Edit tour
Linux
Analysis Report
Kloki.m68k.elf
Overview
General Information
Sample name: | Kloki.m68k.elf |
Analysis ID: | 1591042 |
MD5: | 944b6d159ab3e092bd836ab50ace5726 |
SHA1: | 14c0788721e4ab73da1eff990a53d5110379af60 |
SHA256: | 58e3cfde1874c8b530ff43057d1eeb2e5daa7aa25b75682c6e09bf3b5921b27c |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591042 |
Start date and time: | 2025-01-14 17:13:36 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | Kloki.m68k.elf |
Detection: | MAL |
Classification: | mal52.spre.linELF@0/0@1/0 |
Command: | /tmp/Kloki.m68k.elf |
PID: | 5432 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | suka |
Standard Error: |
- system is lnxubuntu20
- Kloki.m68k.elf New Fork (PID: 5434, Parent: 5432)
- Kloki.m68k.elf New Fork (PID: 5436, Parent: 5434)
- Kloki.m68k.elf New Fork (PID: 5438, Parent: 5434)
- gnome-session-binary New Fork (PID: 5440, Parent: 1588)
- gnome-session-binary New Fork (PID: 5461, Parent: 1588)
- gnome-session-binary New Fork (PID: 5463, Parent: 1588)
- gnome-session-binary New Fork (PID: 5464, Parent: 1588)
- gdm3 New Fork (PID: 5465, Parent: 1400)
- gdm3 New Fork (PID: 5467, Parent: 1400)
- systemd New Fork (PID: 5478, Parent: 1)
- cleanup
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T17:14:21.553369+0100 | 2500034 | 2 | Misc Attack | 83.222.191.90 | 13566 | 192.168.2.13 | 42768 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Non-Standard Port | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
19% | Virustotal | Browse | ||
26% | ReversingLabs | Linux.Backdoor.Mirai |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.90 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.115.218 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.77.184 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.101.63 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.43.26 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.58.178 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.87.84 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.28.197 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.170.242 | unknown | Bulgaria | 49040 | KIG-UNISAT-TVBG | false | |
83.222.117.41 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.116.70 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.84.251 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.185.193 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.187.160 | unknown | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.125.154 | unknown | Russian Federation | 47328 | TRI-ASTrueRecordsIncES | false | |
83.222.169.86 | unknown | Bulgaria | 12615 | GCN-ASGCNAD-SofiaBulgariaBG | false | |
83.222.150.49 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.58.145 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.167.69 | unknown | Bulgaria | 49040 | KIG-UNISAT-TVBG | false | |
83.222.225.141 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.53.56 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.118.219 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.162.58 | unknown | Bulgaria | 31037 | WAVENETLB | false | |
