Edit tour

Linux Analysis Report
loki.sh4.elf

Overview

General Information

Sample name:loki.sh4.elf
Analysis ID:1594483
MD5:9fdfb43e7c4271d64e9ae6171dc0e9f0
SHA1:3f309312bb8d5d9450abcf81b19b5c2859c703aa
SHA256:adc2214eb373c5df5625687dee512fb2c612fd0facb2abff822f2d0544359493
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594483
Start date and time:2025-01-19 03:01:01 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:loki.sh4.elf
Detection:MAL
Classification:mal48.linELF@0/0@1/0
Command:/tmp/loki.sh4.elf
PID:5433
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • loki.sh4.elf (PID: 5433, Parent: 5356, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/loki.sh4.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T03:01:41.493720+010025000342Misc Attack83.222.191.9013566192.168.2.1342858TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: loki.sh4.elfVirustotal: Detection: 23%Perma Link
Source: loki.sh4.elfReversingLabs: Detection: 23%
Source: global trafficTCP traffic: 192.168.2.13:54812 -> 83.222.101.124:13566
Source: global trafficTCP traffic: 192.168.2.13:34498 -> 83.222.72.227:13566
Source: global trafficTCP traffic: 192.168.2.13:52638 -> 83.222.218.1:13566
Source: global trafficTCP traffic: 192.168.2.13:53288 -> 83.222.89.179:13566
Source: global trafficTCP traffic: 192.168.2.13:43260 -> 83.222.181.221:13566
Source: global trafficTCP traffic: 192.168.2.13:38828 -> 83.222.144.175:13566
Source: global trafficTCP traffic: 192.168.2.13:58394 -> 83.222.79.190:13566
Source: global trafficTCP traffic: 192.168.2.13:34582 -> 83.222.179.8:13566
Source: global trafficTCP traffic: 192.168.2.13:33864 -> 83.222.171.39:13566
Source: global trafficTCP traffic: 192.168.2.13:57494 -> 83.222.218.90:13566
Source: global trafficTCP traffic: 192.168.2.13:33464 -> 83.222.95.85:13566
Source: global trafficTCP traffic: 192.168.2.13:43284 -> 83.222.151.192:13566
Source: global trafficTCP traffic: 192.168.2.13:58664 -> 83.222.10.35:13566
Source: global trafficTCP traffic: 192.168.2.13:53392 -> 83.222.178.168:13566
Source: global trafficTCP traffic: 192.168.2.13:54048 -> 83.222.50.71:13566
Source: global trafficTCP traffic: 192.168.2.13:33340 -> 83.222.165.151:13566
Source: global trafficTCP traffic: 192.168.2.13:49678 -> 83.222.195.237:13566
Source: global trafficTCP traffic: 192.168.2.13:57260 -> 83.222.122.157:13566
Source: global trafficTCP traffic: 192.168.2.13:35698 -> 83.222.238.211:13566
Source: global trafficTCP traffic: 192.168.2.13:53440 -> 83.222.81.164:13566
Source: global trafficTCP traffic: 192.168.2.13:58224 -> 83.222.176.225:13566
Source: global trafficTCP traffic: 192.168.2.13:46412 -> 83.222.83.0:13566
Source: global trafficTCP traffic: 192.168.2.13:54186 -> 83.222.159.6:13566
Source: global trafficTCP traffic: 192.168.2.13:34758 -> 83.222.8.74:13566
Source: global trafficTCP traffic: 192.168.2.13:38952 -> 83.222.45.226:13566
Source: global trafficTCP traffic: 192.168.2.13:58058 -> 83.222.165.140:13566
Source: global trafficTCP traffic: 192.168.2.13:55668 -> 83.222.55.60:13566
Source: global trafficTCP traffic: 192.168.2.13:42664 -> 83.222.77.65:13566
Source: global trafficTCP traffic: 192.168.2.13:42804 -> 83.222.95.255:13566
Source: global trafficTCP traffic: 192.168.2.13:50284 -> 83.222.233.145:13566
Source: global trafficTCP traffic: 192.168.2.13:55490 -> 83.222.70.143:13566
Source: global trafficTCP traffic: 192.168.2.13:42776 -> 83.222.41.9:13566
Source: global trafficTCP traffic: 192.168.2.13:53380 -> 83.222.124.163:13566
Source: global trafficTCP traffic: 192.168.2.13:41148 -> 83.222.166.107:13566
Source: global trafficTCP traffic: 192.168.2.13:44260 -> 83.222.119.247:13566
Source: global trafficTCP traffic: 192.168.2.13:44310 -> 83.222.15.39:13566
Source: global trafficTCP traffic: 192.168.2.13:56370 -> 83.222.217.98:13566
Source: global trafficTCP traffic: 192.168.2.13:47586 -> 83.222.39.120:13566
Source: global trafficTCP traffic: 192.168.2.13:50252 -> 83.222.104.47:13566
Source: global trafficTCP traffic: 192.168.2.13:60856 -> 83.222.195.150:13566
Source: global trafficTCP traffic: 192.168.2.13:56260 -> 83.222.17.104:13566
Source: global trafficTCP traffic: 192.168.2.13:35912 -> 83.222.34.72:13566
Source: global trafficTCP traffic: 192.168.2.13:54564 -> 83.222.164.111:13566
Source: global trafficTCP traffic: 192.168.2.13:36286 -> 83.222.137.3:13566
Source: global trafficTCP traffic: 192.168.2.13:33582 -> 83.222.110.115:13566
Source: global trafficTCP traffic: 192.168.2.13:55742 -> 83.222.149.180:13566
Source: global trafficTCP traffic: 192.168.2.13:52694 -> 83.222.2.190:13566
Source: global trafficTCP traffic: 192.168.2.13:47124 -> 83.222.189.126:13566
Source: global trafficTCP traffic: 192.168.2.13:46586 -> 83.222.97.100:13566
Source: global trafficTCP traffic: 192.168.2.13:55476 -> 83.222.233.216:13566
Source: global trafficTCP traffic: 192.168.2.13:48584 -> 83.222.91.248:13566
Source: global trafficTCP traffic: 192.168.2.13:55842 -> 83.222.0.52:13566
Source: global trafficTCP traffic: 192.168.2.13:54590 -> 83.222.90.39:13566
Source: global trafficTCP traffic: 192.168.2.13:50716 -> 83.222.173.195:13566
Source: global trafficTCP traffic: 192.168.2.13:39556 -> 83.222.87.112:13566
Source: global trafficTCP traffic: 192.168.2.13:60400 -> 83.222.89.104:13566
Source: global trafficTCP traffic: 192.168.2.13:42612 -> 83.222.216.123:13566
Source: global trafficTCP traffic: 192.168.2.13:41888 -> 83.222.177.124:13566
Source: global trafficTCP traffic: 192.168.2.13:43366 -> 83.222.235.58:13566
Source: global trafficTCP traffic: 192.168.2.13:45440 -> 83.222.127.89:13566
Source: global trafficTCP traffic: 192.168.2.13:53656 -> 83.222.173.20:13566
