Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Kloki.x86.elf

Overview

General Information

Sample name:Kloki.x86.elf
Analysis ID:1591049
MD5:9c0cf500a75080a480c04b5ab4af863a
SHA1:cea9e6df251020d298935228cb1fed36c6263994
SHA256:fc81007d717f418b7542faff1bb8a716003b4338809b6b6f1fae407a22e8808e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1591049
Start date and time:2025-01-14 17:15:32 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.x86.elf
Detection:MAL
Classification:mal64.spre.linELF@0/0@1/0
Command:/tmp/Kloki.x86.elf
PID:5503
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5491, Parent: 3635)
  • rm (PID: 5491, Parent: 3635, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fHLZqw1TN3 /tmp/tmp.ow2JfsB4Wn /tmp/tmp.FCcwH7Zebc
  • dash New Fork (PID: 5492, Parent: 3635)
  • rm (PID: 5492, Parent: 3635, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.fHLZqw1TN3 /tmp/tmp.ow2JfsB4Wn /tmp/tmp.FCcwH7Zebc
  • sh (PID: 5507, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 5507, Parent: 1383, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • sh (PID: 5526, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5526, Parent: 1383, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5530, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5530, Parent: 1383, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • sh (PID: 5531, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 5531, Parent: 1383, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • gdm3 New Fork (PID: 5532, Parent: 1289)
  • Default (PID: 5532, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5533, Parent: 1289)
  • Default (PID: 5533, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5544, Parent: 1)
  • systemd-user-runtime-dir (PID: 5544, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
SourceRuleDescriptionAuthorStrings
5503.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4840:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5503.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_5f7b67b8unknownunknown
  • 0x92d6:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
5503.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6cd2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5503.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0xbca0:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
5503.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0xa496:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 7 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-14T17:16:13.482183+010025000342Misc Attack83.222.191.9013566192.168.2.1456490TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.x86.elfVirustotal: Detection: 15%Perma Link
Source: Kloki.x86.elfReversingLabs: Detection: 21%
Source: Kloki.x86.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.14:45470 -> 83.222.5.109:13566
Source: global trafficTCP traffic: 192.168.2.14:50934 -> 83.222.74.139:13566
Source: global trafficTCP traffic: 192.168.2.14:41380 -> 83.222.111.180:13566
Source: global trafficTCP traffic: 192.168.2.14:47328 -> 83.222.118.245:13566
Source: global trafficTCP traffic: 192.168.2.14:56454 -> 83.222.240.132:13566
Source: global trafficTCP traffic: 192.168.2.14:35130 -> 83.222.109.108:13566
Source: global trafficTCP traffic: 192.168.2.14:59386 -> 83.222.60.121:13566
Source: global trafficTCP traffic: 192.168.2.14:34332 -> 83.222.139.30:13566
Source: global trafficTCP traffic: 192.168.2.14:53760 -> 83.222.191.153:13566
Source: global trafficTCP traffic: 192.168.2.14:51598 -> 83.222.66.227:13566
Source: global trafficTCP traffic: 192.168.2.14:59868 -> 83.222.83.194:13566
Source: global trafficTCP traffic: 192.168.2.14:50980 -> 83.222.52.155:13566
Source: global trafficTCP traffic: 192.168.2.14:37356 -> 83.222.194.181:13566
Source: global trafficTCP traffic: 192.168.2.14:36740 -> 83.222.206.87:13566
Source: global trafficTCP traffic: 192.168.2.14:45182 -> 83.222.29.71:13566
Source: global trafficTCP traffic: 192.168.2.14:60476 -> 83.222.91.34:13566
Source: global trafficTCP traffic: 192.168.2.14:49522 -> 83.222.174.36:13566
Source: global trafficTCP traffic: 192.168.2.14:38054 -> 83.222.180.165:13566
Source: global trafficTCP traffic: 192.168.2.14:35624 -> 83.222.25.74:13566
Source: global trafficTCP traffic: 192.168.2.14:54766 -> 83.222.90.36:13566
Source: global trafficTCP traffic: 192.168.2.14:58002 -> 83.222.168.135:13566
Source: global trafficTCP traffic: 192.168.2.14:50256 -> 83.222.0.66:13566
Source: global trafficTCP traffic: 192.168.2.14:50456 -> 83.222.183.229:13566
Source: global trafficTCP traffic: 192.168.2.14:48930 -> 83.222.3.191:13566
Source: global trafficTCP traffic: 192.168.2.14:40098 -> 83.222.220.69:13566
Source: global trafficTCP traffic: 192.168.2.14:36896 -> 83.222.7.215:13566
Source: global trafficTCP traffic: 192.168.2.14:35536 -> 83.222.202.201:13566
Source: global trafficTCP traffic: 192.168.2.14:50022 -> 83.222.140.152:13566
Source: global trafficTCP traffic: 192.168.2.14:47102 -> 83.222.32.169:13566
Source: global trafficTCP traffic: 192.168.2.14:35948 -> 83.222.163.47:13566
Source: global trafficTCP traffic: 192.168.2.14:44360 -> 83.222.224.124:13566
Source: global trafficTCP traffic: 192.168.2.14:38126 -> 83.222.204.148:13566
Source: global trafficTCP traffic: 192.168.2.14:50312 -> 83.222.33.122:13566
Source: global trafficTCP traffic: 192.168.2.14:40938 -> 83.222.184.123:13566
Source: global trafficTCP traffic: 192.168.2.14:38238 -> 83.222.158.210:13566
Source: global trafficTCP traffic: 192.168.2.14:45162 -> 83.222.89.125:13566
Source: global trafficTCP traffic: 192.168.2.14:57164 -> 83.222.44.89:13566
Source: global trafficTCP traffic: 192.168.2.14:50710 -> 83.222.191.47:13566
Source: global trafficTCP traffic: 192.168.2.14:35358 -> 83.222.116.188:13566