83.222.98.91 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.251.204 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.49.81 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.107.16 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.103.182 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.254.111 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.230.103 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.147.227 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.106.16 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.201.97 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.138.149 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.17.70 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.106.96 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.166.87 | unknown | Bulgaria | 12615 | GCN-ASGCNAD-SofiaBulgariaBG | false | |
83.222.195.2 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.108.38 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.208.135 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.215.167 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.224.161 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.21.221 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.69.49 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.131.245 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.191.90 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.121.112 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.218.3 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.130.253 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.98.76 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.247.222 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.81.84 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.27.57 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.234.102 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.8.57 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.124.101 | unknown | Russian Federation | 47328 | TRI-ASTrueRecordsIncES | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
83.222.58.145 | Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MNOGOBYTE-ASMoscowRussiaRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
LOL-ASluLU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
MNOGOBYTE-ASMoscowRussiaRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.706702809147777 |
TrID: |
|
File name: | Kloki.m68k.elf |
File size: | 153'984 bytes |
MD5: | 944b6d159ab3e092bd836ab50ace5726 |
SHA1: | 14c0788721e4ab73da1eff990a53d5110379af60 |
SHA256: | 58e3cfde1874c8b530ff43057d1eeb2e5daa7aa25b75682c6e09bf3b5921b27c |
SHA512: | 4045db565e294feb77f4bc29e2df85fee9c8d425be526d3ded91d7d20bd7110d1b0787bd4641c614817229e7b585742b3cba5c06add40597c0ccba07e03b6994 |
SSDEEP: | 3072:6SyFEZIXJ5aWVoTcVUmsOMMNFSkXtkEEVCjbiYL13cRAyOpF1f:jLIZsO/NI6tkEzL5yOf1f |
TLSH: | EDE32ACBF800DEBDF80AE73B48130805B130BBA155925E376257797FED3A1990967E86 |
File Content Preview: | .ELF.......................D...4..W......4. ...(.......................$...$...... ........(../(../(..H........... .dt.Q............................NV..a....da.....N^NuNV..J9..w.f>"y../D QJ.g.X.#.../DN."y../D QJ.f.A.....J.g.Hy...$N.X.......w.N^NuNV..N^NuN |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 153584 |
Section Header Size: | 40 |
Number of Section Headers: | 10 |
