Edit tour

Linux Analysis Report
dbg.x86.elf

Overview

General Information

Sample name:dbg.x86.elf
Analysis ID:1594241
MD5:9f2c1c92152f3013559fee6e6ecfb565
SHA1:c206b616b5cd97a9384ee6915aa6109b8a248683
SHA256:b30831201a3c2fe4f0562bef572dae187194a7be81c5eff47c07a6102325fe33
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Suricata IDS alerts with low severity for network traffic
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594241
Start date and time:2025-01-18 17:07:11 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 57s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dbg.x86.elf
Detection:MAL
Classification:mal60.linELF@0/0@3/0
Command:/tmp/dbg.x86.elf
PID:5489
Exit Code:
Exit Code Info:
Killed:True
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • dbg.x86.elf (PID: 5489, Parent: 5412, MD5: 9f2c1c92152f3013559fee6e6ecfb565) Arguments: /tmp/dbg.x86.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
5489.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4a40:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
5489.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_5f7b67b8unknownunknown
  • 0x8bad:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
5489.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_449937aaunknownunknown
  • 0xf4ba:$a: 00 00 5B 72 65 73 6F 6C 76 5D 20 46 6F 75 6E 64 20 49 50 20
5489.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x6652:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5489.1.0000000008048000.0000000008059000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0xb5b8:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
Click to see the 2 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-18T17:08:03.266588+010025000342Misc Attack83.222.191.9013566192.168.2.1456490TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: dbg.x86.elfVirustotal: Detection: 18%Perma Link
Source: dbg.x86.elfReversingLabs: Detection: 21%
Source: dbg.x86.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.14:36682 -> 83.222.54.96:13566
Source: global trafficTCP traffic: 192.168.2.14:34796 -> 83.222.76.86:13566
Source: global trafficTCP traffic: 192.168.2.14:35546 -> 83.222.134.84:13566
Source: global trafficTCP traffic: 192.168.2.14:35022 -> 83.222.238.151:13566
Source: global trafficTCP traffic: 192.168.2.14:33898 -> 83.222.100.147:13566
Source: global trafficTCP traffic: 192.168.2.14:49760 -> 83.222.232.215:13566
Source: global trafficTCP traffic: 192.168.2.14:40996 -> 83.222.225.236:13566
Source: global trafficTCP traffic: 192.168.2.14:54754 -> 83.222.222.240:13566
Source: global trafficTCP traffic: 192.168.2.14:46450 -> 83.222.9.41:13566
Source: global trafficTCP traffic: 192.168.2.14:32884 -> 83.222.238.142:13566
Source: global trafficTCP traffic: 192.168.2.14:35040 -> 83.222.201.183:13566
Source: global trafficTCP traffic: 192.168.2.14:36548 -> 83.222.138.44:13566
Source: global trafficTCP traffic: 192.168.2.14:48518 -> 83.222.67.120:13566
Source: global trafficTCP traffic: 192.168.2.14:56804 -> 83.222.131.104:13566
Source: global trafficTCP traffic: 192.168.2.14:46900 -> 83.222.186.121:13566
Source: global trafficTCP traffic: 192.168.2.14:40038 -> 83.222.216.6:13566
Source: global trafficTCP traffic: 192.168.2.14:56642 -> 83.222.221.86:13566
Source: global trafficTCP traffic: 192.168.2.14:51076 -> 83.222.21.142:13566
Source: global trafficTCP traffic: 192.168.2.14:52556 -> 83.222.77.121:13566
Source: global trafficTCP traffic: 192.168.2.14:45126 -> 83.222.177.247:13566
Source: global trafficTCP traffic: 192.168.2.14:35350 -> 83.222.217.218:13566
Source: global trafficTCP traffic: 192.168.2.14:60212 -> 83.222.207.192:13566
Source: global trafficTCP traffic: 192.168.2.14:33984 -> 83.222.16.235:13566
Source: global trafficTCP traffic: 192.168.2.14:41268 -> 83.222.34.59:13566
Source: global trafficTCP traffic: 192.168.2.14:57394 -> 83.222.226.225:13566
Source: global trafficTCP traffic: 192.168.2.14:51594 -> 83.222.250.187:13566
Source: global trafficTCP traffic: 192.168.2.14:45476 -> 83.222.187.125:13566
Source: global trafficTCP traffic: 192.168.2.14:57576 -> 83.222.169.102:13566
Source: global trafficTCP traffic: 192.168.2.14:40846 -> 83.222.189.100:13566
Source: global trafficTCP traffic: 192.168.2.14:39014 -> 83.222.223.149:13566
Source: global trafficTCP traffic: 192.168.2.14:35958 -> 83.222.106.175:13566
Source: global trafficTCP traffic: 192.168.2.14:54384 -> 83.222.242.242:13566
Source: global trafficTCP traffic: 192.168.2.14:48600 -> 83.222.216.209:13566
Source: global trafficTCP traffic: 192.168.2.14:53612 -> 83.222.86.72:13566
Source: global trafficTCP traffic: 192.168.2.14:37870 -> 83.222.35.69:13566
Source: global trafficTCP traffic: 192.168.2.14:52718 -> 83.222.5.107:13566
Source: global trafficTCP traffic: 192.168.2.14:40628 -> 83.222.214.82:13566
Source: global trafficTCP traffic: 192.168.2.14:49378 -> 83.222.228.248:13566
Source: global trafficTCP traffic: 192.168.2.14:49592 -> 83.222.142.245:13566
Source: global trafficTCP traffic: 192.168.2.14:43142 -> 83.222.228.128:13566
Source: global trafficTCP traffic: 192.168.2.14:54996 -> 83.222.231.188:13566
Source: global trafficTCP traffic: 192.168.2.14:48750 -> 83.222.81.201:13566