Source: global trafficTCP traffic: 192.168.2.14:36894 -> 83.222.25.155:13566
Source: global trafficTCP traffic: 192.168.2.14:57450 -> 83.222.202.123:13566
Source: global trafficTCP traffic: 192.168.2.14:32812 -> 83.222.147.148:13566
Source: global trafficTCP traffic: 192.168.2.14:54690 -> 83.222.68.31:13566
Source: global trafficTCP traffic: 192.168.2.14:49592 -> 83.222.45.101:13566
Source: global trafficTCP traffic: 192.168.2.14:50490 -> 83.222.200.13:13566
Source: global trafficTCP traffic: 192.168.2.14:54916 -> 83.222.225.148:13566
Source: global trafficTCP traffic: 192.168.2.14:36858 -> 83.222.14.90:13566
Source: global trafficTCP traffic: 192.168.2.14:60910 -> 83.222.161.2:13566
Source: global trafficTCP traffic: 192.168.2.14:47318 -> 83.222.126.173:13566
Source: global trafficTCP traffic: 192.168.2.14:46298 -> 83.222.198.71:13566
Source: global trafficTCP traffic: 192.168.2.14:60436 -> 83.222.44.68:13566
Source: global trafficTCP traffic: 192.168.2.14:49778 -> 83.222.244.133:13566
Source: global trafficTCP traffic: 192.168.2.14:49166 -> 83.222.193.32:13566
Source: global trafficTCP traffic: 192.168.2.14:38860 -> 83.222.222.128:13566
Source: global trafficTCP traffic: 192.168.2.14:33906 -> 83.222.79.247:13566
Source: global trafficTCP traffic: 192.168.2.14:34908 -> 83.222.28.195:13566
Source: global trafficTCP traffic: 192.168.2.14:40272 -> 83.222.179.230:13566
Source: global trafficTCP traffic: 192.168.2.14:48212 -> 83.222.62.70:13566
Source: global trafficTCP traffic: 192.168.2.14:55064 -> 83.222.123.130:13566
Source: global trafficTCP traffic: 192.168.2.14:35204 -> 83.222.101.168:13566
Source: global trafficTCP traffic: 192.168.2.14:55022 -> 83.222.231.46:13566
Source: global trafficTCP traffic: 192.168.2.14:47728 -> 83.222.181.200:13566
Source: global trafficTCP traffic: 192.168.2.14:58478 -> 83.222.203.209:13566
Source: global trafficTCP traffic: 192.168.2.14:34042 -> 83.222.194.86:13566
Source: global trafficTCP traffic: 192.168.2.14:60028 -> 83.222.176.73:13566
Source: global trafficTCP traffic: 192.168.2.14:49638 -> 83.222.126.220:13566
Source: global trafficTCP traffic: 192.168.2.14:49386 -> 83.222.141.114:13566
Source: global trafficTCP traffic: 192.168.2.14:50454 -> 83.222.97.78:13566
Source: global trafficTCP traffic: 192.168.2.14:56752 -> 83.222.146.64:13566
Source: global trafficTCP traffic: 192.168.2.14:58622 -> 83.222.206.225:13566
Source: global trafficTCP traffic: 192.168.2.14:37894 -> 83.222.55.234:13566
Source: global trafficTCP traffic: 192.168.2.14:57386 -> 83.222.164.235:13566
Source: global trafficTCP traffic: 192.168.2.14:50578 -> 83.222.209.226:13566
Source: global trafficTCP traffic: 192.168.2.14:47370 -> 83.222.49.76:13566
Source: global trafficTCP traffic: 192.168.2.14:56490 -> 83.222.191.90:13566
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.14:56490
Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.5.109
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.74.139
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.111.180
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.118.245
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.240.132
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.109.108
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.60.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.139.30
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.153
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.66.227
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.83.194
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.52.155
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.194.181
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.206.87
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.29.71
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.91.34
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.174.36
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.25.74
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.90.36
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.135
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.0.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.183.229
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.3.191
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.220.69
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.7.215
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.202.201
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.140.152
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.32.169
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.163.47
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.224.124
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.204.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.122
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.123
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.158.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.89.125
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.44.89
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.191.47
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.116.188
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.25.155
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.202.123
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.147.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.68.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.45.101
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.200.13
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.225.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.14.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.161.2
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.126.173
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.198.71
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