Header String Table Index: | 9 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x80000094 | 0x94 | 0x14 | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.text | PROGBITS | 0x800000a8 | 0xa8 | 0x1f2e2 | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.fini | PROGBITS | 0x8001f38a | 0x1f38a | 0xe | 0x0 | 0x6 | AX | 0 | 0 | 2 |
.rodata | PROGBITS | 0x8001f398 | 0x1f398 | 0x1b8c | 0x0 | 0x2 | A | 0 | 0 | 2 |
.ctors | PROGBITS | 0x80022f28 | 0x20f28 | 0xc | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x80022f34 | 0x20f34 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x80022f40 | 0x20f40 | 0x4870 | 0x0 | 0x3 | WA | 0 | 0 | 32 |
.bss | NOBITS | 0x800277b0 | 0x257b0 | 0x5528 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.shstrtab | STRTAB | 0x0 | 0x257b0 | 0x3e | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x80000000 | 0x80000000 | 0x20f24 | 0x20f24 | 6.1327 | 0x5 | R E | 0x2000 | .init .text .fini .rodata | |
LOAD | 0x20f28 | 0x80022f28 | 0x80022f28 | 0x4888 | 0x9db0 | 0.3587 | 0x6 | RW | 0x2000 | .ctors .dtors .data .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x6 | RW | 0x4 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T17:14:21.553369+0100 | 2500034 | ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 | 2 | 83.222.191.90 | 13566 | 192.168.2.13 | 42768 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 17:14:21.216056108 CET | 60708 | 13566 | 192.168.2.13 | 83.222.131.245 |
Jan 14, 2025 17:14:21.220916033 CET | 13566 | 60708 | 83.222.131.245 | 192.168.2.13 |
Jan 14, 2025 17:14:21.221139908 CET | 60708 | 13566 | 192.168.2.13 | 83.222.131.245 |
Jan 14, 2025 17:14:21.255336046 CET | 60708 | 13566 | 192.168.2.13 | 83.222.131.245 |
Jan 14, 2025 17:14:21.256104946 CET | 57786 | 13566 | 192.168.2.13 | 83.222.106.96 |
Jan 14, 2025 17:14:21.260445118 CET | 13566 | 60708 | 83.222.131.245 | 192.168.2.13 |
Jan 14, 2025 17:14:21.260765076 CET | 60708 | 13566 | 192.168.2.13 | 83.222.131.245 |
Jan 14, 2025 17:14:21.260926962 CET | 13566 | 57786 | 83.222.106.96 | 192.168.2.13 |
Jan 14, 2025 17:14:21.261008978 CET | 57786 | 13566 | 192.168.2.13 | 83.222.106.96 |
Jan 14, 2025 17:14:21.278148890 CET | 57786 | 13566 | 192.168.2.13 | 83.222.106.96 |
Jan 14, 2025 17:14:21.282170057 CET | 39572 | 13566 | 192.168.2.13 | 83.222.77.184 |
Jan 14, 2025 17:14:21.283029079 CET | 13566 | 57786 | 83.222.106.96 | 192.168.2.13 |
Jan 14, 2025 17:14:21.283143044 CET | 57786 | 13566 | 192.168.2.13 | 83.222.106.96 |
Jan 14, 2025 17:14:21.285475016 CET | 36224 | 13566 | 192.168.2.13 | 83.222.138.149 |
Jan 14, 2025 17:14:21.286842108 CET | 43684 | 13566 | 192.168.2.13 | 83.222.108.38 |
Jan 14, 2025 17:14:21.287275076 CET | 13566 | 39572 | 83.222.77.184 | 192.168.2.13 |
Jan 14, 2025 17:14:21.287321091 CET | 39572 | 13566 | 192.168.2.13 | 83.222.77.184 |
Jan 14, 2025 17:14:21.290288925 CET | 13566 | 36224 | 83.222.138.149 | 192.168.2.13 |
Jan 14, 2025 17:14:21.290348053 CET | 36224 | 13566 | 192.168.2.13 | 83.222.138.149 |
Jan 14, 2025 17:14:21.291645050 CET | 13566 | 43684 | 83.222.108.38 | 192.168.2.13 |
Jan 14, 2025 17:14:21.291729927 CET | 43684 | 13566 | 192.168.2.13 | 83.222.108.38 |
Jan 14, 2025 17:14:21.302573919 CET | 49270 | 13566 | 192.168.2.13 | 83.222.121.112 |
Jan 14, 2025 17:14:21.307338953 CET | 34496 | 13566 | 192.168.2.13 | 83.222.130.253 |
Jan 14, 2025 17:14:21.307436943 CET | 13566 | 49270 | 83.222.121.112 | 192.168.2.13 |
Jan 14, 2025 17:14:21.307518005 CET | 49270 | 13566 | 192.168.2.13 | 83.222.121.112 |