Source: global trafficTCP traffic: 192.168.2.14:43890 -> 83.222.157.76:13566
Source: global trafficTCP traffic: 192.168.2.14:50862 -> 83.222.133.88:13566
Source: global trafficTCP traffic: 192.168.2.14:45592 -> 83.222.201.168:13566
Source: global trafficTCP traffic: 192.168.2.14:39380 -> 83.222.158.115:13566
Source: global trafficTCP traffic: 192.168.2.14:45780 -> 83.222.215.238:13566
Source: global trafficTCP traffic: 192.168.2.14:47080 -> 83.222.15.91:13566
Source: global trafficTCP traffic: 192.168.2.14:58338 -> 83.222.241.65:13566
Source: global trafficTCP traffic: 192.168.2.14:50492 -> 83.222.157.71:13566
Source: global trafficTCP traffic: 192.168.2.14:39766 -> 83.222.137.162:13566
Source: global trafficTCP traffic: 192.168.2.14:44098 -> 83.222.178.96:13566
Source: global trafficTCP traffic: 192.168.2.14:46304 -> 83.222.245.150:13566
Source: global trafficTCP traffic: 192.168.2.14:38810 -> 83.222.88.131:13566
Source: global trafficTCP traffic: 192.168.2.14:44834 -> 83.222.139.60:13566
Source: global trafficTCP traffic: 192.168.2.14:52936 -> 83.222.3.114:13566
Source: global trafficTCP traffic: 192.168.2.14:53332 -> 83.222.248.85:13566
Source: global trafficTCP traffic: 192.168.2.14:33238 -> 83.222.60.149:13566
Source: global trafficTCP traffic: 192.168.2.14:49370 -> 83.222.161.193:13566
Source: global trafficTCP traffic: 192.168.2.14:49420 -> 83.222.105.140:13566
Source: global trafficTCP traffic: 192.168.2.14:50666 -> 83.222.238.106:13566
Source: global trafficTCP traffic: 192.168.2.14:59838 -> 83.222.231.180:13566
Source: global trafficTCP traffic: 192.168.2.14:44884 -> 83.222.221.120:13566
Source: global trafficTCP traffic: 192.168.2.14:56626 -> 83.222.103.216:13566
Source: global trafficTCP traffic: 192.168.2.14:60728 -> 83.222.246.4:13566
Source: global trafficTCP traffic: 192.168.2.14:57038 -> 83.222.31.127:13566
Source: global trafficTCP traffic: 192.168.2.14:56490 -> 83.222.191.90:13566
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.14:56490
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.54.96
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.76.86
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.134.84
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.151
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.100.147
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.232.215
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.225.236
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.222.240
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.9.41
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.142
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.201.183
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.138.44
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.67.120
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.131.104
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.186.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.216.6
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.221.86
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.21.142
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.77.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.177.247
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.217.218
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.207.192
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.16.235
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.34.59
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.226.225
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.250.187
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.125
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.169.102
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.189.100
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.223.149
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.106.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.242.242
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.216.209
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.86.72
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.35.69
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.5.107
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.214.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.228.248
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.142.245
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.228.128
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.231.188
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.81.201
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.157.76
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.133.88
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.201.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.158.115
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.215.238
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.15.91
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.241.65
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.157.71
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

System Summary

barindex
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_449937aa Author: unknown
