Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Kloki.arm4.elf

Overview

General Information

Sample name:Kloki.arm4.elf
Analysis ID:1591029
MD5:b1f3a500f6313f6580d511bd121673fb
SHA1:8551921306b456d3d31e61768e125e235f3d691e
SHA256:04773b2be8239ff774f0549a81559504c1dcdd4556c3aa8a28a77b285e02348b
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1591029
Start date and time:2025-01-14 17:05:02 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 39s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.arm4.elf
Detection:MAL
Classification:mal52.spre.linELF@0/0@1/0
Command:/tmp/Kloki.arm4.elf
PID:5476
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5484, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 5484, Parent: 1383, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • sh (PID: 5505, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5505, Parent: 1383, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5507, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5507, Parent: 1383, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • sh (PID: 5508, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5508, Parent: 1383, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • gdm3 New Fork (PID: 5509, Parent: 1289)
  • Default (PID: 5509, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5511, Parent: 1289)
  • Default (PID: 5511, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5522, Parent: 1)
  • systemd-user-runtime-dir (PID: 5522, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-14T17:05:46.793673+010025000342Misc Attack83.222.191.9013566192.168.2.1456532TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.arm4.elfVirustotal: Detection: 28%Perma Link
Source: Kloki.arm4.elfReversingLabs: Detection: 21%
Source: global trafficTCP traffic: 192.168.2.14:44418 -> 83.222.42.25:13566
Source: global trafficTCP traffic: 192.168.2.14:56394 -> 83.222.186.220:13566
Source: global trafficTCP traffic: 192.168.2.14:35422 -> 83.222.145.130:13566
Source: global trafficTCP traffic: 192.168.2.14:41850 -> 83.222.71.157:13566
Source: global trafficTCP traffic: 192.168.2.14:48112 -> 83.222.15.195:13566
Source: global trafficTCP traffic: 192.168.2.14:39990 -> 83.222.166.183:13566
Source: global trafficTCP traffic: 192.168.2.14:37770 -> 83.222.50.111:13566
Source: global trafficTCP traffic: 192.168.2.14:43808 -> 83.222.87.183:13566
Source: global trafficTCP traffic: 192.168.2.14:43900 -> 83.222.0.13:13566
Source: global trafficTCP traffic: 192.168.2.14:38756 -> 83.222.22.43:13566
Source: global trafficTCP traffic: 192.168.2.14:55124 -> 83.222.252.160:13566
Source: global trafficTCP traffic: 192.168.2.14:46234 -> 83.222.199.144:13566
Source: global trafficTCP traffic: 192.168.2.14:40108 -> 83.222.185.126:13566
Source: global trafficTCP traffic: 192.168.2.14:40058 -> 83.222.241.195:13566
Source: global trafficTCP traffic: 192.168.2.14:51738 -> 83.222.97.189:13566
Source: global trafficTCP traffic: 192.168.2.14:59710 -> 83.222.245.140:13566
Source: global trafficTCP traffic: 192.168.2.14:57602 -> 83.222.214.175:13566
Source: global trafficTCP traffic: 192.168.2.14:59526 -> 83.222.104.103:13566
Source: global trafficTCP traffic: 192.168.2.14:37964 -> 83.222.49.175:13566
Source: global trafficTCP traffic: 192.168.2.14:38924 -> 83.222.4.65:13566
Source: global trafficTCP traffic: 192.168.2.14:54960 -> 83.222.114.171:13566
Source: global trafficTCP traffic: 192.168.2.14:55108 -> 83.222.248.165:13566
Source: global trafficTCP traffic: 192.168.2.14:46936 -> 83.222.26.79:13566
Source: global trafficTCP traffic: 192.168.2.14:41652 -> 83.222.92.26:13566
Source: global trafficTCP traffic: 192.168.2.14:47044 -> 83.222.93.115:13566
Source: global trafficTCP traffic: 192.168.2.14:43830 -> 83.222.69.89:13566
Source: global trafficTCP traffic: 192.168.2.14:43552 -> 83.222.19.12:13566
Source: global trafficTCP traffic: 192.168.2.14:42186 -> 83.222.233.204:13566
Source: global trafficTCP traffic: 192.168.2.14:39530 -> 83.222.138.218:13566
Source: global trafficTCP traffic: 192.168.2.14:45588 -> 83.222.144.235:13566
Source: global trafficTCP traffic: 192.168.2.14:43794 -> 83.222.151.133:13566
Source: global trafficTCP traffic: 192.168.2.14:35930 -> 83.222.119.109:13566
Source: global trafficTCP traffic: 192.168.2.14:45814 -> 83.222.53.223:13566
Source: global trafficTCP traffic: 192.168.2.14:44126 -> 83.222.212.102:13566
Source: global trafficTCP traffic: 192.168.2.14:58610 -> 83.222.143.217:13566
Source: global trafficTCP traffic: 192.168.2.14:44972 -> 83.222.167.1:13566
Source: global trafficTCP traffic: 192.168.2.14:49228 -> 83.222.132.160:13566
Source: global trafficTCP traffic: 192.168.2.14:53980 -> 83.222.166.158:13566
Source: global trafficTCP traffic: 192.168.2.14:49334 -> 83.222.239.3:13566
Source: global trafficTCP traffic: 192.168.2.14:51802 -> 83.222.184.76:13566
Source: global trafficTCP traffic: 192.168.2.14:46320 -> 83.222.118.253:13566
Source: global trafficTCP traffic: 192.168.2.14:46958 -> 83.222.165.137:13566
Source: global trafficTCP traffic: 192.168.2.14:59142 -> 83.222.9.142:13566
Source: global trafficTCP traffic: 192.168.2.14:53646 -> 83.222.86.147:13566
Source: global trafficTCP traffic: 192.168.2.14:52198 -> 83.222.104.230:13566
Source: global trafficTCP traffic: 192.168.2.14:57998 -> 83.222.126.255:13566
Source: global trafficTCP traffic: 192.168.2.14:44760 -> 83.222.107.246:13566
Source: global trafficTCP traffic: 192.168.2.14:33808 -> 83.222.108.160:13566
Source: global trafficTCP traffic: 192.168.2.14:36864 -> 83.222.213.65:13566
Source: global trafficTCP traffic: 192.168.2.14:45506 -> 83.222.7.100:13566
Source: global trafficTCP traffic: 192.168.2.14:45578 -> 83.222.26.174:13566
Source: global trafficTCP traffic: 192.168.2.14:36918 -> 83.222.102.158:13566
Source: global trafficTCP traffic: 192.168.2.14:51876 -> 83.222.78.12:13566
Source: global trafficTCP traffic: 192.168.2.14:54180 -> 83.222.60.62:13566
Source: global trafficTCP traffic: 192.168.2.14:56718 -> 83.222.15.244:13566
Source: global trafficTCP traffic: 192.168.2.14:54610 -> 83.222.138.133:13566
Source: global trafficTCP traffic: 192.168.2.14:53008 -> 83.222.241.48:13566
Source: global trafficTCP traffic: 192.168.2.14:38316 -> 83.222.15.250:13566
Source: global trafficTCP traffic: 192.168.2.14:40570 -> 83.222.190.101:13566
Source: global trafficTCP traffic: 192.168.2.14:33022 -> 83.222.141.39:13566
Source: global trafficTCP traffic: 192.168.2.14:33176 -> 83.222.75.11:13566
Source: global trafficTCP traffic: 192.168.2.14:53636 -> 83.222.38.182:13566
Source: global trafficTCP traffic: 192.168.2.14:41244 -> 83.222.1.147:13566
Source: global trafficTCP traffic: 192.168.2.14:47658 -> 83.222.87.215:13566
Source: global trafficTCP traffic: 192.168.2.14:54972 -> 83.222.212.94:13566
Source: global trafficTCP traffic: 192.168.2.14:51152 -> 83.222.59.238:13566
Source: global trafficTCP traffic: 192.168.2.14:45820 -> 83.222.12.161:13566
Source: global trafficTCP traffic: 192.168.2.14:57442 -> 83.222.140.91:13566
Source: global trafficTCP traffic: 192.168.2.14:44476 -> 83.222.174.200:13566
Source: global trafficTCP traffic: 192.168.2.14:60630 -> 83.222.153.189:13566
Source: global trafficTCP traffic: 192.168.2.14:58448 -> 83.222.188.35:13566
Source: global trafficTCP traffic: 192.168.2.14:37108 -> 83.222.67.173:13566
Source: global trafficTCP traffic: 192.168.2.14:59770 -> 83.222.83.82:13566
Source: global trafficTCP traffic: 192.168.2.14:52102 -> 83.222.167.18:13566
Source: global trafficTCP traffic: 192.168.2.14:42594 -> 83.222.183.52:13566
Source: global trafficTCP traffic: 192.168.2.14:43372 -> 83.222.57.2:13566
Source: global trafficTCP traffic: 192.168.2.14:46808 -> 83.222.63.95:13566
Source: global trafficTCP traffic: 192.168.2.14:42618 -> 83.222.184.65:13566
Source: global trafficTCP traffic: 192.168.2.14:35218 -> 83.222.242.15:13566
Source: global trafficTCP traffic: 192.168.2.14:36138 -> 83.222.24.198:13566
Source: global trafficTCP traffic: 192.168.2.14:59888 -> 83.222.109.83:13566
Source: global trafficTCP traffic: 192.168.2.14:36480 -> 83.222.180.122:13566
Source: global trafficTCP traffic: 192.168.2.14:49230 -> 83.222.245.64:13566