Jan 14, 2025 17:14:21.312236071 CET | 13566 | 34496 | 83.222.130.253 | 192.168.2.13 |
Jan 14, 2025 17:14:21.312345982 CET | 34496 | 13566 | 192.168.2.13 | 83.222.130.253 |
Jan 14, 2025 17:14:21.316320896 CET | 34940 | 13566 | 192.168.2.13 | 83.222.225.141 |
Jan 14, 2025 17:14:21.321249962 CET | 13566 | 34940 | 83.222.225.141 | 192.168.2.13 |
Jan 14, 2025 17:14:21.321336031 CET | 34940 | 13566 | 192.168.2.13 | 83.222.225.141 |
Jan 14, 2025 17:14:21.328363895 CET | 34940 | 13566 | 192.168.2.13 | 83.222.225.141 |
Jan 14, 2025 17:14:21.329562902 CET | 50490 | 13566 | 192.168.2.13 | 83.222.101.63 |
Jan 14, 2025 17:14:21.331772089 CET | 40992 | 13566 | 192.168.2.13 | 83.222.124.101 |
Jan 14, 2025 17:14:21.333491087 CET | 13566 | 34940 | 83.222.225.141 | 192.168.2.13 |
Jan 14, 2025 17:14:21.333554983 CET | 34940 | 13566 | 192.168.2.13 | 83.222.225.141 |
Jan 14, 2025 17:14:21.334355116 CET | 13566 | 50490 | 83.222.101.63 | 192.168.2.13 |
Jan 14, 2025 17:14:21.334377050 CET | 56112 | 13566 | 192.168.2.13 | 83.222.166.87 |
Jan 14, 2025 17:14:21.334440947 CET | 50490 | 13566 | 192.168.2.13 | 83.222.101.63 |
Jan 14, 2025 17:14:21.336642027 CET | 13566 | 40992 | 83.222.124.101 | 192.168.2.13 |
Jan 14, 2025 17:14:21.336684942 CET | 36092 | 13566 | 192.168.2.13 | 83.222.117.41 |
Jan 14, 2025 17:14:21.336757898 CET | 40992 | 13566 | 192.168.2.13 | 83.222.124.101 |
Jan 14, 2025 17:14:21.339242935 CET | 13566 | 56112 | 83.222.166.87 | 192.168.2.13 |
Jan 14, 2025 17:14:21.339330912 CET | 56112 | 13566 | 192.168.2.13 | 83.222.166.87 |
Jan 14, 2025 17:14:21.340042114 CET | 45944 | 13566 | 192.168.2.13 | 83.222.17.70 |
Jan 14, 2025 17:14:21.341835022 CET | 13566 | 36092 | 83.222.117.41 | 192.168.2.13 |
Jan 14, 2025 17:14:21.341880083 CET | 36092 | 13566 | 192.168.2.13 | 83.222.117.41 |
Jan 14, 2025 17:14:21.342809916 CET | 54352 | 13566 | 192.168.2.13 | 83.222.69.49 |
Jan 14, 2025 17:14:21.344939947 CET | 13566 | 45944 | 83.222.17.70 | 192.168.2.13 |
Jan 14, 2025 17:14:21.344984055 CET | 45944 | 13566 | 192.168.2.13 | 83.222.17.70 |
Jan 14, 2025 17:14:21.346540928 CET | 52442 | 13566 | 192.168.2.13 | 83.222.195.2 |
Jan 14, 2025 17:14:21.347594976 CET | 13566 | 54352 | 83.222.69.49 | 192.168.2.13 |
Jan 14, 2025 17:14:21.347668886 CET | 54352 | 13566 | 192.168.2.13 | 83.222.69.49 |
Jan 14, 2025 17:14:21.351506948 CET | 13566 | 52442 | 83.222.195.2 | 192.168.2.13 |
Jan 14, 2025 17:14:21.351603985 CET | 52442 | 13566 | 192.168.2.13 | 83.222.195.2 |
Jan 14, 2025 17:14:21.352982044 CET | 42470 | 13566 | 192.168.2.13 | 83.222.116.70 |
Jan 14, 2025 17:14:21.356462002 CET | 49228 | 13566 | 192.168.2.13 | 83.222.247.222 |
Jan 14, 2025 17:14:21.357875109 CET | 13566 | 42470 | 83.222.116.70 | 192.168.2.13 |
Jan 14, 2025 17:14:21.358194113 CET | 42470 | 13566 | 192.168.2.13 | 83.222.116.70 |
Jan 14, 2025 17:14:21.361279964 CET | 13566 | 49228 | 83.222.247.222 | 192.168.2.13 |
Jan 14, 2025 17:14:21.361553907 CET | 49228 | 13566 | 192.168.2.13 | 83.222.247.222 |
Jan 14, 2025 17:14:21.362431049 CET | 41168 | 13566 | 192.168.2.13 | 83.222.167.69 |
Jan 14, 2025 17:14:21.364742994 CET | 57492 | 13566 | 192.168.2.13 | 83.222.150.49 |
Jan 14, 2025 17:14:21.367284060 CET | 13566 | 41168 | 83.222.167.69 | 192.168.2.13 |
Jan 14, 2025 17:14:21.367367983 CET | 41168 | 13566 | 192.168.2.13 | 83.222.167.69 |