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: LOAD without section mappingsProgram segment: 0x8048000
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_449937aa reference_sample = 6f27766534445cffb097c7c52db1fca53b2210c1b10b75594f77c34dc8b994fe, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = cf2c6b86830099f039b41aeaafbffedfb8294a1124c499e99a11f48a06cd1dfd, id = 449937aa-682a-4906-89ab-80d7127e461e, last_modified = 2021-09-16
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5489.1.0000000008048000.0000000008059000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal60.linELF@0/0@3/0
Source: dbg.x86.elfSubmission file: segment LOAD with 7.8959 entropy (max. 8.0)
Source: dbg.x86.elfSubmission file: segment LOAD with 7.9646 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Obfuscated Files or Information
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594241 Sample: dbg.x86.elf Startdate: 18/01/2025 Architecture: LINUX Score: 60 8 83.222.201.168, 13566, 45592 SYNTERRA-ASRU Russian Federation 2->8 10 83.222.201.183, 13566, 35040 SYNTERRA-ASRU Russian Federation 2->10 12 66 other IPs or domains 2->12 14 Malicious sample detected (through community Yara rule) 2->14 16 Multi AV Scanner detection for submitted file 2->16 18 Machine Learning detection for sample 2->18 6 dbg.x86.elf 2->6         started        signatures3 process4
SourceDetectionScannerLabelLink
dbg.x86.elf19%VirustotalBrowse
dbg.x86.elf21%ReversingLabsLinux.Packed.Mirai
dbg.x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    high
    secure-network-rebirthltd.ru
    83.222.191.90
    truefalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      83.222.106.175
      unknownRussian Federation
      42632MNOGOBYTE-ASMoscowRussiaRUfalse
      83.222.201.168
      unknownRussian Federation
      6854SYNTERRA-ASRUfalse
      83.222.81.201
      unknownRussian Federation
      16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
      83.222.223.149
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.231.188
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.228.248
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.60.149
      unknownLuxembourg
      8632LOL-ASluLUfalse
      83.222.225.236
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.86.72
      unknownRussian Federation
      16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
      83.222.228.128
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.246.4
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.169.102
      unknownBulgaria
      12615GCN-ASGCNAD-SofiaBulgariaBGfalse
      83.222.100.147
      unknownRussian Federation
      42632MNOGOBYTE-ASMoscowRussiaRUfalse
      83.222.238.142
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.67.120
      unknownRussian Federation
      16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
      83.222.131.104
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.216.209
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.221.120
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.157.71
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.76.86
      unknownRussian Federation
      16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
      83.222.137.162
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.221.86
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.133.88
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.226.225
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.161.193
      unknownBulgaria
      12615GCN-ASGCNAD-SofiaBulgariaBGfalse
      83.222.207.192
      unknownRussian Federation
      6854SYNTERRA-ASRUfalse
      83.222.139.60
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.238.106
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.231.180
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.189.100
      unknownBulgaria
      43561NET1-ASBGfalse
      83.222.9.41
      unknownRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      83.222.232.215
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.157.76
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.21.142
      unknownRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      83.222.177.247
      unknownBulgaria
      12615GCN-ASGCNAD-SofiaBulgariaBGfalse
      83.222.142.245
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.158.115
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.222.240
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.217.218
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.201.183
      unknownRussian Federation
      6854SYNTERRA-ASRUfalse
      83.222.15.91
      unknownRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      83.222.238.151
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.103.216
      unknownRussian Federation
      42632MNOGOBYTE-ASMoscowRussiaRUfalse
      83.222.186.121
      unknownBulgaria
      43561NET1-ASBGfalse
      83.222.214.82
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.241.65
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.187.125
      unknownBulgaria
      43561NET1-ASBGfalse
      83.222.77.121
      unknownRussian Federation
      16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