Source: global trafficTCP traffic: 192.168.2.14:56368 -> 83.222.213.163:13566
Source: global trafficTCP traffic: 192.168.2.14:40420 -> 83.222.8.110:13566
Source: global trafficTCP traffic: 192.168.2.14:53138 -> 83.222.96.196:13566
Source: global trafficTCP traffic: 192.168.2.14:35048 -> 83.222.145.163:13566
Source: global trafficTCP traffic: 192.168.2.14:35332 -> 83.222.113.229:13566
Source: global trafficTCP traffic: 192.168.2.14:55652 -> 83.222.245.24:13566
Source: global trafficTCP traffic: 192.168.2.14:56104 -> 83.222.247.172:13566
Source: global trafficTCP traffic: 192.168.2.14:47992 -> 83.222.76.48:13566
Source: global trafficTCP traffic: 192.168.2.14:52660 -> 83.222.174.140:13566
Source: global trafficTCP traffic: 192.168.2.14:56176 -> 83.222.143.103:13566
Source: global trafficTCP traffic: 192.168.2.14:45746 -> 83.222.205.130:13566
Source: global trafficTCP traffic: 192.168.2.14:57498 -> 83.222.118.229:13566
Source: global trafficTCP traffic: 192.168.2.14:40002 -> 83.222.72.228:13566
Source: global trafficTCP traffic: 192.168.2.14:46726 -> 83.222.56.253:13566
Source: global trafficTCP traffic: 192.168.2.14:47992 -> 83.222.94.45:13566
Source: global trafficTCP traffic: 192.168.2.14:56532 -> 83.222.191.90:13566
Source: /tmp/Kloki.arm4.elf (PID: 5476)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.14:56532
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.42.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.42.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.42.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.42.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.186.220
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.145.130
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.71.157
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.186.220
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.145.130
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.71.157
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.15.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.166.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.50.111
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.15.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.166.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.87.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.0.13
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.50.111
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.87.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.22.43
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.0.13
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.252.160
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.22.43
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.199.144
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.252.160
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.185.126
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.199.144
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.241.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.185.126
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.97.189
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.241.195
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.245.140
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.97.189
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.214.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.245.140
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.104.103
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.214.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.104.103
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.114.171
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.248.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.26.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.114.171
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.248.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.26.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.26.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.92.26
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru

System Summary

barindex
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5459, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5484, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5505, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5507, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5508, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5509, result: successfulJump to behavior
Source: LOAD without section mappingsProgram segment: 0x8000
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5459, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5484, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5505, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5507, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5508, result: successfulJump to behavior
Source: /tmp/Kloki.arm4.elf (PID: 5482)SIGKILL sent: pid: 5509, result: successfulJump to behavior
Source: classification engineClassification label: mal52.spre.linELF@0/0@1/0
Source: Kloki.arm4.elfSubmission file: segment LOAD with 7.8919 entropy (max. 8.0)
Source: Kloki.arm4.elfSubmission file: segment LOAD with 7.9798 entropy (max. 8.0)
Source: /tmp/Kloki.arm4.elf (PID: 5476)Queries kernel information via 'uname': Jump to behavior
Source: Kloki.arm4.elf, 5476.1.00007fff2a160000.00007fff2a181000.rw-.sdmp, Kloki.arm4.elf, 5480.1.00007fff2a160000.00007fff2a181000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/Kloki.arm4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Kloki.arm4.elf
Source: Kloki.arm4.elf, 5476.1.000055a25efc8000.000055a25f141000.rw-.sdmp, Kloki.arm4.elf, 5480.1.000055a25efc8000.000055a25f141000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: Kloki.arm4.elf, 5476.1.000055a25efc8000.000055a25f141000.rw-.sdmp, Kloki.arm4.elf, 5480.1.000055a25efc8000.000055a25f141000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: Kloki.arm4.elf, 5476.1.00007fff2a160000.00007fff2a181000.rw-.sdmp, Kloki.arm4.elf, 5480.1.00007fff2a160000.00007fff2a181000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1591029 Sample: Kloki.arm4.elf Startdate: 14/01/2025 Architecture: LINUX Score: 52 23 83.222.165.137, 13566, 46958 WAVENETLB Bulgaria 2->23 25 83.222.126.255, 13566, 57998 TRI-ASTrueRecordsIncES Russian Federation 2->25 27 97 other IPs or domains 2->27 31 Multi AV Scanner detection for submitted file 2->31 8 Kloki.arm4.elf 2->8         started        10 gnome-session-binary sh gsd-sharing 2->10         started        12 gnome-session-binary sh gnome-shell 2->12         started        14 5 other processes 2->14 signatures3 process4 process5 16 Kloki.arm4.elf 8->16         started        process6 18 Kloki.arm4.elf 16->18         started        21 Kloki.arm4.elf 16->21         started        signatures7 29 Sample tries to kill multiple processes (SIGKILL) 18->29
SourceDetectionScannerLabelLink
Kloki.arm4.elf29%VirustotalBrowse
Kloki.arm4.elf21%ReversingLabsLinux.Trojan.Svirtu
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.15.250
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.86.147
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.7.100
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.83.82
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.12.161
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.4.65
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.186.220
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.247.172
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.143.103
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.67.173
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.71.157
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.49.175
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.174.200
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.212.102
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.233.204
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.87.183
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.214.175
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.57.2