System Summary

barindex
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5484, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5507, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5526, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5530, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5531, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5533, result: successfulJump to behavior
Source: LOAD without section mappingsProgram segment: 0x8048000
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5484, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5507, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5526, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5530, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5531, result: successfulJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5506)SIGKILL sent: pid: 5533, result: successfulJump to behavior
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5505.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 5503.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal64.spre.linELF@0/0@1/0
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3244/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3120/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3361/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3239/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/1299/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3235/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2946/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3134/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/1593/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3011/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3094/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3406/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2955/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3129/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/1588/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3402/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3807/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3125/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3246/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3245/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/767/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/800/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/888/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/801/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/769/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/803/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/806/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/807/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2956/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/490/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3142/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3139/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3412/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3398/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3392/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/780/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/661/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/782/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3304/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3425/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/785/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/940/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3147/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5342/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2991/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/791/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2986/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/794/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/795/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/797/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2983/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3159/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3157/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3711/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3319/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5510/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3178/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3172/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3171/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3329/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2999/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5508/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3207/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5509/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/2997/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/1300/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/725/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/726/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/1309/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5485/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5520/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5521/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3189/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3188/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3187/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3341/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3184/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3183/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/1712/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5519/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3218/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3337/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3215/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/853/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3213/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3212/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5511/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5512/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5513/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5514/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5515/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5516/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5517/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5518/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3190/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3353/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/3193/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/1289/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5522/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5523/statusJump to behavior
Source: /tmp/Kloki.x86.elf (PID: 5505)File opened: /proc/5524/statusJump to behavior
Source: /usr/bin/dash (PID: 5491)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fHLZqw1TN3 /tmp/tmp.ow2JfsB4Wn /tmp/tmp.FCcwH7ZebcJump to behavior
Source: /usr/bin/dash (PID: 5492)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.fHLZqw1TN3 /tmp/tmp.ow2JfsB4Wn /tmp/tmp.FCcwH7ZebcJump to behavior
Source: Kloki.x86.elfSubmission file: segment LOAD with 7.8883 entropy (max. 8.0)
Source: Kloki.x86.elfSubmission file: segment LOAD with 7.9615 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1591049 Sample: Kloki.x86.elf Startdate: 14/01/2025 Architecture: LINUX Score: 64 23 83.222.163.47, 13566, 35948 WAVENETLB Bulgaria 2->23 25 83.222.164.235, 13566, 57386 WAVENETLB Bulgaria 2->25 27 74 other IPs or domains 2->27 31 Malicious sample detected (through community Yara rule) 2->31 33 Multi AV Scanner detection for submitted file 2->33 35 Machine Learning detection for sample 2->35 8 dash rm Kloki.x86.elf 2->8         started        10 gnome-session-binary sh gsd-print-notifications 2->10         started        12 gnome-session-binary sh gnome-shell 2->12         started        14 6 other processes 2->14 signatures3 process4 process5 16 Kloki.x86.elf 8->16         started        process6 18 Kloki.x86.elf 16->18         started        21 Kloki.x86.elf 16->21         started        signatures7 29 Sample tries to kill multiple processes (SIGKILL) 18->29
SourceDetectionScannerLabelLink
Kloki.x86.elf16%VirustotalBrowse
Kloki.x86.elf21%ReversingLabsWin32.Trojan.Generic
Kloki.x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.206.87
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.179.230
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.231.46
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.109.108
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.158.210
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.28.195
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.180.165
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.123.130
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.220.69
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.74.139
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.139.30
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.0.66
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.126.220
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.202.201
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.202.123
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.206.225
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.244.133
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.146.64
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.174.36
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.44.68
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.14.90
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.45.101
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.225.148
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.97.78
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.209.226
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.79.247
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.194.181
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.25.155
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.55.234
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.116.188
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.184.123
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.203.209
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.83.194
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.191.153
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.147.148
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.198.71
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.111.180
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.222.128
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.90.36
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.3.191
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.33.122
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.141.114
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.118.245
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.224.124
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    185.125.190.26
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    83.222.191.47
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.68.31
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.49.76
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.60.121
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.62.70
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.44.89
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.194.86
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.32.169
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.89.125
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.101.168
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.168.135
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.200.13
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.164.235
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.183.229
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.240.132
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.91.34
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.66.227
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.163.47
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.52.155
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.140.152
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.126.173
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.181.200
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.7.215
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.161.2
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.29.71
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.176.73
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.193.32
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.204.148
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.5.109
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.25.74
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    secure-network-rebirthltd.ruKloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.191.90
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    SYNTERRA-ASRUKloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.208.135
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.205.130
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.199.83
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.197.220
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.206.214
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.196.94
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.198.146
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.202.198
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.209.249
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.211.212
    GCN-ASGCNAD-SofiaBulgariaBGKloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.166.87
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.174.140
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.176.30
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.174.1
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.181.243
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.169.127
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.179.249
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.181.63
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.173.21
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.181.68
    COGECO-PEER1CAKloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.234.102
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.239.3
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.245.236
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.252.225
    http://guard-x-tech.vercel.app/Get hashmaliciousHTMLPhisherBrowse
    • 64.29.17.65
    meth9.elfGet hashmaliciousMiraiBrowse
    • 64.65.21.26
    http://aicenterr.vercel.app/asd.com.htmlGet hashmaliciousHTMLPhisherBrowse
    • 64.29.17.129
    https://eb-ri18.vercel.app/verset.htmlGet hashmaliciousHTMLPhisherBrowse
    • 64.29.17.65
    http://inform-customer-sale.vercel.app/Get hashmaliciousHTMLPhisherBrowse
    • 64.29.17.129
    https://jaffeusacanna-9646.vercel.app/zqh.heups/Get hashmaliciousHTMLPhisherBrowse
    • 64.29.17.1
    MNOGOBYTE-ASMoscowRussiaRUKloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.98.76
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.97.189
    Kloki.arm5.elfGet hashmaliciousUnknownBrowse
    • 83.222.115.53
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.120.121
    Kloki.arm7.elfGet hashmaliciousUnknownBrowse
    • 83.222.107.74
    Kloki.m68k.elfGet hashmaliciousUnknownBrowse
    • 83.222.111.94
    Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
    • 83.222.116.93
    Kloki.x86.elfGet hashmaliciousUnknownBrowse
    • 83.222.101.212
    Kloki.arm4.elfGet hashmaliciousUnknownBrowse
    • 83.222.110.86
    Kloki.spc.elfGet hashmaliciousUnknownBrowse
    • 83.222.112.137
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
    Entropy (8bit):7.959187181871756
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:Kloki.x86.elf
    File size:38'312 bytes
    MD5:9c0cf500a75080a480c04b5ab4af863a
    SHA1:cea9e6df251020d298935228cb1fed36c6263994
    SHA256:fc81007d717f418b7542faff1bb8a716003b4338809b6b6f1fae407a22e8808e
    SHA512:f44f278d5468753749252a6122f1f52a835d2cbc7f76314c51d8de7939733e0423b83d986771215f5b428c641837441259cab1438d19cc138d598ab0dd83b61c
    SSDEEP:768:DOHPkureU8rirKpbN5vygzBvykN05/bSPs8eEQX3rXzu3915QnbcuyD7UoUR0:qHMliOFNEgz9FNaiCbXzaEnouy82
    TLSH:FF03E133BAA908C6C1A610365DDF3FE5250183DF1846A52AC86CF07D5E49FCA7A2D366
    File Content Preview:.ELF....................p...4...........4. ...(.........................l....................0...0..................Q.td.............................j=.sfgaD........X...X......V..........?..k.I/.j....\.d*nlz.eB"[bx.|"|M.`...S....] ..Y..|..x.b[.G...w...x.p