      83.222.138.44
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.105.140
      unknownRussian Federation
      42632MNOGOBYTE-ASMoscowRussiaRUfalse
      83.222.134.84
      unknownSwitzerland
      31736SENSELAN-ASsenseLANGmbHCHfalse
      83.222.88.131
      unknownRussian Federation
      16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
      83.222.250.187
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.215.238
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.191.90
      secure-network-rebirthltd.ruBulgaria
      43561NET1-ASBGfalse
      83.222.242.242
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.54.96
      unknownLuxembourg
      8632LOL-ASluLUfalse
      83.222.216.6
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      83.222.35.69
      unknownLuxembourg
      8632LOL-ASluLUfalse
      83.222.34.59
      unknownLuxembourg
      8632LOL-ASluLUfalse
      83.222.245.150
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.31.127
      unknownRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      83.222.248.85
      unknownUnited Kingdom
      13768COGECO-PEER1CAfalse
      83.222.16.235
      unknownRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      83.222.178.96
      unknownBulgaria
      12615GCN-ASGCNAD-SofiaBulgariaBGfalse
      83.222.3.114
      unknownRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      83.222.5.107
      unknownRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      83.222.67.120Kloki.spc.elfGet hashmaliciousUnknownBrowse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        secure-network-rebirthltd.ruloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        loki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.191.90
        Kloki.spc.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.arm5.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        daisy.ubuntu.comI586.elfGet hashmaliciousMiraiBrowse
        • 162.213.35.24
        ARMV4L.elfGet hashmaliciousUnknownBrowse
        • 162.213.35.24
        ARMV6L.elfGet hashmaliciousUnknownBrowse
        • 162.213.35.24
        MIPSEL.elfGet hashmaliciousUnknownBrowse
        • 162.213.35.25
        ARMV5L.elfGet hashmaliciousUnknownBrowse
        • 162.213.35.24
        sshd.elfGet hashmaliciousUnknownBrowse
        • 162.213.35.24
        .i.elfGet hashmaliciousUnknownBrowse
        • 162.213.35.25
        armv7l.elfGet hashmaliciousMiraiBrowse
        • 162.213.35.25
        armv6l.elfGet hashmaliciousMiraiBrowse
        • 162.213.35.25
        arm7.elfGet hashmaliciousMiraiBrowse
        • 162.213.35.24
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        MNOGOBYTE-ASMoscowRussiaRUloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.109.99
        loki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.120.85
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.99.213
        Kloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.113.214
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.118.111
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.96.0
        Kloki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.122.221
        Kloki.spc.elfGet hashmaliciousUnknownBrowse
        • 83.222.115.97
        Kloki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.101.124
        Kloki.arm5.elfGet hashmaliciousUnknownBrowse
        • 83.222.99.171
        SYNTERRA-ASRUloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.209.207
        loki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.195.90
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.206.35
        Kloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.204.120
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.197.216
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.196.227
        Kloki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.202.81
        Kloki.spc.elfGet hashmaliciousUnknownBrowse
        • 83.222.209.206
        Kloki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.198.182
        Kloki.arm5.elfGet hashmaliciousUnknownBrowse
        • 83.222.198.132
        ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.64.68
        loki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.67.220
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.85.46
        Kloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.86.49
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.69.178
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.80.120
        Kloki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.69.49
        Kloki.spc.elfGet hashmaliciousUnknownBrowse
        • 83.222.72.213
        Kloki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.73.253
        Kloki.arm5.elfGet hashmaliciousUnknownBrowse
        • 83.222.94.114
        SONICDUO-ASRUloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.214.205
        loki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.212.78
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.223.232
        Kloki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.220.113
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.219.64