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.109.83
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.184.76
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.165.137
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.118.253
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.212.94
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.213.65
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.60.62
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.1.147
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.15.195
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.104.103
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.19.12
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.108.160
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.76.48
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.199.144
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.145.130
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.140.91
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.184.65
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.245.24
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.72.228
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.87.215
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.38.182
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.69.89
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.153.189
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.15.244
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.166.183
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.56.253
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.205.130
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.104.230
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.138.218
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.0.13
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.126.255
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.53.223
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.119.109
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.114.171
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.252.160
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.241.195
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.180.122
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.144.235
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.241.48
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.242.15
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.96.196
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.75.11
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.118.229
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.78.12
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.102.158
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.151.133
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.92.26
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.94.45
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.9.142
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.248.165
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.107.246
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.8.110
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.59.238
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.63.95
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.185.126
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.24.198
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.93.115
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.166.158
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.188.35
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.132.160
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.183.52
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.50.111
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.245.64
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.167.18
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.245.140
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.26.79
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.113.229
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.174.140
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.97.189
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.42.25
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.26.174
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.239.3
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.190.101
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.145.163
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.138.133
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.141.39
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.143.217
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.22.43
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.167.1
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.213.163
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.184.65Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      secure-network-rebirthltd.ruKloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      MASTERHOST-ASMoscowRussiaRUKloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.27.129
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.27.245
      rACq8Eaix6.exeGet hashmaliciousFormBookBrowse
      • 90.156.201.74
      frosty.x86.elfGet hashmaliciousMiraiBrowse
      • 90.156.234.102
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.6.30
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.18.36
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.30.186
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.26.170
      Kloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.4.239
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.13.30
      MASTERHOST-ASMoscowRussiaRUKloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.27.129
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.27.245
      rACq8Eaix6.exeGet hashmaliciousFormBookBrowse
      • 90.156.201.74
      frosty.x86.elfGet hashmaliciousMiraiBrowse
      • 90.156.234.102
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.6.30
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.18.36
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.30.186
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.26.170
      Kloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.4.239
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.13.30
      ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUKloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.78.154
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.82.17
      Kloki.arm7.elfGet hashmaliciousUnknownBrowse
      • 83.222.70.81
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.83.69
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.87.13
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.68.210
      Kloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.73.212
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.89.90
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.64.159
      skid.x86.elfGet hashmaliciousMoobotBrowse
      • 83.222.64.191
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
      Entropy (8bit):7.978501152570999
      TrID:
      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
      File name:Kloki.arm4.elf
      File size:52'492 bytes
      MD5:b1f3a500f6313f6580d511bd121673fb
      SHA1:8551921306b456d3d31e61768e125e235f3d691e
      SHA256:04773b2be8239ff774f0549a81559504c1dcdd4556c3aa8a28a77b285e02348b
      SHA512:a3dda12bb35abe16202f086834c5a1bfeb3bb2084fa0df8d4d0e73caa0011452513db507b8b1c1b345dc9349eaec494ed5e3a3cf699135963ad033f5e365c081
      SSDEEP:768:Rhlj99J7ZaMOB6RIwqD2z896wloUQoC9KUq0LxtkZQ9HfK53UGR:Rhlx9J7ZaMOBcqD2zMNloUTCwUqstEZR
      TLSH:113302E11E42D9F0D7394D39F15D929ED7561EBCD0A1B03B220882407B8253FAACE5AB
      File Content Preview:.ELF...a..........(.....d:..4...........4. ...(.....................................................................Q.td............................\...sfga........`...`.......S..........?.E.h;.}...^..........f?..S......{.#yq...><.N.=....m..G.|.v.........

