01.613990068 CET3721813566192.168.2.1383.222.166.14
    Jan 14, 2025 16:58:01.614996910 CET135664775883.222.159.244192.168.2.13
    Jan 14, 2025 16:58:01.615044117 CET4775813566192.168.2.1383.222.159.244
    Jan 14, 2025 16:58:01.617041111 CET3430013566192.168.2.1383.222.45.0
    Jan 14, 2025 16:58:01.618807077 CET135663721883.222.166.14192.168.2.13
    Jan 14, 2025 16:58:01.618850946 CET3721813566192.168.2.1383.222.166.14
    Jan 14, 2025 16:58:01.621068001 CET5873013566192.168.2.1383.222.77.166
    Jan 14, 2025 16:58:01.621814966 CET135663430083.222.45.0192.168.2.13
    Jan 14, 2025 16:58:01.621879101 CET3430013566192.168.2.1383.222.45.0
    Jan 14, 2025 16:58:01.624049902 CET5519013566192.168.2.1383.222.70.63
    Jan 14, 2025 16:58:01.625932932 CET135665873083.222.77.166192.168.2.13
    Jan 14, 2025 16:58:01.625982046 CET5873013566192.168.2.1383.222.77.166
    Jan 14, 2025 16:58:01.627912998 CET3747413566192.168.2.1383.222.158.39
    Jan 14, 2025 16:58:01.628902912 CET135665519083.222.70.63192.168.2.13
    Jan 14, 2025 16:58:01.628954887 CET5519013566192.168.2.1383.222.70.63
    Jan 14, 2025 16:58:01.632694960 CET135663747483.222.158.39192.168.2.13
    Jan 14, 2025 16:58:01.632744074 CET3747413566192.168.2.1383.222.158.39
    Jan 14, 2025 16:58:01.646332026 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:58:01.651228905 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:58:01.651302099 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:58:01.654700994 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:58:01.659563065 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:58:01.659620047 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:58:01.664398909 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:58:11.664911985 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:58:11.669785023 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:58:11.878386974 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:58:11.878470898 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:58:12.254390001 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:58:12.254499912 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:59:12.306452990 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:59:12.311430931 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:59:12.520499945 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:59:12.520605087 CET4286013566192.168.2.1383.222.191.90
    Jan 14, 2025 16:59:13.453150034 CET135664286083.222.191.90192.168.2.13
    Jan 14, 2025 16:59:13.453274012 CET4286013566192.168.2.1383.222.191.90
    TimestampSource PortDest PortSource IPDest IP
    Jan 14, 2025 16:58:01.634536982 CET4257853192.168.2.138.8.8.8
    Jan 14, 2025 16:58:01.644057989 CET53425788.8.8.8192.168.2.13
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jan 14, 2025 16:58:01.634536982 CET192.168.2.138.8.8.80x5df3Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jan 14, 2025 16:58:01.644057989 CET8.8.8.8192.168.2.130x5df3No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:/tmp/Kloki.arm5.elf
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/bin/gnome-shell
    Arguments:/usr/bin/gnome-shell
    File size:23168 bytes
    MD5 hash:da7a257239677622fe4b3a65972c9e87

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gsd-print-notifications
    Arguments:/usr/libexec/gsd-print-notifications
    File size:51840 bytes
    MD5 hash:71539698aa691718cee775d6b9450ae2

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gsd-rfkill
    Arguments:/usr/libexec/gsd-rfkill
    File size:51808 bytes
    MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):15:58:00
    Start date (UTC):14/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c