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.212.74
        Kloki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.213.75
        Kloki.spc.elfGet hashmaliciousUnknownBrowse
        • 83.222.212.208
        Kloki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.222.77
        Kloki.arm5.elfGet hashmaliciousUnknownBrowse
        • 83.222.219.215
        No context
        No context
        No created / dropped files found
        File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
        Entropy (8bit):7.962272139947051
        TrID:
        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
        File name:dbg.x86.elf
        File size:37'484 bytes
        MD5:9f2c1c92152f3013559fee6e6ecfb565
        SHA1:c206b616b5cd97a9384ee6915aa6109b8a248683
        SHA256:b30831201a3c2fe4f0562bef572dae187194a7be81c5eff47c07a6102325fe33
        SHA512:8858d35ec9ed1ac36d244b8ea08fa3700be857cce9aa80709ed16162f43353cd2cbcd10aae48e5fc33c67cc7818d88280b55c87cf443557988819a138ae19642
        SSDEEP:768:3WVYzxXEK9/fmBPTJoMHivqMRlv51G2n68N0qHjH4QMsBxFnbcuyD7UoURe:3WVIEK9/+BCMCvdv5tnFN0cj/v/Fnou6
        TLSH:DBF2E15DABCD5F61E97FB3B704FEA7000D217356C59D4A96F6C8051D36207883A21AC7
        File Content Preview:.ELF....................0...4...........4. ...(.........................l.................... ... ..i...i...........Q.td.............................j=.sfgaD........X...X......V..........?..k.I/.j....\.d*nlz.eB"[bx.|"|M.`...S....T[.N.........8 ...'.b.B?..

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:Intel 80386
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:UNIX - Linux
        ABI Version:0
        Entry Point Address:0x8069f30
        Flags:0x0
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:3
        Section Header Offset:0
        Section Header Size:40
        Number of Section Headers:0
        Header String Table Index:0
        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x80480000x80480000x10000x19f6c7.89590x6RW 0x1000
        LOAD0x00x80620000x80620000x91690x91697.96460x5R E0x1000
        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

        Download Network PCAP: filteredfull

        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
        2025-01-18T17:08:03.266588+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1456490TCP
        • Total Packets: 144
        • 13566 undefined
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Jan 18, 2025 17:08:03.234124899 CET3668213566192.168.2.1483.222.54.96
        Jan 18, 2025 17:08:03.234124899 CET3479613566192.168.2.1483.222.76.86
        Jan 18, 2025 17:08:03.234149933 CET3554613566192.168.2.1483.222.134.84
        Jan 18, 2025 17:08:03.234163046 CET3502213566192.168.2.1483.222.238.151
        Jan 18, 2025 17:08:03.234175920 CET3389813566192.168.2.1483.222.100.147
        Jan 18, 2025 17:08:03.234181881 CET4976013566192.168.2.1483.222.232.215
        Jan 18, 2025 17:08:03.234181881 CET4099613566192.168.2.1483.222.225.236
        Jan 18, 2025 17:08:03.234191895 CET5475413566192.168.2.1483.222.222.240
        Jan 18, 2025 17:08:03.234193087 CET4645013566192.168.2.1483.222.9.41
        Jan 18, 2025 17:08:03.234200001 CET3288413566192.168.2.1483.222.238.142
        Jan 18, 2025 17:08:03.234205008 CET3504013566192.168.2.1483.222.201.183
        Jan 18, 2025 17:08:03.234225988 CET3654813566192.168.2.1483.222.138.44
        Jan 18, 2025 17:08:03.234225988 CET4851813566192.168.2.1483.222.67.120
        Jan 18, 2025 17:08:03.234232903 CET5680413566192.168.2.1483.222.131.104
        Jan 18, 2025 17:08:03.234235048 CET4690013566192.168.2.1483.222.186.121
        Jan 18, 2025 17:08:03.234237909 CET4003813566192.168.2.1483.222.216.6
        Jan 18, 2025 17:08:03.234252930 CET5664213566192.168.2.1483.222.221.86
        Jan 18, 2025 17:08:03.234252930 CET5107613566192.168.2.1483.222.21.142
        Jan 18, 2025 17:08:03.234265089 CET5255613566192.168.2.1483.222.77.121
        Jan 18, 2025 17:08:03.234270096 CET4512613566192.168.2.1483.222.177.247
        Jan 18, 2025 17:08:03.234266996 CET3535013566192.168.2.1483.222.217.218
        Jan 18, 2025 17:08:03.234267950 CET6021213566192.168.2.1483.222.207.192
        Jan 18, 2025 17:08:03.234277010 CET3398413566192.168.2.1483.222.16.235
        Jan 18, 2025 17:08:03.234307051 CET4126813566192.168.2.1483.222.34.59
        Jan 18, 2025 17:08:03.234307051 CET5739413566192.168.2.1483.222.226.225
        Jan 18, 2025 17:08:03.234307051 CET5159413566192.168.2.1483.222.250.187
        Jan 18, 2025 17:08:03.234319925 CET4547613566192.168.2.1483.222.187.125
        Jan 18, 2025 17:08:03.234330893 CET5757613566192.168.2.1483.222.169.102
        Jan 18, 2025 17:08:03.234338999 CET4084613566192.168.2.1483.222.189.100
        Jan 18, 2025 17:08:03.234342098 CET3901413566192.168.2.1483.222.223.149
        Jan 18, 2025 17:08:03.234349012 CET3595813566192.168.2.1483.222.106.175
        Jan 18, 2025 17:08:03.234360933 CET5438413566192.168.2.1483.222.242.242
        Jan 18, 2025 17:08:03.234360933 CET4860013566192.168.2.1483.222.216.209
        Jan 18, 2025 17:08:03.234364033 CET5361213566192.168.2.1483.222.86.72
        Jan 18, 2025 17:08:03.234361887 CET3787013566192.168.2.1483.222.35.69