Jan 14, 2025 17:14:21.369618893 CET | 13566 | 57492 | 83.222.150.49 | 192.168.2.13 |
Jan 14, 2025 17:14:21.370449066 CET | 57492 | 13566 | 192.168.2.13 | 83.222.150.49 |
Jan 14, 2025 17:14:21.377367020 CET | 57492 | 13566 | 192.168.2.13 | 83.222.150.49 |
Jan 14, 2025 17:14:21.378215075 CET | 46972 | 13566 | 192.168.2.13 | 83.222.218.3 |
Jan 14, 2025 17:14:21.382214069 CET | 13566 | 57492 | 83.222.150.49 | 192.168.2.13 |
Jan 14, 2025 17:14:21.382327080 CET | 57492 | 13566 | 192.168.2.13 | 83.222.150.49 |
Jan 14, 2025 17:14:21.382591963 CET | 58796 | 13566 | 192.168.2.13 | 83.222.87.84 |
Jan 14, 2025 17:14:21.382996082 CET | 13566 | 46972 | 83.222.218.3 | 192.168.2.13 |
Jan 14, 2025 17:14:21.383068085 CET | 46972 | 13566 | 192.168.2.13 | 83.222.218.3 |
Jan 14, 2025 17:14:21.386974096 CET | 34746 | 13566 | 192.168.2.13 | 83.222.115.218 |
Jan 14, 2025 17:14:21.387531042 CET | 13566 | 58796 | 83.222.87.84 | 192.168.2.13 |
Jan 14, 2025 17:14:21.387592077 CET | 58796 | 13566 | 192.168.2.13 | 83.222.87.84 |
Jan 14, 2025 17:14:21.391016006 CET | 35098 | 13566 | 192.168.2.13 | 83.222.81.84 |
Jan 14, 2025 17:14:21.391773939 CET | 13566 | 34746 | 83.222.115.218 | 192.168.2.13 |
Jan 14, 2025 17:14:21.391836882 CET | 34746 | 13566 | 192.168.2.13 | 83.222.115.218 |
Jan 14, 2025 17:14:21.395833015 CET | 13566 | 35098 | 83.222.81.84 | 192.168.2.13 |
Jan 14, 2025 17:14:21.396234989 CET | 35098 | 13566 | 192.168.2.13 | 83.222.81.84 |
Jan 14, 2025 17:14:21.416358948 CET | 35098 | 13566 | 192.168.2.13 | 83.222.81.84 |
Jan 14, 2025 17:14:21.421181917 CET | 13566 | 35098 | 83.222.81.84 | 192.168.2.13 |
Jan 14, 2025 17:14:21.421224117 CET | 35098 | 13566 | 192.168.2.13 | 83.222.81.84 |
Jan 14, 2025 17:14:21.422893047 CET | 57754 | 13566 | 192.168.2.13 | 83.222.103.182 |
Jan 14, 2025 17:14:21.426759958 CET | 38670 | 13566 | 192.168.2.13 | 83.222.147.227 |
Jan 14, 2025 17:14:21.427738905 CET | 13566 | 57754 | 83.222.103.182 | 192.168.2.13 |
Jan 14, 2025 17:14:21.427783012 CET | 57754 | 13566 | 192.168.2.13 | 83.222.103.182 |
Jan 14, 2025 17:14:21.430783033 CET | 42936 | 13566 | 192.168.2.13 | 83.222.27.57 |
Jan 14, 2025 17:14:21.431637049 CET | 13566 | 38670 | 83.222.147.227 | 192.168.2.13 |
Jan 14, 2025 17:14:21.431674957 CET | 38670 | 13566 | 192.168.2.13 | 83.222.147.227 |
Jan 14, 2025 17:14:21.435601950 CET | 13566 | 42936 | 83.222.27.57 | 192.168.2.13 |
Jan 14, 2025 17:14:21.435695887 CET | 42936 | 13566 | 192.168.2.13 | 83.222.27.57 |
Jan 14, 2025 17:14:21.435981989 CET | 42936 | 13566 | 192.168.2.13 | 83.222.27.57 |
Jan 14, 2025 17:14:21.437581062 CET | 40920 | 13566 | 192.168.2.13 | 83.222.58.145 |
Jan 14, 2025 17:14:21.440784931 CET | 13566 | 42936 | 83.222.27.57 | 192.168.2.13 |
Jan 14, 2025 17:14:21.440829992 CET | 42936 | 13566 | 192.168.2.13 | 83.222.27.57 |
Jan 14, 2025 17:14:21.442126989 CET | 50586 | 13566 | 192.168.2.13 | 83.222.98.76 |
Jan 14, 2025 17:14:21.442336082 CET | 13566 | 40920 | 83.222.58.145 | 192.168.2.13 |
Jan 14, 2025 17:14:21.443351030 CET | 40920 | 13566 | 192.168.2.13 | 83.222.58.145 |
Jan 14, 2025 17:14:21.444863081 CET | 54270 | 13566 | 192.168.2.13 | 83.222.215.167 |
Jan 14, 2025 17:14:21.446880102 CET | 13566 | 50586 | 83.222.98.76 | 192.168.2.13 |
Jan 14, 2025 17:14:21.446916103 CET | 50586 | 13566 | 192.168.2.13 | 83.222.98.76 |