Source: global trafficTCP traffic: 192.168.2.13:43820 -> 83.222.14.175:13566
Source: global trafficTCP traffic: 192.168.2.13:47706 -> 83.222.210.203:13566
Source: global trafficTCP traffic: 192.168.2.13:36106 -> 83.222.46.52:13566
Source: global trafficTCP traffic: 192.168.2.13:34440 -> 83.222.47.23:13566
Source: global trafficTCP traffic: 192.168.2.13:43382 -> 83.222.12.139:13566
Source: global trafficTCP traffic: 192.168.2.13:40600 -> 83.222.16.12:13566
Source: global trafficTCP traffic: 192.168.2.13:47668 -> 83.222.191.106:13566
Source: global trafficTCP traffic: 192.168.2.13:40642 -> 83.222.52.108:13566
Source: global trafficTCP traffic: 192.168.2.13:54094 -> 83.222.45.139:13566
Source: global trafficTCP traffic: 192.168.2.13:35964 -> 83.222.220.134:13566
Source: global trafficTCP traffic: 192.168.2.13:40456 -> 83.222.243.180:13566
Source: global trafficTCP traffic: 192.168.2.13:44666 -> 83.222.2.164:13566
Source: global trafficTCP traffic: 192.168.2.13:40550 -> 83.222.48.237:13566
Source: global trafficTCP traffic: 192.168.2.13:33722 -> 83.222.223.176:13566
Source: global trafficTCP traffic: 192.168.2.13:56750 -> 83.222.70.140:13566
Source: global trafficTCP traffic: 192.168.2.13:41238 -> 83.222.196.84:13566
Source: global trafficTCP traffic: 192.168.2.13:46804 -> 83.222.60.151:13566
Source: global trafficTCP traffic: 192.168.2.13:56420 -> 83.222.32.106:13566
Source: global trafficTCP traffic: 192.168.2.13:42570 -> 83.222.203.79:13566
Source: global trafficTCP traffic: 192.168.2.13:37050 -> 83.222.129.215:13566
Source: global trafficTCP traffic: 192.168.2.13:52536 -> 83.222.218.145:13566
Source: global trafficTCP traffic: 192.168.2.13:41704 -> 83.222.228.154:13566
Source: global trafficTCP traffic: 192.168.2.13:41874 -> 83.222.252.24:13566
Source: global trafficTCP traffic: 192.168.2.13:52782 -> 83.222.6.41:13566
Source: global trafficTCP traffic: 192.168.2.13:44978 -> 83.222.163.227:13566
Source: global trafficTCP traffic: 192.168.2.13:46870 -> 83.222.176.150:13566
Source: global trafficTCP traffic: 192.168.2.13:44720 -> 83.222.151.178:13566
Source: global trafficTCP traffic: 192.168.2.13:38454 -> 83.222.59.200:13566
Source: global trafficTCP traffic: 192.168.2.13:33708 -> 83.222.159.26:13566
Source: global trafficTCP traffic: 192.168.2.13:55390 -> 83.222.120.229:13566
Source: global trafficTCP traffic: 192.168.2.13:39402 -> 83.222.166.60:13566
Source: global trafficTCP traffic: 192.168.2.13:42650 -> 83.222.58.226:13566
Source: global trafficTCP traffic: 192.168.2.13:38054 -> 83.222.211.90:13566
Source: global trafficTCP traffic: 192.168.2.13:55740 -> 83.222.76.158:13566
Source: global trafficTCP traffic: 192.168.2.13:35046 -> 83.222.169.206:13566
Source: global trafficTCP traffic: 192.168.2.13:39352 -> 83.222.118.132:13566
Source: global trafficTCP traffic: 192.168.2.13:45080 -> 83.222.95.90:13566
Source: global trafficTCP traffic: 192.168.2.13:33372 -> 83.222.30.91:13566
Source: global trafficTCP traffic: 192.168.2.13:58110 -> 83.222.114.36:13566
Source: global trafficTCP traffic: 192.168.2.13:42858 -> 83.222.191.90:13566
Source: /tmp/loki.sh4.elf (PID: 5433)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.13:42858
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.101.124
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.101.124
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.72.227
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.72.227
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.218.1
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.89.179
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.181.221
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.144.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.218.1
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.89.179
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.181.221
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.144.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.144.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.79.190
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.144.175
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.79.190
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.179.8
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.39
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.179.8
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.39
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.218.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.218.90
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.95.85
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.151.192
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.95.85
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.151.192
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.178.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.178.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.50.71
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.50.71
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.151
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.151
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.195.237
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.195.237
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.122.157
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.211
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.81.164
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.122.157
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.211
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.176.225
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.81.164
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.83.0