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:ARM
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:ARM - ABI
      ABI Version:0
      Entry Point Address:0x43a64
      Flags:0x202
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:0
      Section Header Size:40
      Number of Section Headers:0
      Header String Table Index:0
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x80000x80000x10000x2edbc7.89190x6RW 0x8000
      LOAD0x00x380000x380000xcc130xcc137.97980x5R E0x8000
      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
      2025-01-14T17:05:46.793673+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1456532TCP
      TimestampSource PortDest PortSource IPDest IP
      Jan 14, 2025 17:05:46.356303930 CET4441813566192.168.2.1483.222.42.25
      Jan 14, 2025 17:05:46.361994982 CET135664441883.222.42.25192.168.2.14
      Jan 14, 2025 17:05:46.362047911 CET4441813566192.168.2.1483.222.42.25
      Jan 14, 2025 17:05:46.363142967 CET4441813566192.168.2.1483.222.42.25
      Jan 14, 2025 17:05:46.368622065 CET135664441883.222.42.25192.168.2.14
      Jan 14, 2025 17:05:46.368663073 CET4441813566192.168.2.1483.222.42.25
      Jan 14, 2025 17:05:46.377497911 CET5639413566192.168.2.1483.222.186.220
      Jan 14, 2025 17:05:46.381254911 CET3542213566192.168.2.1483.222.145.130
      Jan 14, 2025 17:05:46.382534981 CET4185013566192.168.2.1483.222.71.157
      Jan 14, 2025 17:05:46.382687092 CET135665639483.222.186.220192.168.2.14
      Jan 14, 2025 17:05:46.382733107 CET5639413566192.168.2.1483.222.186.220
      Jan 14, 2025 17:05:46.386552095 CET135663542283.222.145.130192.168.2.14
      Jan 14, 2025 17:05:46.386601925 CET3542213566192.168.2.1483.222.145.130
      Jan 14, 2025 17:05:46.387671947 CET135664185083.222.71.157192.168.2.14
      Jan 14, 2025 17:05:46.387706041 CET4185013566192.168.2.1483.222.71.157
      Jan 14, 2025 17:05:46.395334959 CET4811213566192.168.2.1483.222.15.195
      Jan 14, 2025 17:05:46.398016930 CET3999013566192.168.2.1483.222.166.183
      Jan 14, 2025 17:05:46.400376081 CET3777013566192.168.2.1483.222.50.111
      Jan 14, 2025 17:05:46.400866985 CET135664811283.222.15.195192.168.2.14
      Jan 14, 2025 17:05:46.400911093 CET4811213566192.168.2.1483.222.15.195
      Jan 14, 2025 17:05:46.402818918 CET135663999083.222.166.183192.168.2.14
      Jan 14, 2025 17:05:46.402864933 CET3999013566192.168.2.1483.222.166.183
      Jan 14, 2025 17:05:46.402978897 CET4380813566192.168.2.1483.222.87.183
      Jan 14, 2025 17:05:46.406043053 CET4390013566192.168.2.1483.222.0.13
      Jan 14, 2025 17:05:46.406177044 CET135663777083.222.50.111192.168.2.14
      Jan 14, 2025 17:05:46.406207085 CET3777013566192.168.2.1483.222.50.111
      Jan 14, 2025 17:05:46.407699108 CET135664380883.222.87.183192.168.2.14
      Jan 14, 2025 17:05:46.407732010 CET4380813566192.168.2.1483.222.87.183
      Jan 14, 2025 17:05:46.409863949 CET3875613566192.168.2.1483.222.22.43
      Jan 14, 2025 17:05:46.410878897 CET135664390083.222.0.13192.168.2.14
      Jan 14, 2025 17:05:46.410908937 CET4390013566192.168.2.1483.222.0.13
      Jan 14, 2025 17:05:46.413469076 CET5512413566192.168.2.1483.222.252.160
      Jan 14, 2025 17:05:46.414638996 CET135663875683.222.22.43192.168.2.14
      Jan 14, 2025 17:05:46.414691925 CET3875613566192.168.2.1483.222.22.43
      Jan 14, 2025 17:05:46.416843891 CET4623413566192.168.2.1483.222.199.144
      Jan 14, 2025 17:05:46.418940067 CET135665512483.222.252.160192.168.2.14
      Jan 14, 2025 17:05:46.418975115 CET5512413566192.168.2.1483.222.252.160
      Jan 14, 2025 17:05:46.420260906 CET4010813566192.168.2.1483.222.185.126
      Jan 14, 2025 17:05:46.421932936 CET135664623483.222.199.144192.168.2.14
      Jan 14, 2025 17:05:46.421973944 CET4623413566192.168.2.1483.222.199.144
      Jan 14, 2025 17:05:46.423957109 CET4005813566192.168.2.1483.222.241.195
      Jan 14, 2025 17:05:46.425297022 CET135664010883.222.185.126192.168.2.14
      Jan 14, 2025 17:05:46.425355911 CET4010813566192.168.2.1483.222.185.126
      Jan 14, 2025 17:05:46.428625107 CET5173813566192.168.2.1483.222.97.189
      Jan 14, 2025 17:05:46.428714037 CET135664005883.222.241.195192.168.2.14
      Jan 14, 2025 17:05:46.428755999 CET4005813566192.168.2.1483.222.241.195
      Jan 14, 2025 17:05:46.431961060 CET5971013566192.168.2.1483.222.245.140
      Jan 14, 2025 17:05:46.434067011 CET135665173883.222.97.189192.168.2.14
      Jan 14, 2025 17:05:46.434112072 CET5173813566192.168.2.1483.222.97.189
      Jan 14, 2025 17:05:46.435348988 CET5760213566192.168.2.1483.222.214.175
      Jan 14, 2025 17:05:46.437124968 CET135665971083.222.245.140192.168.2.14
      Jan 14, 2025 17:05:46.437160015 CET5971013566192.168.2.1483.222.245.140
      Jan 14, 2025 17:05:46.437170029 CET5952613566192.168.2.1483.222.104.103
      Jan 14, 2025 17:05:46.440892935 CET135665760283.222.214.175192.168.2.14
      Jan 14, 2025 17:05:46.440937996 CET5760213566192.168.2.1483.222.214.175
      Jan 14, 2025 17:05:46.441910028 CET3796413566192.168.2.1483.222.49.175
      Jan 14, 2025 17:05:46.442344904 CET135665952683.222.104.103192.168.2.14
      Jan 14, 2025 17:05:46.442382097 CET5952613566192.168.2.1483.222.104.103
      Jan 14, 2025 17:05:46.444565058 CET3892413566192.168.2.1483.222.4.65
      Jan 14, 2025 17:05:46.446655035 CET135663796483.222.49.175192.168.2.14
      Jan 14, 2025 17:05:46.446695089 CET3796413566192.168.2.1483.222.49.175
      Jan 14, 2025 17:05:46.449297905 CET135663892483.222.4.65192.168.2.14
      Jan 14, 2025 17:05:46.449340105 CET3892413566192.168.2.1483.222.4.65
      Jan 14, 2025 17:05:46.449852943 CET5496013566192.168.2.1483.222.114.171
      Jan 14, 2025 17:05:46.451986074 CET5510813566192.168.2.1483.222.248.165
      Jan 14, 2025 17:05:46.453471899 CET4693613566192.168.2.1483.222.26.79