Jan 14, 2025 17:14:21.449642897 CET | 13566 | 54270 | 83.222.215.167 | 192.168.2.13 |
Jan 14, 2025 17:14:21.449690104 CET | 54270 | 13566 | 192.168.2.13 | 83.222.215.167 |
Jan 14, 2025 17:14:21.451334953 CET | 37480 | 13566 | 192.168.2.13 | 83.222.125.154 |
Jan 14, 2025 17:14:21.451673985 CET | 33484 | 13566 | 192.168.2.13 | 83.222.170.242 |
Jan 14, 2025 17:14:21.456132889 CET | 13566 | 37480 | 83.222.125.154 | 192.168.2.13 |
Jan 14, 2025 17:14:21.456238031 CET | 37480 | 13566 | 192.168.2.13 | 83.222.125.154 |
Jan 14, 2025 17:14:21.456482887 CET | 13566 | 33484 | 83.222.170.242 | 192.168.2.13 |
Jan 14, 2025 17:14:21.456587076 CET | 60448 | 13566 | 192.168.2.13 | 83.222.224.161 |
Jan 14, 2025 17:14:21.456717014 CET | 33484 | 13566 | 192.168.2.13 | 83.222.170.242 |
Jan 14, 2025 17:14:21.459832907 CET | 37976 | 13566 | 192.168.2.13 | 83.222.208.135 |
Jan 14, 2025 17:14:21.461365938 CET | 13566 | 60448 | 83.222.224.161 | 192.168.2.13 |
Jan 14, 2025 17:14:21.462815046 CET | 39788 | 13566 | 192.168.2.13 | 83.222.230.103 |
Jan 14, 2025 17:14:21.464366913 CET | 57898 | 13566 | 192.168.2.13 | 83.222.185.193 |
Jan 14, 2025 17:14:21.464464903 CET | 60448 | 13566 | 192.168.2.13 | 83.222.224.161 |
Jan 14, 2025 17:14:21.464616060 CET | 13566 | 37976 | 83.222.208.135 | 192.168.2.13 |
Jan 14, 2025 17:14:21.464668036 CET | 37976 | 13566 | 192.168.2.13 | 83.222.208.135 |
Jan 14, 2025 17:14:21.466403008 CET | 33592 | 13566 | 192.168.2.13 | 83.222.106.16 |
Jan 14, 2025 17:14:21.467633009 CET | 13566 | 39788 | 83.222.230.103 | 192.168.2.13 |
Jan 14, 2025 17:14:21.467689991 CET | 39788 | 13566 | 192.168.2.13 | 83.222.230.103 |
Jan 14, 2025 17:14:21.468022108 CET | 51412 | 13566 | 192.168.2.13 | 83.222.21.221 |
Jan 14, 2025 17:14:21.469175100 CET | 13566 | 57898 | 83.222.185.193 | 192.168.2.13 |
Jan 14, 2025 17:14:21.469314098 CET | 57898 | 13566 | 192.168.2.13 | 83.222.185.193 |
Jan 14, 2025 17:14:21.470331907 CET | 37584 | 13566 | 192.168.2.13 | 83.222.234.102 |
Jan 14, 2025 17:14:21.471199036 CET | 13566 | 33592 | 83.222.106.16 | 192.168.2.13 |
Jan 14, 2025 17:14:21.471259117 CET | 33592 | 13566 | 192.168.2.13 | 83.222.106.16 |
Jan 14, 2025 17:14:21.472167969 CET | 45116 | 13566 | 192.168.2.13 | 83.222.49.81 |
Jan 14, 2025 17:14:21.472783089 CET | 13566 | 51412 | 83.222.21.221 | 192.168.2.13 |
Jan 14, 2025 17:14:21.472825050 CET | 51412 | 13566 | 192.168.2.13 | 83.222.21.221 |
Jan 14, 2025 17:14:21.474172115 CET | 42754 | 13566 | 192.168.2.13 | 83.222.28.197 |
Jan 14, 2025 17:14:21.475094080 CET | 13566 | 37584 | 83.222.234.102 | 192.168.2.13 |
Jan 14, 2025 17:14:21.475167036 CET | 37584 | 13566 | 192.168.2.13 | 83.222.234.102 |
Jan 14, 2025 17:14:21.477402925 CET | 13566 | 45116 | 83.222.49.81 | 192.168.2.13 |
Jan 14, 2025 17:14:21.477462053 CET | 45116 | 13566 | 192.168.2.13 | 83.222.49.81 |
Jan 14, 2025 17:14:21.477832079 CET | 43066 | 13566 | 192.168.2.13 | 83.222.53.56 |
Jan 14, 2025 17:14:21.479028940 CET | 13566 | 42754 | 83.222.28.197 | 192.168.2.13 |
Jan 14, 2025 17:14:21.479208946 CET | 42754 | 13566 | 192.168.2.13 | 83.222.28.197 |
Jan 14, 2025 17:14:21.481826067 CET | 43492 | 13566 | 192.168.2.13 | 83.222.254.111 |
Jan 14, 2025 17:14:21.482635975 CET | 13566 | 43066 | 83.222.53.56 | 192.168.2.13 |
Jan 14, 2025 17:14:21.482685089 CET | 43066 | 13566 | 192.168.2.13 | 83.222.53.56 |