        Jan 18, 2025 17:08:03.234369993 CET5271813566192.168.2.1483.222.5.107
        Jan 18, 2025 17:08:03.234378099 CET4062813566192.168.2.1483.222.214.82
        Jan 18, 2025 17:08:03.234392881 CET4937813566192.168.2.1483.222.228.248
        Jan 18, 2025 17:08:03.234395027 CET4959213566192.168.2.1483.222.142.245
        Jan 18, 2025 17:08:03.234406948 CET4314213566192.168.2.1483.222.228.128
        Jan 18, 2025 17:08:03.234416962 CET5499613566192.168.2.1483.222.231.188
        Jan 18, 2025 17:08:03.234431982 CET4875013566192.168.2.1483.222.81.201
        Jan 18, 2025 17:08:03.234435081 CET4389013566192.168.2.1483.222.157.76
        Jan 18, 2025 17:08:03.234446049 CET5086213566192.168.2.1483.222.133.88
        Jan 18, 2025 17:08:03.234455109 CET4559213566192.168.2.1483.222.201.168
        Jan 18, 2025 17:08:03.234472990 CET3938013566192.168.2.1483.222.158.115
        Jan 18, 2025 17:08:03.234472990 CET4578013566192.168.2.1483.222.215.238
        Jan 18, 2025 17:08:03.234476089 CET4708013566192.168.2.1483.222.15.91
        Jan 18, 2025 17:08:03.234484911 CET5833813566192.168.2.1483.222.241.65
        Jan 18, 2025 17:08:03.234488010 CET5049213566192.168.2.1483.222.157.71
        Jan 18, 2025 17:08:03.234508038 CET3976613566192.168.2.1483.222.137.162
        Jan 18, 2025 17:08:03.234508991 CET4409813566192.168.2.1483.222.178.96
        Jan 18, 2025 17:08:03.234518051 CET4630413566192.168.2.1483.222.245.150
        Jan 18, 2025 17:08:03.234522104 CET3881013566192.168.2.1483.222.88.131
        Jan 18, 2025 17:08:03.234538078 CET4483413566192.168.2.1483.222.139.60
        Jan 18, 2025 17:08:03.234541893 CET5293613566192.168.2.1483.222.3.114
        Jan 18, 2025 17:08:03.234556913 CET5333213566192.168.2.1483.222.248.85
        Jan 18, 2025 17:08:03.234572887 CET3323813566192.168.2.1483.222.60.149
        Jan 18, 2025 17:08:03.234572887 CET4937013566192.168.2.1483.222.161.193
        Jan 18, 2025 17:08:03.234579086 CET4942013566192.168.2.1483.222.105.140
        Jan 18, 2025 17:08:03.234582901 CET5066613566192.168.2.1483.222.238.106
        Jan 18, 2025 17:08:03.234596014 CET5983813566192.168.2.1483.222.231.180
        Jan 18, 2025 17:08:03.234597921 CET4488413566192.168.2.1483.222.221.120
        Jan 18, 2025 17:08:03.234611034 CET5662613566192.168.2.1483.222.103.216
        Jan 18, 2025 17:08:03.234613895 CET6072813566192.168.2.1483.222.246.4
        Jan 18, 2025 17:08:03.234625101 CET5703813566192.168.2.1483.222.31.127
        Jan 18, 2025 17:08:03.250891924 CET135663668283.222.54.96192.168.2.14
        Jan 18, 2025 17:08:03.250948906 CET135663479683.222.76.86192.168.2.14
        Jan 18, 2025 17:08:03.250971079 CET3668213566192.168.2.1483.222.54.96
        Jan 18, 2025 17:08:03.250983000 CET3479613566192.168.2.1483.222.76.86
        Jan 18, 2025 17:08:03.250998020 CET135663502283.222.238.151192.168.2.14
        Jan 18, 2025 17:08:03.251029968 CET135663554683.222.134.84192.168.2.14
        Jan 18, 2025 17:08:03.251040936 CET3502213566192.168.2.1483.222.238.151
        Jan 18, 2025 17:08:03.251061916 CET135664976083.222.232.215192.168.2.14
        Jan 18, 2025 17:08:03.251070023 CET3554613566192.168.2.1483.222.134.84
        Jan 18, 2025 17:08:03.251091003 CET135664099683.222.225.236192.168.2.14
        Jan 18, 2025 17:08:03.251106977 CET4976013566192.168.2.1483.222.232.215
        Jan 18, 2025 17:08:03.251121998 CET4099613566192.168.2.1483.222.225.236
        Jan 18, 2025 17:08:03.251130104 CET135663504083.222.201.183192.168.2.14
        Jan 18, 2025 17:08:03.251161098 CET135665475483.222.222.240192.168.2.14
        Jan 18, 2025 17:08:03.251172066 CET3504013566192.168.2.1483.222.201.183
        Jan 18, 2025 17:08:03.251189947 CET135664645083.222.9.41192.168.2.14
        Jan 18, 2025 17:08:03.251199007 CET5475413566192.168.2.1483.222.222.240
        Jan 18, 2025 17:08:03.251225948 CET4645013566192.168.2.1483.222.9.41
        Jan 18, 2025 17:08:03.251231909 CET135663288483.222.238.142192.168.2.14
        Jan 18, 2025 17:08:03.251275063 CET3288413566192.168.2.1483.222.238.142
        Jan 18, 2025 17:08:03.255705118 CET135665680483.222.131.104192.168.2.14
        Jan 18, 2025 17:08:03.255737066 CET135664690083.222.186.121192.168.2.14
        Jan 18, 2025 17:08:03.255748987 CET5680413566192.168.2.1483.222.131.104
        Jan 18, 2025 17:08:03.255767107 CET135664003883.222.216.6192.168.2.14
        Jan 18, 2025 17:08:03.255773067 CET4690013566192.168.2.1483.222.186.121
        Jan 18, 2025 17:08:03.255798101 CET135663654883.222.138.44192.168.2.14
        Jan 18, 2025 17:08:03.255803108 CET4003813566192.168.2.1483.222.216.6
        Jan 18, 2025 17:08:03.255827904 CET135664851883.222.67.120192.168.2.14
        Jan 18, 2025 17:08:03.255836964 CET3654813566192.168.2.1483.222.138.44
        Jan 18, 2025 17:08:03.255857944 CET135663389883.222.100.147192.168.2.14
        Jan 18, 2025 17:08:03.255866051 CET4851813566192.168.2.1483.222.67.120
        Jan 18, 2025 17:08:03.255887032 CET135665664283.222.221.86192.168.2.14
        Jan 18, 2025 17:08:03.255904913 CET3389813566192.168.2.1483.222.100.147
        Jan 18, 2025 17:08:03.255917072 CET135665107683.222.21.142192.168.2.14
        Jan 18, 2025 17:08:03.255920887 CET5664213566192.168.2.1483.222.221.86