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Intel 80386
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - Linux
    ABI Version:0
    Entry Point Address:0x806b270
    Flags:0x0
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:40
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x80480000x80480000x10000x1af6c7.88830x6RW 0x1000
    LOAD0x00x80630000x80630000x94a90x94a97.96150x5R E0x1000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
    2025-01-14T17:16:13.482183+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1456490TCP
    TimestampSource PortDest PortSource IPDest IP
    Jan 14, 2025 17:16:13.464518070 CET4547013566192.168.2.1483.222.5.109
    Jan 14, 2025 17:16:13.464540958 CET5093413566192.168.2.1483.222.74.139
    Jan 14, 2025 17:16:13.464560032 CET4138013566192.168.2.1483.222.111.180
    Jan 14, 2025 17:16:13.464576006 CET4732813566192.168.2.1483.222.118.245
    Jan 14, 2025 17:16:13.464595079 CET5645413566192.168.2.1483.222.240.132
    Jan 14, 2025 17:16:13.464595079 CET3513013566192.168.2.1483.222.109.108
    Jan 14, 2025 17:16:13.464603901 CET5938613566192.168.2.1483.222.60.121
    Jan 14, 2025 17:16:13.464615107 CET3433213566192.168.2.1483.222.139.30
    Jan 14, 2025 17:16:13.464639902 CET5376013566192.168.2.1483.222.191.153
    Jan 14, 2025 17:16:13.464679956 CET5159813566192.168.2.1483.222.66.227
    Jan 14, 2025 17:16:13.464683056 CET5986813566192.168.2.1483.222.83.194
    Jan 14, 2025 17:16:13.464692116 CET5098013566192.168.2.1483.222.52.155
    Jan 14, 2025 17:16:13.464708090 CET3735613566192.168.2.1483.222.194.181
    Jan 14, 2025 17:16:13.464714050 CET3674013566192.168.2.1483.222.206.87
    Jan 14, 2025 17:16:13.464726925 CET4518213566192.168.2.1483.222.29.71
    Jan 14, 2025 17:16:13.464746952 CET6047613566192.168.2.1483.222.91.34
    Jan 14, 2025 17:16:13.464746952 CET4952213566192.168.2.1483.222.174.36
    Jan 14, 2025 17:16:13.464760065 CET3805413566192.168.2.1483.222.180.165
    Jan 14, 2025 17:16:13.464787960 CET3562413566192.168.2.1483.222.25.74
    Jan 14, 2025 17:16:13.464796066 CET5476613566192.168.2.1483.222.90.36
    Jan 14, 2025 17:16:13.464801073 CET5800213566192.168.2.1483.222.168.135
    Jan 14, 2025 17:16:13.464816093 CET5025613566192.168.2.1483.222.0.66
    Jan 14, 2025 17:16:13.464817047 CET5045613566192.168.2.1483.222.183.229
    Jan 14, 2025 17:16:13.464817047 CET4893013566192.168.2.1483.222.3.191
    Jan 14, 2025 17:16:13.464843035 CET4009813566192.168.2.1483.222.220.69
    Jan 14, 2025 17:16:13.465373993 CET3689613566192.168.2.1483.222.7.215
    Jan 14, 2025 17:16:13.465373993 CET3553613566192.168.2.1483.222.202.201
    Jan 14, 2025 17:16:13.465394974 CET5002213566192.168.2.1483.222.140.152
    Jan 14, 2025 17:16:13.465408087 CET4710213566192.168.2.1483.222.32.169
    Jan 14, 2025 17:16:13.465409994 CET3594813566192.168.2.1483.222.163.47
    Jan 14, 2025 17:16:13.465409994 CET4436013566192.168.2.1483.222.224.124
    Jan 14, 2025 17:16:13.465434074 CET3812613566192.168.2.1483.222.204.148
    Jan 14, 2025 17:16:13.465439081 CET5031213566192.168.2.1483.222.33.122
    Jan 14, 2025 17:16:13.465445042 CET4093813566192.168.2.1483.222.184.123
    Jan 14, 2025 17:16:13.465460062 CET3823813566192.168.2.1483.222.158.210
    Jan 14, 2025 17:16:13.465488911 CET4516213566192.168.2.1483.222.89.125
    Jan 14, 2025 17:16:13.465507030 CET5716413566192.168.2.1483.222.44.89
    Jan 14, 2025 17:16:13.465534925 CET5071013566192.168.2.1483.222.191.47
    Jan 14, 2025 17:16:13.465553045 CET3535813566192.168.2.1483.222.116.188
    Jan 14, 2025 17:16:13.465554953 CET3689413566192.168.2.1483.222.25.155
    Jan 14, 2025 17:16:13.465554953 CET5745013566192.168.2.1483.222.202.123
    Jan 14, 2025 17:16:13.465570927 CET3281213566192.168.2.1483.222.147.148
    Jan 14, 2025 17:16:13.465579033 CET5469013566192.168.2.1483.222.68.31
    Jan 14, 2025 17:16:13.465589046 CET4959213566192.168.2.1483.222.45.101
    Jan 14, 2025 17:16:13.465610981 CET5049013566192.168.2.1483.222.200.13
    Jan 14, 2025 17:16:13.465610981 CET5491613566192.168.2.1483.222.225.148
    Jan 14, 2025 17:16:13.465640068 CET3685813566192.168.2.1483.222.14.90
    Jan 14, 2025 17:16:13.465645075 CET6091013566192.168.2.1483.222.161.2
    Jan 14, 2025 17:16:13.465646982 CET4731813566192.168.2.1483.222.126.173
    Jan 14, 2025 17:16:13.465648890 CET4629813566192.168.2.1483.222.198.71
    Jan 14, 2025 17:16:13.465648890 CET6043613566192.168.2.1483.222.44.68
    Jan 14, 2025 17:16:13.465667963 CET4977813566192.168.2.1483.222.244.133
    Jan 14, 2025 17:16:13.465687037 CET4916613566192.168.2.1483.222.193.32
    Jan 14, 2025 17:16:13.465692997 CET3886013566192.168.2.1483.222.222.128
    Jan 14, 2025 17:16:13.465718985 CET3390613566192.168.2.1483.222.79.247
    Jan 14, 2025 17:16:13.465733051 CET3490813566192.168.2.1483.222.28.195
    Jan 14, 2025 17:16:13.465744972 CET4027213566192.168.2.1483.222.179.230