      Jan 14, 2025 17:05:46.454658985 CET135665496083.222.114.171192.168.2.14
      Jan 14, 2025 17:05:46.454727888 CET5496013566192.168.2.1483.222.114.171
      Jan 14, 2025 17:05:46.457051039 CET135665510883.222.248.165192.168.2.14
      Jan 14, 2025 17:05:46.457115889 CET5510813566192.168.2.1483.222.248.165
      Jan 14, 2025 17:05:46.458414078 CET135664693683.222.26.79192.168.2.14
      Jan 14, 2025 17:05:46.458461046 CET4693613566192.168.2.1483.222.26.79
      Jan 14, 2025 17:05:46.473284960 CET4693613566192.168.2.1483.222.26.79
      Jan 14, 2025 17:05:46.474602938 CET4165213566192.168.2.1483.222.92.26
      Jan 14, 2025 17:05:46.476339102 CET4704413566192.168.2.1483.222.93.115
      Jan 14, 2025 17:05:46.478982925 CET135664693683.222.26.79192.168.2.14
      Jan 14, 2025 17:05:46.479043961 CET4693613566192.168.2.1483.222.26.79
      Jan 14, 2025 17:05:46.479387999 CET135664165283.222.92.26192.168.2.14
      Jan 14, 2025 17:05:46.479439974 CET4165213566192.168.2.1483.222.92.26
      Jan 14, 2025 17:05:46.481182098 CET135664704483.222.93.115192.168.2.14
      Jan 14, 2025 17:05:46.481224060 CET4704413566192.168.2.1483.222.93.115
      Jan 14, 2025 17:05:46.481286049 CET4704413566192.168.2.1483.222.93.115
      Jan 14, 2025 17:05:46.483290911 CET4383013566192.168.2.1483.222.69.89
      Jan 14, 2025 17:05:46.486591101 CET135664704483.222.93.115192.168.2.14
      Jan 14, 2025 17:05:46.486639023 CET4704413566192.168.2.1483.222.93.115
      Jan 14, 2025 17:05:46.487514019 CET4355213566192.168.2.1483.222.19.12
      Jan 14, 2025 17:05:46.488084078 CET135664383083.222.69.89192.168.2.14
      Jan 14, 2025 17:05:46.488141060 CET4383013566192.168.2.1483.222.69.89
      Jan 14, 2025 17:05:46.491044998 CET4218613566192.168.2.1483.222.233.204
      Jan 14, 2025 17:05:46.492331028 CET135664355283.222.19.12192.168.2.14
      Jan 14, 2025 17:05:46.492384911 CET4355213566192.168.2.1483.222.19.12
      Jan 14, 2025 17:05:46.493817091 CET3953013566192.168.2.1483.222.138.218
      Jan 14, 2025 17:05:46.496248007 CET4558813566192.168.2.1483.222.144.235
      Jan 14, 2025 17:05:46.496376038 CET135664218683.222.233.204192.168.2.14
      Jan 14, 2025 17:05:46.496423960 CET4218613566192.168.2.1483.222.233.204
      Jan 14, 2025 17:05:46.498452902 CET4379413566192.168.2.1483.222.151.133
      Jan 14, 2025 17:05:46.500329971 CET135663953083.222.138.218192.168.2.14
      Jan 14, 2025 17:05:46.500369072 CET3953013566192.168.2.1483.222.138.218
      Jan 14, 2025 17:05:46.500957966 CET3593013566192.168.2.1483.222.119.109
      Jan 14, 2025 17:05:46.502212048 CET4581413566192.168.2.1483.222.53.223
      Jan 14, 2025 17:05:46.503684044 CET135664558883.222.144.235192.168.2.14
      Jan 14, 2025 17:05:46.503732920 CET4558813566192.168.2.1483.222.144.235
      Jan 14, 2025 17:05:46.505525112 CET4412613566192.168.2.1483.222.212.102
      Jan 14, 2025 17:05:46.505532026 CET135664379483.222.151.133192.168.2.14
      Jan 14, 2025 17:05:46.505584002 CET4379413566192.168.2.1483.222.151.133
      Jan 14, 2025 17:05:46.508274078 CET135663593083.222.119.109192.168.2.14
      Jan 14, 2025 17:05:46.508320093 CET3593013566192.168.2.1483.222.119.109
      Jan 14, 2025 17:05:46.508558989 CET135664581483.222.53.223192.168.2.14
      Jan 14, 2025 17:05:46.508595943 CET4581413566192.168.2.1483.222.53.223
      Jan 14, 2025 17:05:46.509324074 CET5861013566192.168.2.1483.222.143.217
      Jan 14, 2025 17:05:46.511502981 CET135664412683.222.212.102192.168.2.14
      Jan 14, 2025 17:05:46.511540890 CET4412613566192.168.2.1483.222.212.102
      Jan 14, 2025 17:05:46.511796951 CET4497213566192.168.2.1483.222.167.1
      Jan 14, 2025 17:05:46.514379978 CET4922813566192.168.2.1483.222.132.160
      Jan 14, 2025 17:05:46.515348911 CET135665861083.222.143.217192.168.2.14
      Jan 14, 2025 17:05:46.515388966 CET5861013566192.168.2.1483.222.143.217
      Jan 14, 2025 17:05:46.516818047 CET5398013566192.168.2.1483.222.166.158
      Jan 14, 2025 17:05:46.517311096 CET135664497283.222.167.1192.168.2.14
      Jan 14, 2025 17:05:46.517349958 CET4497213566192.168.2.1483.222.167.1
      Jan 14, 2025 17:05:46.519361019 CET4933413566192.168.2.1483.222.239.3
      Jan 14, 2025 17:05:46.520057917 CET135664922883.222.132.160192.168.2.14
      Jan 14, 2025 17:05:46.520098925 CET4922813566192.168.2.1483.222.132.160
      Jan 14, 2025 17:05:46.522557974 CET5180213566192.168.2.1483.222.184.76
      Jan 14, 2025 17:05:46.523451090 CET135665398083.222.166.158192.168.2.14
      Jan 14, 2025 17:05:46.523495913 CET5398013566192.168.2.1483.222.166.158
      Jan 14, 2025 17:05:46.525588036 CET135664933483.222.239.3192.168.2.14
      Jan 14, 2025 17:05:46.525628090 CET4933413566192.168.2.1483.222.239.3
      Jan 14, 2025 17:05:46.527935982 CET4632013566192.168.2.1483.222.118.253
      Jan 14, 2025 17:05:46.529495955 CET135665180283.222.184.76192.168.2.14
      Jan 14, 2025 17:05:46.529534101 CET5180213566192.168.2.1483.222.184.76
      Jan 14, 2025 17:05:46.531320095 CET4695813566192.168.2.1483.222.165.137
      Jan 14, 2025 17:05:46.533366919 CET135664632083.222.118.253192.168.2.14
      Jan 14, 2025 17:05:46.533406019 CET4632013566192.168.2.1483.222.118.253
      Jan 14, 2025 17:05:46.534394026 CET5914213566192.168.2.1483.222.9.142
      Jan 14, 2025 17:05:46.537067890 CET5364613566192.168.2.1483.222.86.147
      Jan 14, 2025 17:05:46.537327051 CET135664695883.222.165.137192.168.2.14
      Jan 14, 2025 17:05:46.537359953 CET4695813566192.168.2.1483.222.165.137
      Jan 14, 2025 17:05:46.539350033 CET135665914283.222.9.142192.168.2.14
      Jan 14, 2025 17:05:46.539388895 CET5914213566192.168.2.1483.222.9.142
      Jan 14, 2025 17:05:46.539729118 CET5219813566192.168.2.1483.222.104.230
      Jan 14, 2025 17:05:46.541822910 CET135665364683.222.86.147192.168.2.14