        Jan 18, 2025 17:08:03.255954027 CET5107613566192.168.2.1483.222.21.142
        Jan 18, 2025 17:08:03.255970001 CET135665255683.222.77.121192.168.2.14
        Jan 18, 2025 17:08:03.256000042 CET135663398483.222.16.235192.168.2.14
        Jan 18, 2025 17:08:03.256005049 CET5255613566192.168.2.1483.222.77.121
        Jan 18, 2025 17:08:03.256028891 CET135663535083.222.217.218192.168.2.14
        Jan 18, 2025 17:08:03.256031990 CET3398413566192.168.2.1483.222.16.235
        Jan 18, 2025 17:08:03.256058931 CET135666021283.222.207.192192.168.2.14
        Jan 18, 2025 17:08:03.256088018 CET135664126883.222.34.59192.168.2.14
        Jan 18, 2025 17:08:03.256088018 CET3535013566192.168.2.1483.222.217.218
        Jan 18, 2025 17:08:03.256110907 CET6021213566192.168.2.1483.222.207.192
        Jan 18, 2025 17:08:03.256115913 CET135664547683.222.187.125192.168.2.14
        Jan 18, 2025 17:08:03.256131887 CET4126813566192.168.2.1483.222.34.59
        Jan 18, 2025 17:08:03.256145000 CET135665739483.222.226.225192.168.2.14
        Jan 18, 2025 17:08:03.256153107 CET4547613566192.168.2.1483.222.187.125
        Jan 18, 2025 17:08:03.256172895 CET135665159483.222.250.187192.168.2.14
        Jan 18, 2025 17:08:03.256181955 CET5739413566192.168.2.1483.222.226.225
        Jan 18, 2025 17:08:03.256201982 CET135665757683.222.169.102192.168.2.14
        Jan 18, 2025 17:08:03.256211042 CET5159413566192.168.2.1483.222.250.187
        Jan 18, 2025 17:08:03.256231070 CET135664512683.222.177.247192.168.2.14
        Jan 18, 2025 17:08:03.256238937 CET5757613566192.168.2.1483.222.169.102
        Jan 18, 2025 17:08:03.256259918 CET135663901483.222.223.149192.168.2.14
        Jan 18, 2025 17:08:03.256278038 CET4512613566192.168.2.1483.222.177.247
        Jan 18, 2025 17:08:03.256289005 CET135664084683.222.189.100192.168.2.14
        Jan 18, 2025 17:08:03.256294012 CET3901413566192.168.2.1483.222.223.149
        Jan 18, 2025 17:08:03.256318092 CET135663595883.222.106.175192.168.2.14
        Jan 18, 2025 17:08:03.256334066 CET4084613566192.168.2.1483.222.189.100
        Jan 18, 2025 17:08:03.256349087 CET3595813566192.168.2.1483.222.106.175
        Jan 18, 2025 17:08:03.256359100 CET135665361283.222.86.72192.168.2.14
        Jan 18, 2025 17:08:03.256400108 CET5361213566192.168.2.1483.222.86.72
        Jan 18, 2025 17:08:03.256412983 CET135665271883.222.5.107192.168.2.14
        Jan 18, 2025 17:08:03.256444931 CET5271813566192.168.2.1483.222.5.107
        Jan 18, 2025 17:08:03.256449938 CET135664062883.222.214.82192.168.2.14
        Jan 18, 2025 17:08:03.256460905 CET135665438483.222.242.242192.168.2.14
        Jan 18, 2025 17:08:03.256470919 CET135664860083.222.216.209192.168.2.14
        Jan 18, 2025 17:08:03.256479979 CET135663787083.222.35.69192.168.2.14
        Jan 18, 2025 17:08:03.256484985 CET4062813566192.168.2.1483.222.214.82
        Jan 18, 2025 17:08:03.256489038 CET135664959283.222.142.245192.168.2.14
        Jan 18, 2025 17:08:03.256511927 CET5438413566192.168.2.1483.222.242.242
        Jan 18, 2025 17:08:03.256511927 CET4860013566192.168.2.1483.222.216.209
        Jan 18, 2025 17:08:03.256511927 CET3787013566192.168.2.1483.222.35.69
        Jan 18, 2025 17:08:03.256519079 CET135664937883.222.228.248192.168.2.14
        Jan 18, 2025 17:08:03.256532907 CET4959213566192.168.2.1483.222.142.245
        Jan 18, 2025 17:08:03.256547928 CET135664314283.222.228.128192.168.2.14
        Jan 18, 2025 17:08:03.256567955 CET4937813566192.168.2.1483.222.228.248
        Jan 18, 2025 17:08:03.256587029 CET4314213566192.168.2.1483.222.228.128
        Jan 18, 2025 17:08:03.256587982 CET135665499683.222.231.188192.168.2.14
        Jan 18, 2025 17:08:03.256618023 CET135664875083.222.81.201192.168.2.14
        Jan 18, 2025 17:08:03.256628036 CET5499613566192.168.2.1483.222.231.188
        Jan 18, 2025 17:08:03.256645918 CET135664389083.222.157.76192.168.2.14
        Jan 18, 2025 17:08:03.256653070 CET4875013566192.168.2.1483.222.81.201
        Jan 18, 2025 17:08:03.256675005 CET135665086283.222.133.88192.168.2.14
        Jan 18, 2025 17:08:03.256680012 CET4389013566192.168.2.1483.222.157.76
        Jan 18, 2025 17:08:03.256705999 CET135664559283.222.201.168192.168.2.14
        Jan 18, 2025 17:08:03.256711960 CET5086213566192.168.2.1483.222.133.88
        Jan 18, 2025 17:08:03.256716967 CET135663938083.222.158.115192.168.2.14
        Jan 18, 2025 17:08:03.256726980 CET135664708083.222.15.91192.168.2.14
        Jan 18, 2025 17:08:03.256736994 CET4559213566192.168.2.1483.222.201.168
        Jan 18, 2025 17:08:03.256750107 CET3938013566192.168.2.1483.222.158.115
        Jan 18, 2025 17:08:03.256755114 CET135664578083.222.215.238192.168.2.14
        Jan 18, 2025 17:08:03.256767988 CET4708013566192.168.2.1483.222.15.91
        Jan 18, 2025 17:08:03.256784916 CET135665833883.222.241.65192.168.2.14
        Jan 18, 2025 17:08:03.256792068 CET4578013566192.168.2.1483.222.215.238
        Jan 18, 2025 17:08:03.256814003 CET135665049283.222.157.71192.168.2.14
        Jan 18, 2025 17:08:03.256824970 CET5833813566192.168.2.1483.222.241.65
        Jan 18, 2025 17:08:03.256850004 CET5049213566192.168.2.1483.222.157.71
        Jan 18, 2025 17:08:03.256860018 CET135664409883.222.178.96192.168.2.14