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.159.6
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.176.225
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.83.0
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.159.6
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.159.6
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.8.74
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.159.6
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.8.74
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@1/0
Source: /tmp/loki.sh4.elf (PID: 5433)Queries kernel information via 'uname': Jump to behavior
Source: loki.sh4.elf, 5433.1.00007ffde1de8000.00007ffde1e09000.rw-.sdmp, loki.sh4.elf, 5435.1.00007ffde1de8000.00007ffde1e09000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/loki.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/loki.sh4.elf
Source: loki.sh4.elf, 5433.1.00007ffde1de8000.00007ffde1e09000.rw-.sdmp, loki.sh4.elf, 5435.1.00007ffde1de8000.00007ffde1e09000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: loki.sh4.elf, 5433.1.000055866c3a0000.000055866c429000.rw-.sdmp, loki.sh4.elf, 5435.1.000055866c3a0000.000055866c403000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: loki.sh4.elf, 5433.1.000055866c3a0000.000055866c429000.rw-.sdmp, loki.sh4.elf, 5435.1.000055866c3a0000.000055866c403000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594483 Sample: loki.sh4.elf Startdate: 19/01/2025 Architecture: LINUX Score: 48 13 83.222.163.227, 13566, 44978 WAVENETLB Bulgaria 2->13 15 83.222.164.111, 13566, 54564 WAVENETLB Bulgaria 2->15 17 98 other IPs or domains 2->17 19 Multi AV Scanner detection for submitted file 2->19 7 loki.sh4.elf 2->7         started        signatures3 process4 process5 9 loki.sh4.elf 7->9         started        11 loki.sh4.elf 7->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
loki.sh4.elf24%VirustotalBrowse
loki.sh4.elf24%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.110.115
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.79.190
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.81.164
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.210.203
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.195.150
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.52.108
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.34.72
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.151.192
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.87.112
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.217.98
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.14.175
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.252.24
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.196.84
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.32.106
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.216.123
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.151.178
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.89.104
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.118.132
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.176.225
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.163.227
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.120.229
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.119.247
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.46.52
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.47.23
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.144.175
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.171.39
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.45.139
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.30.91
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.89.179
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.95.85
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.203.79
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.76.158
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.129.215
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.177.124
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.218.145
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.114.36
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.211.90
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.95.90
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.10.35
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.72.227
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.165.140
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.159.26
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.191.106
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.2.190
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.178.168
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.235.58
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.16.12
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.233.145
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.149.180
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.218.1
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.164.111
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.223.176
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.59.200
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.166.107
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.165.151
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.15.39
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.122.157
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.220.134
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.39.120
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.166.60
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.238.211
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.2.164