      Jan 14, 2025 17:05:46.541862965 CET5364613566192.168.2.1483.222.86.147
      Jan 14, 2025 17:05:46.542383909 CET5799813566192.168.2.1483.222.126.255
      Jan 14, 2025 17:05:46.544470072 CET135665219883.222.104.230192.168.2.14
      Jan 14, 2025 17:05:46.544507980 CET5219813566192.168.2.1483.222.104.230
      Jan 14, 2025 17:05:46.544945002 CET4476013566192.168.2.1483.222.107.246
      Jan 14, 2025 17:05:46.547610044 CET3380813566192.168.2.1483.222.108.160
      Jan 14, 2025 17:05:46.548562050 CET135665799883.222.126.255192.168.2.14
      Jan 14, 2025 17:05:46.548612118 CET5799813566192.168.2.1483.222.126.255
      Jan 14, 2025 17:05:46.549685001 CET135664476083.222.107.246192.168.2.14
      Jan 14, 2025 17:05:46.549727917 CET4476013566192.168.2.1483.222.107.246
      Jan 14, 2025 17:05:46.549866915 CET3686413566192.168.2.1483.222.213.65
      Jan 14, 2025 17:05:46.552351952 CET4550613566192.168.2.1483.222.7.100
      Jan 14, 2025 17:05:46.552423000 CET135663380883.222.108.160192.168.2.14
      Jan 14, 2025 17:05:46.552473068 CET3380813566192.168.2.1483.222.108.160
      Jan 14, 2025 17:05:46.555138111 CET135663686483.222.213.65192.168.2.14
      Jan 14, 2025 17:05:46.555176020 CET3686413566192.168.2.1483.222.213.65
      Jan 14, 2025 17:05:46.555404902 CET4557813566192.168.2.1483.222.26.174
      Jan 14, 2025 17:05:46.557097912 CET135664550683.222.7.100192.168.2.14
      Jan 14, 2025 17:05:46.557132006 CET4550613566192.168.2.1483.222.7.100
      Jan 14, 2025 17:05:46.558330059 CET3691813566192.168.2.1483.222.102.158
      Jan 14, 2025 17:05:46.560158968 CET135664557883.222.26.174192.168.2.14
      Jan 14, 2025 17:05:46.560198069 CET4557813566192.168.2.1483.222.26.174
      Jan 14, 2025 17:05:46.560864925 CET5187613566192.168.2.1483.222.78.12
      Jan 14, 2025 17:05:46.562268019 CET5418013566192.168.2.1483.222.60.62
      Jan 14, 2025 17:05:46.563179016 CET135663691883.222.102.158192.168.2.14
      Jan 14, 2025 17:05:46.563215017 CET3691813566192.168.2.1483.222.102.158
      Jan 14, 2025 17:05:46.566360950 CET5671813566192.168.2.1483.222.15.244
      Jan 14, 2025 17:05:46.566905022 CET135665187683.222.78.12192.168.2.14
      Jan 14, 2025 17:05:46.566941977 CET5187613566192.168.2.1483.222.78.12
      Jan 14, 2025 17:05:46.568639994 CET135665418083.222.60.62192.168.2.14
      Jan 14, 2025 17:05:46.568686962 CET5418013566192.168.2.1483.222.60.62
      Jan 14, 2025 17:05:46.570111036 CET5461013566192.168.2.1483.222.138.133
      Jan 14, 2025 17:05:46.572504997 CET135665671883.222.15.244192.168.2.14
      Jan 14, 2025 17:05:46.572536945 CET5671813566192.168.2.1483.222.15.244
      Jan 14, 2025 17:05:46.573772907 CET5300813566192.168.2.1483.222.241.48
      Jan 14, 2025 17:05:46.576812983 CET3831613566192.168.2.1483.222.15.250
      Jan 14, 2025 17:05:46.577533960 CET135665461083.222.138.133192.168.2.14
      Jan 14, 2025 17:05:46.577570915 CET5461013566192.168.2.1483.222.138.133
      Jan 14, 2025 17:05:46.580636024 CET4057013566192.168.2.1483.222.190.101
      Jan 14, 2025 17:05:46.580899000 CET135665300883.222.241.48192.168.2.14
      Jan 14, 2025 17:05:46.580931902 CET5300813566192.168.2.1483.222.241.48
      Jan 14, 2025 17:05:46.583558083 CET3302213566192.168.2.1483.222.141.39
      Jan 14, 2025 17:05:46.584408045 CET135663831683.222.15.250192.168.2.14
      Jan 14, 2025 17:05:46.584439993 CET3831613566192.168.2.1483.222.15.250
      Jan 14, 2025 17:05:46.587397099 CET3317613566192.168.2.1483.222.75.11
      Jan 14, 2025 17:05:46.588002920 CET135664057083.222.190.101192.168.2.14
      Jan 14, 2025 17:05:46.588042021 CET4057013566192.168.2.1483.222.190.101
      Jan 14, 2025 17:05:46.590763092 CET5363613566192.168.2.1483.222.38.182
      Jan 14, 2025 17:05:46.590871096 CET135663302283.222.141.39192.168.2.14
      Jan 14, 2025 17:05:46.590909004 CET3302213566192.168.2.1483.222.141.39
      Jan 14, 2025 17:05:46.595051050 CET135663317683.222.75.11192.168.2.14
      Jan 14, 2025 17:05:46.595098972 CET3317613566192.168.2.1483.222.75.11
      Jan 14, 2025 17:05:46.595599890 CET4124413566192.168.2.1483.222.1.147
      Jan 14, 2025 17:05:46.598520994 CET135665363683.222.38.182192.168.2.14
      Jan 14, 2025 17:05:46.598567963 CET5363613566192.168.2.1483.222.38.182
      Jan 14, 2025 17:05:46.598584890 CET4765813566192.168.2.1483.222.87.215
      Jan 14, 2025 17:05:46.602263927 CET5497213566192.168.2.1483.222.212.94
      Jan 14, 2025 17:05:46.602433920 CET135664124483.222.1.147192.168.2.14
      Jan 14, 2025 17:05:46.602467060 CET4124413566192.168.2.1483.222.1.147
      Jan 14, 2025 17:05:46.604981899 CET135664765883.222.87.215192.168.2.14
      Jan 14, 2025 17:05:46.605030060 CET4765813566192.168.2.1483.222.87.215
      Jan 14, 2025 17:05:46.605360985 CET5115213566192.168.2.1483.222.59.238
      Jan 14, 2025 17:05:46.609426022 CET4582013566192.168.2.1483.222.12.161
      Jan 14, 2025 17:05:46.609838963 CET135665497283.222.212.94192.168.2.14
      Jan 14, 2025 17:05:46.609888077 CET5497213566192.168.2.1483.222.212.94
      Jan 14, 2025 17:05:46.612854958 CET135665115283.222.59.238192.168.2.14
      Jan 14, 2025 17:05:46.612927914 CET5744213566192.168.2.1483.222.140.91
      Jan 14, 2025 17:05:46.612931013 CET5115213566192.168.2.1483.222.59.238
      Jan 14, 2025 17:05:46.617010117 CET135664582083.222.12.161192.168.2.14
      Jan 14, 2025 17:05:46.617059946 CET4582013566192.168.2.1483.222.12.161
      Jan 14, 2025 17:05:46.617181063 CET4447613566192.168.2.1483.222.174.200
      Jan 14, 2025 17:05:46.620630980 CET135665744283.222.140.91192.168.2.14
      Jan 14, 2025 17:05:46.620660067 CET6063013566192.168.2.1483.222.153.189
      Jan 14, 2025 17:05:46.620676041 CET5744213566192.168.2.1483.222.140.91
      Jan 14, 2025 17:05:46.624756098 CET135664447683.222.174.200192.168.2.14