        Jan 18, 2025 17:08:03.256894112 CET4409813566192.168.2.1483.222.178.96
        Jan 18, 2025 17:08:03.256922960 CET135663976683.222.137.162192.168.2.14
        Jan 18, 2025 17:08:03.256953955 CET135664630483.222.245.150192.168.2.14
        Jan 18, 2025 17:08:03.256958961 CET3976613566192.168.2.1483.222.137.162
        Jan 18, 2025 17:08:03.256963015 CET135663881083.222.88.131192.168.2.14
        Jan 18, 2025 17:08:03.256984949 CET4630413566192.168.2.1483.222.245.150
        Jan 18, 2025 17:08:03.256993055 CET135665293683.222.3.114192.168.2.14
        Jan 18, 2025 17:08:03.257000923 CET3881013566192.168.2.1483.222.88.131
        Jan 18, 2025 17:08:03.257021904 CET135664483483.222.139.60192.168.2.14
        Jan 18, 2025 17:08:03.257028103 CET5293613566192.168.2.1483.222.3.114
        Jan 18, 2025 17:08:03.257050991 CET135665333283.222.248.85192.168.2.14
        Jan 18, 2025 17:08:03.257070065 CET4483413566192.168.2.1483.222.139.60
        Jan 18, 2025 17:08:03.257088900 CET5333213566192.168.2.1483.222.248.85
        Jan 18, 2025 17:08:03.257092953 CET135664942083.222.105.140192.168.2.14
        Jan 18, 2025 17:08:03.257122040 CET135665066683.222.238.106192.168.2.14
        Jan 18, 2025 17:08:03.257149935 CET135663323883.222.60.149192.168.2.14
        Jan 18, 2025 17:08:03.257150888 CET4942013566192.168.2.1483.222.105.140
        Jan 18, 2025 17:08:03.257159948 CET5066613566192.168.2.1483.222.238.106
        Jan 18, 2025 17:08:03.257179022 CET135664937083.222.161.193192.168.2.14
        Jan 18, 2025 17:08:03.257196903 CET3323813566192.168.2.1483.222.60.149
        Jan 18, 2025 17:08:03.257219076 CET135665983883.222.231.180192.168.2.14
        Jan 18, 2025 17:08:03.257220984 CET4937013566192.168.2.1483.222.161.193
        Jan 18, 2025 17:08:03.257246971 CET135664488483.222.221.120192.168.2.14
        Jan 18, 2025 17:08:03.257261992 CET5983813566192.168.2.1483.222.231.180
        Jan 18, 2025 17:08:03.257275105 CET135665662683.222.103.216192.168.2.14
        Jan 18, 2025 17:08:03.257285118 CET4488413566192.168.2.1483.222.221.120
        Jan 18, 2025 17:08:03.257309914 CET5662613566192.168.2.1483.222.103.216
        Jan 18, 2025 17:08:03.257312059 CET135665703883.222.31.127192.168.2.14
        Jan 18, 2025 17:08:03.257319927 CET135666072883.222.246.4192.168.2.14
        Jan 18, 2025 17:08:03.257348061 CET5703813566192.168.2.1483.222.31.127
        Jan 18, 2025 17:08:03.257354021 CET6072813566192.168.2.1483.222.246.4
        Jan 18, 2025 17:08:03.261723995 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:03.266587973 CET135665649083.222.191.90192.168.2.14
        Jan 18, 2025 17:08:03.266650915 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:03.266710043 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:03.271599054 CET135665649083.222.191.90192.168.2.14
        Jan 18, 2025 17:08:03.271646976 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:03.276509047 CET135665649083.222.191.90192.168.2.14
        Jan 18, 2025 17:08:13.272944927 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:13.277968884 CET135665649083.222.191.90192.168.2.14
        Jan 18, 2025 17:08:13.475294113 CET135665649083.222.191.90192.168.2.14
        Jan 18, 2025 17:08:13.475485086 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:13.842721939 CET135665649083.222.191.90192.168.2.14
        Jan 18, 2025 17:08:13.842946053 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:48.231350899 CET5649013566192.168.2.1483.222.191.90
        Jan 18, 2025 17:08:48.236921072 CET135665649083.222.191.90192.168.2.14
        Jan 18, 2025 17:08:48.237071991 CET5649013566192.168.2.1483.222.191.90
        TimestampSource PortDest PortSource IPDest IP
        Jan 18, 2025 17:08:03.234644890 CET5637853192.168.2.148.8.8.8
        Jan 18, 2025 17:08:03.261552095 CET53563788.8.8.8192.168.2.14
        Jan 18, 2025 17:10:47.297169924 CET5125053192.168.2.141.1.1.1
        Jan 18, 2025 17:10:47.297271967 CET4089953192.168.2.141.1.1.1
        Jan 18, 2025 17:10:47.304843903 CET53408991.1.1.1192.168.2.14
        Jan 18, 2025 17:10:47.304877996 CET53512501.1.1.1192.168.2.14
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 18, 2025 17:08:03.234644890 CET192.168.2.148.8.8.80xb3feStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
        Jan 18, 2025 17:10:47.297169924 CET192.168.2.141.1.1.10x3f68Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
        Jan 18, 2025 17:10:47.297271967 CET192.168.2.141.1.1.10xde48Standard query (0)daisy.ubuntu.com28IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 18, 2025 17:08:03.261552095 CET8.8.8.8192.168.2.140xb3feNo error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false
        Jan 18, 2025 17:10:47.304877996 CET1.1.1.1192.168.2.140x3f68No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
        Jan 18, 2025 17:10:47.304877996 CET1.1.1.1192.168.2.140x3f68No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

        System Behavior

        Start time (UTC):16:08:02
        Start date (UTC):18/01/2025
        Path:/tmp/dbg.x86.elf
        Arguments:/tmp/dbg.x86.elf
        File size:37484 bytes
        MD5 hash:9f2c1c92152f3013559fee6e6ecfb565