    Jan 14, 2025 17:16:13.465764046 CET4821213566192.168.2.1483.222.62.70
    Jan 14, 2025 17:16:13.465770006 CET5506413566192.168.2.1483.222.123.130
    Jan 14, 2025 17:16:13.465781927 CET3520413566192.168.2.1483.222.101.168
    Jan 14, 2025 17:16:13.465801001 CET5502213566192.168.2.1483.222.231.46
    Jan 14, 2025 17:16:13.465814114 CET4772813566192.168.2.1483.222.181.200
    Jan 14, 2025 17:16:13.465828896 CET5847813566192.168.2.1483.222.203.209
    Jan 14, 2025 17:16:13.465836048 CET3404213566192.168.2.1483.222.194.86
    Jan 14, 2025 17:16:13.465841055 CET6002813566192.168.2.1483.222.176.73
    Jan 14, 2025 17:16:13.465857983 CET4963813566192.168.2.1483.222.126.220
    Jan 14, 2025 17:16:13.465874910 CET4938613566192.168.2.1483.222.141.114
    Jan 14, 2025 17:16:13.465893984 CET5045413566192.168.2.1483.222.97.78
    Jan 14, 2025 17:16:13.465903997 CET5675213566192.168.2.1483.222.146.64
    Jan 14, 2025 17:16:13.465915918 CET5862213566192.168.2.1483.222.206.225
    Jan 14, 2025 17:16:13.465918064 CET3789413566192.168.2.1483.222.55.234
    Jan 14, 2025 17:16:13.465929031 CET5738613566192.168.2.1483.222.164.235
    Jan 14, 2025 17:16:13.465939045 CET5057813566192.168.2.1483.222.209.226
    Jan 14, 2025 17:16:13.465985060 CET4737013566192.168.2.1483.222.49.76
    Jan 14, 2025 17:16:13.469463110 CET135664547083.222.5.109192.168.2.14
    Jan 14, 2025 17:16:13.469522953 CET4547013566192.168.2.1483.222.5.109
    Jan 14, 2025 17:16:13.469644070 CET135664138083.222.111.180192.168.2.14
    Jan 14, 2025 17:16:13.469657898 CET135665093483.222.74.139192.168.2.14
    Jan 14, 2025 17:16:13.469669104 CET135664732883.222.118.245192.168.2.14
    Jan 14, 2025 17:16:13.469679117 CET135665938683.222.60.121192.168.2.14
    Jan 14, 2025 17:16:13.469688892 CET4138013566192.168.2.1483.222.111.180
    Jan 14, 2025 17:16:13.469691038 CET135665645483.222.240.132192.168.2.14
    Jan 14, 2025 17:16:13.469696999 CET4732813566192.168.2.1483.222.118.245
    Jan 14, 2025 17:16:13.469703913 CET135663513083.222.109.108192.168.2.14
    Jan 14, 2025 17:16:13.469715118 CET135663433283.222.139.30192.168.2.14
    Jan 14, 2025 17:16:13.469722986 CET5093413566192.168.2.1483.222.74.139
    Jan 14, 2025 17:16:13.469731092 CET5645413566192.168.2.1483.222.240.132
    Jan 14, 2025 17:16:13.469739914 CET5938613566192.168.2.1483.222.60.121
    Jan 14, 2025 17:16:13.469754934 CET3513013566192.168.2.1483.222.109.108
    Jan 14, 2025 17:16:13.469758987 CET3433213566192.168.2.1483.222.139.30
    Jan 14, 2025 17:16:13.470014095 CET135665376083.222.191.153192.168.2.14
    Jan 14, 2025 17:16:13.470026970 CET135665159883.222.66.227192.168.2.14
    Jan 14, 2025 17:16:13.470037937 CET135665986883.222.83.194192.168.2.14
    Jan 14, 2025 17:16:13.470047951 CET135665098083.222.52.155192.168.2.14
    Jan 14, 2025 17:16:13.470057011 CET5376013566192.168.2.1483.222.191.153
    Jan 14, 2025 17:16:13.470057011 CET5159813566192.168.2.1483.222.66.227
    Jan 14, 2025 17:16:13.470057964 CET135663735683.222.194.181192.168.2.14
    Jan 14, 2025 17:16:13.470077991 CET5098013566192.168.2.1483.222.52.155
    Jan 14, 2025 17:16:13.470078945 CET5986813566192.168.2.1483.222.83.194
    Jan 14, 2025 17:16:13.470089912 CET135663674083.222.206.87192.168.2.14
    Jan 14, 2025 17:16:13.470102072 CET135664518283.222.29.71192.168.2.14
    Jan 14, 2025 17:16:13.470113039 CET135663805483.222.180.165192.168.2.14
    Jan 14, 2025 17:16:13.470124006 CET135666047683.222.91.34192.168.2.14
    Jan 14, 2025 17:16:13.470124006 CET3674013566192.168.2.1483.222.206.87
    Jan 14, 2025 17:16:13.470138073 CET3805413566192.168.2.1483.222.180.165
    Jan 14, 2025 17:16:13.470139027 CET135664952283.222.174.36192.168.2.14
    Jan 14, 2025 17:16:13.470149994 CET135663562483.222.25.74192.168.2.14
    Jan 14, 2025 17:16:13.470154047 CET6047613566192.168.2.1483.222.91.34
    Jan 14, 2025 17:16:13.470163107 CET4952213566192.168.2.1483.222.174.36
    Jan 14, 2025 17:16:13.470163107 CET135665800283.222.168.135192.168.2.14
    Jan 14, 2025 17:16:13.470172882 CET135665025683.222.0.66192.168.2.14
    Jan 14, 2025 17:16:13.470180988 CET135665045683.222.183.229192.168.2.14
    Jan 14, 2025 17:16:13.470182896 CET3562413566192.168.2.1483.222.25.74
    Jan 14, 2025 17:16:13.470191002 CET5800213566192.168.2.1483.222.168.135
    Jan 14, 2025 17:16:13.470191956 CET135665476683.222.90.36192.168.2.14
    Jan 14, 2025 17:16:13.470199108 CET5025613566192.168.2.1483.222.0.66
    Jan 14, 2025 17:16:13.470204115 CET135664893083.222.3.191192.168.2.14
    Jan 14, 2025 17:16:13.470211983 CET5045613566192.168.2.1483.222.183.229
    Jan 14, 2025 17:16:13.470213890 CET135664009883.222.220.69192.168.2.14
    Jan 14, 2025 17:16:13.470228910 CET4518213566192.168.2.1483.222.29.71
    Jan 14, 2025 17:16:13.470236063 CET4893013566192.168.2.1483.222.3.191
    Jan 14, 2025 17:16:13.470259905 CET4009813566192.168.2.1483.222.220.69