      Jan 14, 2025 17:05:46.624819994 CET4447613566192.168.2.1483.222.174.200
      Jan 14, 2025 17:05:46.625014067 CET5844813566192.168.2.1483.222.188.35
      Jan 14, 2025 17:05:46.628134966 CET135666063083.222.153.189192.168.2.14
      Jan 14, 2025 17:05:46.628177881 CET6063013566192.168.2.1483.222.153.189
      Jan 14, 2025 17:05:46.628335953 CET3710813566192.168.2.1483.222.67.173
      Jan 14, 2025 17:05:46.632386923 CET135665844883.222.188.35192.168.2.14
      Jan 14, 2025 17:05:46.632488012 CET5844813566192.168.2.1483.222.188.35
      Jan 14, 2025 17:05:46.632870913 CET5977013566192.168.2.1483.222.83.82
      Jan 14, 2025 17:05:46.635890007 CET135663710883.222.67.173192.168.2.14
      Jan 14, 2025 17:05:46.635972023 CET3710813566192.168.2.1483.222.67.173
      Jan 14, 2025 17:05:46.637821913 CET5210213566192.168.2.1483.222.167.18
      Jan 14, 2025 17:05:46.640537977 CET135665977083.222.83.82192.168.2.14
      Jan 14, 2025 17:05:46.640593052 CET5977013566192.168.2.1483.222.83.82
      Jan 14, 2025 17:05:46.643364906 CET4259413566192.168.2.1483.222.183.52
      Jan 14, 2025 17:05:46.643589973 CET135665210283.222.167.18192.168.2.14
      Jan 14, 2025 17:05:46.643639088 CET5210213566192.168.2.1483.222.167.18
      Jan 14, 2025 17:05:46.647067070 CET4337213566192.168.2.1483.222.57.2
      Jan 14, 2025 17:05:46.649512053 CET135664259483.222.183.52192.168.2.14
      Jan 14, 2025 17:05:46.649594069 CET4259413566192.168.2.1483.222.183.52
      Jan 14, 2025 17:05:46.652362108 CET4680813566192.168.2.1483.222.63.95
      Jan 14, 2025 17:05:46.653666973 CET135664337283.222.57.2192.168.2.14
      Jan 14, 2025 17:05:46.653709888 CET4337213566192.168.2.1483.222.57.2
      Jan 14, 2025 17:05:46.656383991 CET4261813566192.168.2.1483.222.184.65
      Jan 14, 2025 17:05:46.658668041 CET135664680883.222.63.95192.168.2.14
      Jan 14, 2025 17:05:46.658719063 CET4680813566192.168.2.1483.222.63.95
      Jan 14, 2025 17:05:46.661514044 CET3521813566192.168.2.1483.222.242.15
      Jan 14, 2025 17:05:46.663664103 CET135664261883.222.184.65192.168.2.14
      Jan 14, 2025 17:05:46.663713932 CET4261813566192.168.2.1483.222.184.65
      Jan 14, 2025 17:05:46.666277885 CET3613813566192.168.2.1483.222.24.198
      Jan 14, 2025 17:05:46.669187069 CET135663521883.222.242.15192.168.2.14
      Jan 14, 2025 17:05:46.669235945 CET3521813566192.168.2.1483.222.242.15
      Jan 14, 2025 17:05:46.671866894 CET5988813566192.168.2.1483.222.109.83
      Jan 14, 2025 17:05:46.673546076 CET135663613883.222.24.198192.168.2.14
      Jan 14, 2025 17:05:46.673607111 CET3613813566192.168.2.1483.222.24.198
      Jan 14, 2025 17:05:46.676429987 CET3648013566192.168.2.1483.222.180.122
      Jan 14, 2025 17:05:46.676634073 CET135665988883.222.109.83192.168.2.14
      Jan 14, 2025 17:05:46.676709890 CET5988813566192.168.2.1483.222.109.83
      Jan 14, 2025 17:05:46.681776047 CET4923013566192.168.2.1483.222.245.64
      Jan 14, 2025 17:05:46.682765961 CET135663648083.222.180.122192.168.2.14
      Jan 14, 2025 17:05:46.682832956 CET3648013566192.168.2.1483.222.180.122
      Jan 14, 2025 17:05:46.686506033 CET5636813566192.168.2.1483.222.213.163
      Jan 14, 2025 17:05:46.687794924 CET135664923083.222.245.64192.168.2.14
      Jan 14, 2025 17:05:46.687835932 CET4923013566192.168.2.1483.222.245.64
      Jan 14, 2025 17:05:46.691958904 CET4042013566192.168.2.1483.222.8.110
      Jan 14, 2025 17:05:46.692799091 CET135665636883.222.213.163192.168.2.14
      Jan 14, 2025 17:05:46.692848921 CET5636813566192.168.2.1483.222.213.163
      Jan 14, 2025 17:05:46.696219921 CET5313813566192.168.2.1483.222.96.196
      Jan 14, 2025 17:05:46.697724104 CET135664042083.222.8.110192.168.2.14
      Jan 14, 2025 17:05:46.697788954 CET4042013566192.168.2.1483.222.8.110
      Jan 14, 2025 17:05:46.701925039 CET3504813566192.168.2.1483.222.145.163
      Jan 14, 2025 17:05:46.702393055 CET135665313883.222.96.196192.168.2.14
      Jan 14, 2025 17:05:46.702450991 CET5313813566192.168.2.1483.222.96.196
      Jan 14, 2025 17:05:46.706283092 CET3533213566192.168.2.1483.222.113.229
      Jan 14, 2025 17:05:46.707727909 CET135663504883.222.145.163192.168.2.14
      Jan 14, 2025 17:05:46.707791090 CET3504813566192.168.2.1483.222.145.163
      Jan 14, 2025 17:05:46.711108923 CET135663533283.222.113.229192.168.2.14
      Jan 14, 2025 17:05:46.711153984 CET3533213566192.168.2.1483.222.113.229
      Jan 14, 2025 17:05:46.711944103 CET5565213566192.168.2.1483.222.245.24
      Jan 14, 2025 17:05:46.716285944 CET5610413566192.168.2.1483.222.247.172
      Jan 14, 2025 17:05:46.716773987 CET135665565283.222.245.24192.168.2.14
      Jan 14, 2025 17:05:46.716828108 CET5565213566192.168.2.1483.222.245.24
      Jan 14, 2025 17:05:46.721088886 CET135665610483.222.247.172192.168.2.14
      Jan 14, 2025 17:05:46.721131086 CET5610413566192.168.2.1483.222.247.172
      Jan 14, 2025 17:05:46.722064972 CET4799213566192.168.2.1483.222.76.48
      Jan 14, 2025 17:05:46.726185083 CET5266013566192.168.2.1483.222.174.140
      Jan 14, 2025 17:05:46.726953030 CET135664799283.222.76.48192.168.2.14
      Jan 14, 2025 17:05:46.727035999 CET4799213566192.168.2.1483.222.76.48
      Jan 14, 2025 17:05:46.731013060 CET135665266083.222.174.140192.168.2.14
      Jan 14, 2025 17:05:46.731362104 CET5266013566192.168.2.1483.222.174.140
      Jan 14, 2025 17:05:46.732182026 CET5617613566192.168.2.1483.222.143.103
      Jan 14, 2025 17:05:46.736999035 CET135665617683.222.143.103192.168.2.14
      Jan 14, 2025 17:05:46.737051010 CET5617613566192.168.2.1483.222.143.103
      Jan 14, 2025 17:05:46.738101006 CET4574613566192.168.2.1483.222.205.130
      Jan 14, 2025 17:05:46.743052006 CET135664574683.222.205.130192.168.2.14
      Jan 14, 2025 17:05:46.743161917 CET4574613566192.168.2.1483.222.205.130