Jan 14, 2025 17:14:21.484240055 CET | 56220 | 13566 | 192.168.2.13 | 83.222.201.97 |
Jan 14, 2025 17:14:21.486641884 CET | 58076 | 13566 | 192.168.2.13 | 83.222.187.160 |
Jan 14, 2025 17:14:21.486675978 CET | 13566 | 43492 | 83.222.254.111 | 192.168.2.13 |
Jan 14, 2025 17:14:21.486716032 CET | 43492 | 13566 | 192.168.2.13 | 83.222.254.111 |
Jan 14, 2025 17:14:21.488563061 CET | 40820 | 13566 | 192.168.2.13 | 83.222.8.57 |
Jan 14, 2025 17:14:21.489021063 CET | 13566 | 56220 | 83.222.201.97 | 192.168.2.13 |
Jan 14, 2025 17:14:21.489136934 CET | 56220 | 13566 | 192.168.2.13 | 83.222.201.97 |
Jan 14, 2025 17:14:21.491343975 CET | 50030 | 13566 | 192.168.2.13 | 83.222.58.178 |
Jan 14, 2025 17:14:21.491449118 CET | 13566 | 58076 | 83.222.187.160 | 192.168.2.13 |
Jan 14, 2025 17:14:21.491513968 CET | 58076 | 13566 | 192.168.2.13 | 83.222.187.160 |
Jan 14, 2025 17:14:21.493411064 CET | 13566 | 40820 | 83.222.8.57 | 192.168.2.13 |
Jan 14, 2025 17:14:21.493469954 CET | 40820 | 13566 | 192.168.2.13 | 83.222.8.57 |
Jan 14, 2025 17:14:21.493603945 CET | 33526 | 13566 | 192.168.2.13 | 83.222.43.26 |
Jan 14, 2025 17:14:21.496186972 CET | 13566 | 50030 | 83.222.58.178 | 192.168.2.13 |
Jan 14, 2025 17:14:21.496321917 CET | 50030 | 13566 | 192.168.2.13 | 83.222.58.178 |
Jan 14, 2025 17:14:21.496520996 CET | 38122 | 13566 | 192.168.2.13 | 83.222.84.251 |
Jan 14, 2025 17:14:21.498378992 CET | 13566 | 33526 | 83.222.43.26 | 192.168.2.13 |
Jan 14, 2025 17:14:21.498548985 CET | 33526 | 13566 | 192.168.2.13 | 83.222.43.26 |
Jan 14, 2025 17:14:21.498712063 CET | 44370 | 13566 | 192.168.2.13 | 83.222.162.58 |
Jan 14, 2025 17:14:21.501305103 CET | 13566 | 38122 | 83.222.84.251 | 192.168.2.13 |
Jan 14, 2025 17:14:21.501368999 CET | 38122 | 13566 | 192.168.2.13 | 83.222.84.251 |
Jan 14, 2025 17:14:21.503550053 CET | 13566 | 44370 | 83.222.162.58 | 192.168.2.13 |
Jan 14, 2025 17:14:21.503644943 CET | 44370 | 13566 | 192.168.2.13 | 83.222.162.58 |
Jan 14, 2025 17:14:21.516859055 CET | 44370 | 13566 | 192.168.2.13 | 83.222.162.58 |
Jan 14, 2025 17:14:21.518086910 CET | 45108 | 13566 | 192.168.2.13 | 83.222.98.91 |
Jan 14, 2025 17:14:21.520272970 CET | 59070 | 13566 | 192.168.2.13 | 83.222.251.204 |
Jan 14, 2025 17:14:21.522989988 CET | 13566 | 45108 | 83.222.98.91 | 192.168.2.13 |
Jan 14, 2025 17:14:21.523062944 CET | 45108 | 13566 | 192.168.2.13 | 83.222.98.91 |
Jan 14, 2025 17:14:21.523590088 CET | 13566 | 44370 | 83.222.162.58 | 192.168.2.13 |
Jan 14, 2025 17:14:21.525150061 CET | 13566 | 59070 | 83.222.251.204 | 192.168.2.13 |
Jan 14, 2025 17:14:21.525194883 CET | 59070 | 13566 | 192.168.2.13 | 83.222.251.204 |
Jan 14, 2025 17:14:21.525598049 CET | 52998 | 13566 | 192.168.2.13 | 83.222.107.16 |
Jan 14, 2025 17:14:21.527821064 CET | 53192 | 13566 | 192.168.2.13 | 83.222.169.86 |
Jan 14, 2025 17:14:21.530415058 CET | 13566 | 52998 | 83.222.107.16 | 192.168.2.13 |
Jan 14, 2025 17:14:21.530539036 CET | 52998 | 13566 | 192.168.2.13 | 83.222.107.16 |
Jan 14, 2025 17:14:21.531119108 CET | 39304 | 13566 | 192.168.2.13 | 83.222.118.219 |
Jan 14, 2025 17:14:21.532624960 CET | 13566 | 53192 | 83.222.169.86 | 192.168.2.13 |
Jan 14, 2025 17:14:21.532712936 CET | 53192 | 13566 | 192.168.2.13 | 83.222.169.86 |
Jan 14, 2025 17:14:21.535924911 CET | 13566 | 39304 | 83.222.118.219 | 192.168.2.13 |