    Jan 14, 2025 17:16:13.470320940 CET135663689683.222.7.215192.168.2.14
    Jan 14, 2025 17:16:13.470360994 CET5476613566192.168.2.1483.222.90.36
    Jan 14, 2025 17:16:13.470361948 CET3735613566192.168.2.1483.222.194.181
    Jan 14, 2025 17:16:13.470382929 CET3689613566192.168.2.1483.222.7.215
    Jan 14, 2025 17:16:13.470809937 CET135663553683.222.202.201192.168.2.14
    Jan 14, 2025 17:16:13.470822096 CET135665002283.222.140.152192.168.2.14
    Jan 14, 2025 17:16:13.470832109 CET135664710283.222.32.169192.168.2.14
    Jan 14, 2025 17:16:13.470843077 CET135663594883.222.163.47192.168.2.14
    Jan 14, 2025 17:16:13.470843077 CET3553613566192.168.2.1483.222.202.201
    Jan 14, 2025 17:16:13.470854044 CET135664436083.222.224.124192.168.2.14
    Jan 14, 2025 17:16:13.470855951 CET5002213566192.168.2.1483.222.140.152
    Jan 14, 2025 17:16:13.470868111 CET4710213566192.168.2.1483.222.32.169
    Jan 14, 2025 17:16:13.470869064 CET135663812683.222.204.148192.168.2.14
    Jan 14, 2025 17:16:13.470880032 CET135665031283.222.33.122192.168.2.14
    Jan 14, 2025 17:16:13.470890045 CET135664093883.222.184.123192.168.2.14
    Jan 14, 2025 17:16:13.470906973 CET5031213566192.168.2.1483.222.33.122
    Jan 14, 2025 17:16:13.470906019 CET3812613566192.168.2.1483.222.204.148
    Jan 14, 2025 17:16:13.470916033 CET4093813566192.168.2.1483.222.184.123
    Jan 14, 2025 17:16:13.470917940 CET135663823883.222.158.210192.168.2.14
    Jan 14, 2025 17:16:13.470930099 CET135664516283.222.89.125192.168.2.14
    Jan 14, 2025 17:16:13.470940113 CET135665716483.222.44.89192.168.2.14
    Jan 14, 2025 17:16:13.470949888 CET135665071083.222.191.47192.168.2.14
    Jan 14, 2025 17:16:13.470954895 CET3823813566192.168.2.1483.222.158.210
    Jan 14, 2025 17:16:13.470958948 CET4516213566192.168.2.1483.222.89.125
    Jan 14, 2025 17:16:13.470959902 CET135663535883.222.116.188192.168.2.14
    Jan 14, 2025 17:16:13.470968962 CET5716413566192.168.2.1483.222.44.89
    Jan 14, 2025 17:16:13.470979929 CET5071013566192.168.2.1483.222.191.47
    Jan 14, 2025 17:16:13.470988989 CET135663689483.222.25.155192.168.2.14
    Jan 14, 2025 17:16:13.470993996 CET3535813566192.168.2.1483.222.116.188
    Jan 14, 2025 17:16:13.470998049 CET3594813566192.168.2.1483.222.163.47
    Jan 14, 2025 17:16:13.470998049 CET4436013566192.168.2.1483.222.224.124
    Jan 14, 2025 17:16:13.471000910 CET135665745083.222.202.123192.168.2.14
    Jan 14, 2025 17:16:13.471012115 CET135663281283.222.147.148192.168.2.14
    Jan 14, 2025 17:16:13.471023083 CET135665469083.222.68.31192.168.2.14
    Jan 14, 2025 17:16:13.471028090 CET3689413566192.168.2.1483.222.25.155
    Jan 14, 2025 17:16:13.471028090 CET5745013566192.168.2.1483.222.202.123
    Jan 14, 2025 17:16:13.471034050 CET135664959283.222.45.101192.168.2.14
    Jan 14, 2025 17:16:13.471050024 CET5469013566192.168.2.1483.222.68.31
    Jan 14, 2025 17:16:13.471069098 CET3281213566192.168.2.1483.222.147.148
    Jan 14, 2025 17:16:13.471074104 CET4959213566192.168.2.1483.222.45.101
    Jan 14, 2025 17:16:13.471451044 CET135665049083.222.200.13192.168.2.14
    Jan 14, 2025 17:16:13.471462965 CET135665491683.222.225.148192.168.2.14
    Jan 14, 2025 17:16:13.471472979 CET135663685883.222.14.90192.168.2.14
    Jan 14, 2025 17:16:13.471483946 CET135666091083.222.161.2192.168.2.14
    Jan 14, 2025 17:16:13.471489906 CET5049013566192.168.2.1483.222.200.13
    Jan 14, 2025 17:16:13.471489906 CET5491613566192.168.2.1483.222.225.148
    Jan 14, 2025 17:16:13.471494913 CET135664731883.222.126.173192.168.2.14
    Jan 14, 2025 17:16:13.471507072 CET3685813566192.168.2.1483.222.14.90
    Jan 14, 2025 17:16:13.471517086 CET6091013566192.168.2.1483.222.161.2
    Jan 14, 2025 17:16:13.471518040 CET135664629883.222.198.71192.168.2.14
    Jan 14, 2025 17:16:13.471529007 CET4731813566192.168.2.1483.222.126.173
    Jan 14, 2025 17:16:13.471533060 CET135664977883.222.244.133192.168.2.14
    Jan 14, 2025 17:16:13.471554995 CET135666043683.222.44.68192.168.2.14
    Jan 14, 2025 17:16:13.471565962 CET135664916683.222.193.32192.168.2.14
    Jan 14, 2025 17:16:13.471575975 CET135663886083.222.222.128192.168.2.14
    Jan 14, 2025 17:16:13.471577883 CET4977813566192.168.2.1483.222.244.133
    Jan 14, 2025 17:16:13.471586943 CET135663390683.222.79.247192.168.2.14
    Jan 14, 2025 17:16:13.471596956 CET4916613566192.168.2.1483.222.193.32
    Jan 14, 2025 17:16:13.471599102 CET135663490883.222.28.195192.168.2.14
    Jan 14, 2025 17:16:13.471609116 CET3886013566192.168.2.1483.222.222.128
    Jan 14, 2025 17:16:13.471609116 CET135664027283.222.179.230192.168.2.14
    Jan 14, 2025 17:16:13.471610069 CET3390613566192.168.2.1483.222.79.247
    Jan 14, 2025 17:16:13.471618891 CET135665506483.222.123.130192.168.2.14
    Jan 14, 2025 17:16:13.471630096 CET3490813566192.168.2.1483.222.28.195
    Jan 14, 2025 17:16:13.471630096 CET135663520483.222.101.168192.168.2.14