      Jan 14, 2025 17:05:46.743722916 CET5749813566192.168.2.1483.222.118.229
      Jan 14, 2025 17:05:46.748526096 CET135665749883.222.118.229192.168.2.14
      Jan 14, 2025 17:05:46.748589993 CET5749813566192.168.2.1483.222.118.229
      Jan 14, 2025 17:05:46.767393112 CET5749813566192.168.2.1483.222.118.229
      Jan 14, 2025 17:05:46.769370079 CET4000213566192.168.2.1483.222.72.228
      Jan 14, 2025 17:05:46.772339106 CET135665749883.222.118.229192.168.2.14
      Jan 14, 2025 17:05:46.772383928 CET5749813566192.168.2.1483.222.118.229
      Jan 14, 2025 17:05:46.772845030 CET4672613566192.168.2.1483.222.56.253
      Jan 14, 2025 17:05:46.774249077 CET135664000283.222.72.228192.168.2.14
      Jan 14, 2025 17:05:46.774816036 CET4000213566192.168.2.1483.222.72.228
      Jan 14, 2025 17:05:46.777090073 CET4799213566192.168.2.1483.222.94.45
      Jan 14, 2025 17:05:46.777667046 CET135664672683.222.56.253192.168.2.14
      Jan 14, 2025 17:05:46.777719975 CET4672613566192.168.2.1483.222.56.253
      Jan 14, 2025 17:05:46.781948090 CET135664799283.222.94.45192.168.2.14
      Jan 14, 2025 17:05:46.781999111 CET4799213566192.168.2.1483.222.94.45
      Jan 14, 2025 17:05:46.788811922 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:05:46.793673038 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:05:46.793845892 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:05:46.795269966 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:05:46.800076008 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:05:46.800124884 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:05:46.805135012 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:05:56.805047989 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:05:56.810722113 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:05:57.015492916 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:05:57.015549898 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:05:57.390358925 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:05:57.390559912 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:06:57.426773071 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:06:57.431652069 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:06:57.638056993 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:06:57.638181925 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:06:59.408638000 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:06:59.408751965 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:06:59.409826040 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:06:59.409861088 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:06:59.411304951 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:06:59.411340952 CET5653213566192.168.2.1483.222.191.90
      Jan 14, 2025 17:06:59.411776066 CET135665653283.222.191.90192.168.2.14
      Jan 14, 2025 17:06:59.411812067 CET5653213566192.168.2.1483.222.191.90
      TimestampSource PortDest PortSource IPDest IP
      Jan 14, 2025 17:05:46.781250954 CET4624453192.168.2.148.8.8.8
      Jan 14, 2025 17:05:46.787801027 CET53462448.8.8.8192.168.2.14
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 14, 2025 17:05:46.781250954 CET192.168.2.148.8.8.80xb556Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 14, 2025 17:05:46.787801027 CET8.8.8.8192.168.2.140xb556No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

      System Behavior

      Start time (UTC):16:05:44
      Start date (UTC):14/01/2025
      Path:/tmp/Kloki.arm4.elf
      Arguments:/tmp/Kloki.arm4.elf
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/tmp/Kloki.arm4.elf
      Arguments:-
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/tmp/Kloki.arm4.elf
      Arguments:-
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/tmp/Kloki.arm4.elf
      Arguments:-
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/bin/sh
      Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/libexec/gsd-sharing
      Arguments:/usr/libexec/gsd-sharing
      File size:35424 bytes
      MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/bin/sh
      Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/bin/gnome-shell
      Arguments:/usr/bin/gnome-shell
      File size:23168 bytes
      MD5 hash:da7a257239677622fe4b3a65972c9e87

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/bin/sh
      Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/libexec/gsd-print-notifications
      Arguments:/usr/libexec/gsd-print-notifications
      File size:51840 bytes
      MD5 hash:71539698aa691718cee775d6b9450ae2

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/bin/sh
      Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/libexec/gsd-rfkill
      Arguments:/usr/libexec/gsd-rfkill
      File size:51808 bytes
      MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/sbin/gdm3
      Arguments:-
      File size:453296 bytes
      MD5 hash:2492e2d8d34f9377e3e530a61a15674f

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/etc/gdm3/PrimeOff/Default
      Arguments:/etc/gdm3/PrimeOff/Default
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/usr/sbin/gdm3
      Arguments:-
      File size:453296 bytes
      MD5 hash:2492e2d8d34f9377e3e530a61a15674f

      Start time (UTC):16:05:45
      Start date (UTC):14/01/2025
      Path:/etc/gdm3/PrimeOff/Default
      Arguments:/etc/gdm3/PrimeOff/Default
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):16:05:55
      Start date (UTC):14/01/2025
      Path:/usr/lib/systemd/systemd
      Arguments:-
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      Start time (UTC):16:05:55
      Start date (UTC):14/01/2025
      Path:/lib/systemd/systemd-user-runtime-dir
      Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
      File size:22672 bytes
      MD5 hash:d55f4b0847f88131dbcfb07435178e54