Jan 14, 2025 17:14:21.535969973 CET | 39304 | 13566 | 192.168.2.13 | 83.222.118.219 |
Jan 14, 2025 17:14:21.538367987 CET | 13566 | 44370 | 83.222.162.58 | 192.168.2.13 |
Jan 14, 2025 17:14:21.538466930 CET | 44370 | 13566 | 192.168.2.13 | 83.222.162.58 |
Jan 14, 2025 17:14:21.548456907 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:14:21.553369045 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:14:21.553442955 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:14:21.556207895 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:14:21.561037064 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:14:21.561130047 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:14:21.565994024 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:14:31.566456079 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:14:31.571266890 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:14:32.179785967 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:14:32.179887056 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:14:33.166980982 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:14:33.167110920 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:15:33.218247890 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:15:33.223263025 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:15:33.423860073 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:15:33.423969984 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Jan 14, 2025 17:15:34.166008949 CET | 13566 | 42768 | 83.222.191.90 | 192.168.2.13 |
Jan 14, 2025 17:15:34.166124105 CET | 42768 | 13566 | 192.168.2.13 | 83.222.191.90 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 17:14:21.536601067 CET | 38667 | 53 | 192.168.2.13 | 8.8.8.8 |
Jan 14, 2025 17:14:21.546730995 CET | 53 | 38667 | 8.8.8.8 | 192.168.2.13 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 14, 2025 17:14:21.536601067 CET | 192.168.2.13 | 8.8.8.8 | 0x2285 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 14, 2025 17:14:21.546730995 CET | 8.8.8.8 | 192.168.2.13 | 0x2285 | No error (0) | 83.222.191.90 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | /tmp/Kloki.m68k.elf |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /tmp/Kloki.m68k.elf |
Arguments: | - |
File size: | 4463432 bytes |
MD5 hash: | cd177594338c77b895ae27c33f8f86cc |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/libexec/gsd-print-notifications |
Arguments: | /usr/libexec/gsd-print-notifications |
File size: | 51840 bytes |
MD5 hash: | 71539698aa691718cee775d6b9450ae2 |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/libexec/gsd-rfkill |
Arguments: | /usr/libexec/gsd-rfkill |
File size: | 51808 bytes |
MD5 hash: | 88a16a3c0aba1759358c06215ecfb5cc |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 16:14:20 |
Start date (UTC): | 14/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 16:14:30 |
Start date (UTC): | 14/01/2025 |
Path: | /usr/lib/systemd/systemd |
Arguments: | - |
File size: | 1620224 bytes |
MD5 hash: | 9b2bec7092a40488108543f9334aab75 |
Start time (UTC): | 16:14:30 |
Start date (UTC): | 14/01/2025 |
Path: | /lib/systemd/systemd-user-runtime-dir |
Arguments: | /lib/systemd/systemd-user-runtime-dir stop 127 |
File size: | 22672 bytes |
MD5 hash: | d55f4b0847f88131dbcfb07435178e54 |