    Jan 14, 2025 17:16:13.471642971 CET135664821283.222.62.70192.168.2.14
    Jan 14, 2025 17:16:13.471648932 CET4027213566192.168.2.1483.222.179.230
    Jan 14, 2025 17:16:13.471648932 CET5506413566192.168.2.1483.222.123.130
    Jan 14, 2025 17:16:13.471659899 CET135665502283.222.231.46192.168.2.14
    Jan 14, 2025 17:16:13.471659899 CET3520413566192.168.2.1483.222.101.168
    Jan 14, 2025 17:16:13.471669912 CET135664772883.222.181.200192.168.2.14
    Jan 14, 2025 17:16:13.471673012 CET4629813566192.168.2.1483.222.198.71
    Jan 14, 2025 17:16:13.471674919 CET4821213566192.168.2.1483.222.62.70
    Jan 14, 2025 17:16:13.471673012 CET6043613566192.168.2.1483.222.44.68
    Jan 14, 2025 17:16:13.471682072 CET135665847883.222.203.209192.168.2.14
    Jan 14, 2025 17:16:13.471689939 CET5502213566192.168.2.1483.222.231.46
    Jan 14, 2025 17:16:13.471693039 CET135663404283.222.194.86192.168.2.14
    Jan 14, 2025 17:16:13.471703053 CET4772813566192.168.2.1483.222.181.200
    Jan 14, 2025 17:16:13.471705914 CET135666002883.222.176.73192.168.2.14
    Jan 14, 2025 17:16:13.471715927 CET135664963883.222.126.220192.168.2.14
    Jan 14, 2025 17:16:13.471719027 CET5847813566192.168.2.1483.222.203.209
    Jan 14, 2025 17:16:13.471740961 CET6002813566192.168.2.1483.222.176.73
    Jan 14, 2025 17:16:13.471744061 CET3404213566192.168.2.1483.222.194.86
    Jan 14, 2025 17:16:13.471759081 CET4963813566192.168.2.1483.222.126.220
    Jan 14, 2025 17:16:13.471842051 CET135664938683.222.141.114192.168.2.14
    Jan 14, 2025 17:16:13.471853018 CET135665045483.222.97.78192.168.2.14
    Jan 14, 2025 17:16:13.471863031 CET135665675283.222.146.64192.168.2.14
    Jan 14, 2025 17:16:13.471877098 CET4938613566192.168.2.1483.222.141.114
    Jan 14, 2025 17:16:13.471882105 CET5045413566192.168.2.1483.222.97.78
    Jan 14, 2025 17:16:13.471894026 CET135665862283.222.206.225192.168.2.14
    Jan 14, 2025 17:16:13.471899986 CET5675213566192.168.2.1483.222.146.64
    Jan 14, 2025 17:16:13.471904039 CET135665738683.222.164.235192.168.2.14
    Jan 14, 2025 17:16:13.471914053 CET135663789483.222.55.234192.168.2.14
    Jan 14, 2025 17:16:13.471924067 CET135665057883.222.209.226192.168.2.14
    Jan 14, 2025 17:16:13.471925974 CET5862213566192.168.2.1483.222.206.225
    Jan 14, 2025 17:16:13.471931934 CET5738613566192.168.2.1483.222.164.235
    Jan 14, 2025 17:16:13.471934080 CET135664737083.222.49.76192.168.2.14
    Jan 14, 2025 17:16:13.471952915 CET5057813566192.168.2.1483.222.209.226
    Jan 14, 2025 17:16:13.471961975 CET3789413566192.168.2.1483.222.55.234
    Jan 14, 2025 17:16:13.471961975 CET4737013566192.168.2.1483.222.49.76
    Jan 14, 2025 17:16:13.477343082 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:16:13.482182980 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:16:13.482228994 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:16:13.482261896 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:16:13.487199068 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:16:13.487232924 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:16:13.492149115 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:16:23.490004063 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:16:23.494848013 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:16:23.622124910 CET46540443192.168.2.14185.125.190.26
    Jan 14, 2025 17:16:23.697230101 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:16:23.697366953 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:16:24.078908920 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:16:24.078969002 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:16:54.340832949 CET46540443192.168.2.14185.125.190.26
    Jan 14, 2025 17:17:24.137701988 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:17:24.142622948 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:17:24.345388889 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:17:24.345508099 CET5649013566192.168.2.1483.222.191.90
    Jan 14, 2025 17:17:25.078016996 CET135665649083.222.191.90192.168.2.14
    Jan 14, 2025 17:17:25.078155994 CET5649013566192.168.2.1483.222.191.90
    TimestampSource PortDest PortSource IPDest IP
    Jan 14, 2025 17:16:13.466006041 CET4883253192.168.2.148.8.8.8
    Jan 14, 2025 17:16:13.477266073 CET53488328.8.8.8192.168.2.14
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Jan 14, 2025 17:16:13.466006041 CET192.168.2.148.8.8.80x2161Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Jan 14, 2025 17:16:13.477266073 CET8.8.8.8192.168.2.140x2161No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):16:16:05
    Start date (UTC):14/01/2025
    Path:/usr/bin/dash
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:05
    Start date (UTC):14/01/2025
    Path:/usr/bin/rm
    Arguments:rm -f /tmp/tmp.fHLZqw1TN3 /tmp/tmp.ow2JfsB4Wn /tmp/tmp.FCcwH7Zebc
    File size:72056 bytes
    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