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.17.104
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.179.8
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.137.3
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.6.41
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.127.89
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.176.150
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.45.226
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.58.226
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.50.71
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.124.163
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.95.255
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.181.221
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.8.74
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.60.151
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.173.20
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.243.180
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.218.90
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.90.39
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.173.195
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.41.9
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.233.216
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.77.65
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.159.6
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.83.0
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    185.125.190.26
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    83.222.169.206
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.48.237
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.70.143
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.104.47
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.97.100
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.55.60
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.101.124
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.91.248
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.70.140
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.195.237
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.189.126
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.12.139
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.79.190loki.sh4.elfGet hashmaliciousUnknownBrowse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      secure-network-rebirthltd.ruloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.191.90
      loki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.71.222
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.121
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.82.115
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.77.162
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.84.27
      Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.84.226
      loki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.82.223
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.89.99
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.78.125
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.88.209
      SYNTERRA-ASRUloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.211.69
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.196.65
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.207.214
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.200.226
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.205.255
      Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.194.159
      loki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.200.182
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.192.170
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.201.96
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.210.254
      MNOGOBYTE-ASMoscowRussiaRUloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.98.5
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.118.190
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.115.165
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.105.229
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.112.215
      Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.110.25
      loki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.101.228
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.107.141
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.109.253
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.112.175
      SYNTERRA-ASRUloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.211.69
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.196.65
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.207.214
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.200.226
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.205.255
      Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.194.159
      loki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.200.182
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.192.170
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.201.96
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.210.254
      ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.71.222
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.121
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.82.115
      Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      • 83.222.77.162
      Kloki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.84.27
      Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.84.226
      loki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.82.223
      Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      • 83.222.89.99