    Start time (UTC):16:16:05
    Start date (UTC):14/01/2025
    Path:/usr/bin/dash
    Arguments:-
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:05
    Start date (UTC):14/01/2025
    Path:/usr/bin/rm
    Arguments:rm -f /tmp/tmp.fHLZqw1TN3 /tmp/tmp.ow2JfsB4Wn /tmp/tmp.FCcwH7Zebc
    File size:72056 bytes
    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:/tmp/Kloki.x86.elf
    File size:38312 bytes
    MD5 hash:9c0cf500a75080a480c04b5ab4af863a

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:-
    File size:38312 bytes
    MD5 hash:9c0cf500a75080a480c04b5ab4af863a

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:-
    File size:38312 bytes
    MD5 hash:9c0cf500a75080a480c04b5ab4af863a

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/tmp/Kloki.x86.elf
    Arguments:-
    File size:38312 bytes
    MD5 hash:9c0cf500a75080a480c04b5ab4af863a

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gsd-print-notifications
    Arguments:/usr/libexec/gsd-print-notifications
    File size:51840 bytes
    MD5 hash:71539698aa691718cee775d6b9450ae2

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/bin/gnome-shell
    Arguments:/usr/bin/gnome-shell
    File size:23168 bytes
    MD5 hash:da7a257239677622fe4b3a65972c9e87

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gsd-rfkill
    Arguments:/usr/libexec/gsd-rfkill
    File size:51808 bytes
    MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gnome-session-binary
    Arguments:-
    File size:334664 bytes
    MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/bin/sh
    Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/libexec/gsd-sharing
    Arguments:/usr/libexec/gsd-sharing
    File size:35424 bytes
    MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/usr/sbin/gdm3
    Arguments:-
    File size:453296 bytes
    MD5 hash:2492e2d8d34f9377e3e530a61a15674f

    Start time (UTC):16:16:13
    Start date (UTC):14/01/2025
    Path:/etc/gdm3/PrimeOff/Default
    Arguments:/etc/gdm3/PrimeOff/Default
    File size:129816 bytes
    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

    Start time (UTC):16:16:23
    Start date (UTC):14/01/2025
    Path:/usr/lib/systemd/systemd
    Arguments:-
    File size:1620224 bytes
    MD5 hash:9b2bec7092a40488108543f9334aab75

    Start time (UTC):16:16:23
    Start date (UTC):14/01/2025
    Path:/lib/systemd/systemd-user-runtime-dir
    Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
    File size:22672 bytes
    MD5 hash:d55f4b0847f88131dbcfb07435178e54