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.78.125
      loki.spc.elfGet hashmaliciousUnknownBrowse
      • 83.222.88.209
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
      Entropy (8bit):6.805730210497
      TrID:
      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
      File name:loki.sh4.elf
      File size:43'416 bytes
      MD5:9fdfb43e7c4271d64e9ae6171dc0e9f0
      SHA1:3f309312bb8d5d9450abcf81b19b5c2859c703aa
      SHA256:adc2214eb373c5df5625687dee512fb2c612fd0facb2abff822f2d0544359493
      SHA512:0763a5554c4d244f94c1289e70c1182f8058cc28011fb09d6e7b5826f5b5e9c04e4d4c6e5394d6f6c1521df3eb45ee80f5ea8833277b5582de37b2d5b4afb0e5
      SSDEEP:768:uaYwt3g/v9Ve4U+8e7ua7LQNQAC7eokg0pHxCJv:uaYwt3yxYaH3hAGhvwxCJv
      TLSH:7E137D7BD87EEF94C15942B8A8708E781B13F444D2532EBF1A9584A79003DACF6093F6
      File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@.x...x...............|...|.A.|.A.L...............Q.td............................././"O.n........#.*@........#.*@L....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:<unknown>
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - System V
      ABI Version:0
      Entry Point Address:0x4001a0
      Flags:0x9
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:43016
      Section Header Size:40
      Number of Section Headers:10
      Header String Table Index:9
      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
      NULL0x00x00x00x00x0000
      .initPROGBITS0x4000940x940x300x00x6AX004
      .textPROGBITS0x4000e00xe00x9f600x00x6AX0032
      .finiPROGBITS0x40a0400xa0400x240x00x6AX004
      .rodataPROGBITS0x40a0640xa0640x5140x00x2A004
      .ctorsPROGBITS0x41a57c0xa57c0x80x00x3WA004
      .dtorsPROGBITS0x41a5840xa5840x80x00x3WA004
      .dataPROGBITS0x41a5900xa5900x2380x00x3WA004
      .bssNOBITS0x41a7c80xa7c80x11640x00x3WA004
      .shstrtabSTRTAB0x00xa7c80x3e0x00x0001
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x4000000x4000000xa5780xa5786.85770x5R E0x10000.init .text .fini .rodata
      LOAD0xa57c0x41a57c0x41a57c0x24c0x13b03.22410x6RW 0x10000.ctors .dtors .data .bss
      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

      Download Network PCAP: filteredfull

      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
      2025-01-19T03:01:41.493720+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1342858TCP
      • Total Packets: 225
      • 13566 undefined
      • 443 (HTTPS)
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 03:01:41.117270947 CET5481213566192.168.2.1383.222.101.124
      Jan 19, 2025 03:01:41.122456074 CET135665481283.222.101.124192.168.2.13
      Jan 19, 2025 03:01:41.122543097 CET5481213566192.168.2.1383.222.101.124
      Jan 19, 2025 03:01:41.137197971 CET3449813566192.168.2.1383.222.72.227
      Jan 19, 2025 03:01:41.142065048 CET135663449883.222.72.227192.168.2.13
      Jan 19, 2025 03:01:41.142117977 CET3449813566192.168.2.1383.222.72.227
      Jan 19, 2025 03:01:41.144087076 CET5263813566192.168.2.1383.222.218.1
      Jan 19, 2025 03:01:41.146570921 CET5328813566192.168.2.1383.222.89.179
      Jan 19, 2025 03:01:41.147850990 CET4326013566192.168.2.1383.222.181.221
      Jan 19, 2025 03:01:41.148777008 CET3882813566192.168.2.1383.222.144.175
      Jan 19, 2025 03:01:41.150120020 CET135665263883.222.218.1192.168.2.13
      Jan 19, 2025 03:01:41.150161982 CET5263813566192.168.2.1383.222.218.1
      Jan 19, 2025 03:01:41.151447058 CET135665328883.222.89.179192.168.2.13
      Jan 19, 2025 03:01:41.151556969 CET5328813566192.168.2.1383.222.89.179
      Jan 19, 2025 03:01:41.153012037 CET135664326083.222.181.221192.168.2.13
      Jan 19, 2025 03:01:41.153060913 CET4326013566192.168.2.1383.222.181.221
      Jan 19, 2025 03:01:41.153601885 CET135663882883.222.144.175192.168.2.13
      Jan 19, 2025 03:01:41.153651953 CET3882813566192.168.2.1383.222.144.175
      Jan 19, 2025 03:01:41.162067890 CET3882813566192.168.2.1383.222.144.175
      Jan 19, 2025 03:01:41.164997101 CET5839413566192.168.2.1383.222.79.190
      Jan 19, 2025 03:01:41.167067051 CET135663882883.222.144.175192.168.2.13
      Jan 19, 2025 03:01:41.167114019 CET3882813566192.168.2.1383.222.144.175
      Jan 19, 2025 03:01:41.169848919 CET135665839483.222.79.190192.168.2.13
      Jan 19, 2025 03:01:41.169900894 CET5839413566192.168.2.1383.222.79.190
      Jan 19, 2025 03:01:41.178097963 CET3458213566192.168.2.1383.222.179.8
      Jan 19, 2025 03:01:41.181454897 CET3386413566192.168.2.1383.222.171.39
      Jan 19, 2025 03:01:41.182979107 CET135663458283.222.179.8192.168.2.13
      Jan 19, 2025 03:01:41.183032036 CET3458213566192.168.2.1383.222.179.8
      Jan 19, 2025 03:01:41.186408997 CET135663386483.222.171.39192.168.2.13
      Jan 19, 2025 03:01:41.186445951 CET3386413566192.168.2.1383.222.171.39
      Jan 19, 2025 03:01:41.186501980 CET5749413566192.168.2.1383.222.218.90
      Jan 19, 2025 03:01:41.191304922 CET135665749483.222.218.90192.168.2.13
      Jan 19, 2025 03:01:41.193125010 CET5749413566192.168.2.1383.222.218.90
      Jan 19, 2025 03:01:41.197515011 CET3346413566192.168.2.1383.222.95.85
      Jan 19, 2025 03:01:41.201299906 CET4328413566192.168.2.1383.222.151.192
      Jan 19, 2025 03:01:41.202409983 CET135663346483.222.95.85192.168.2.13
      Jan 19, 2025 03:01:41.202451944 CET3346413566192.168.2.1383.222.95.85
      Jan 19, 2025 03:01:41.206186056 CET135664328483.222.151.192192.168.2.13
      Jan 19, 2025 03:01:41.206235886 CET4328413566192.168.2.1383.222.151.192
      Jan 19, 2025 03:01:41.207467079 CET5866413566192.168.2.1383.222.10.35
      Jan 19, 2025 03:01:41.212379932 CET135665866483.222.10.35192.168.2.13
      Jan 19, 2025 03:01:41.212424040 CET5866413566192.168.2.1383.222.10.35
      Jan 19, 2025 03:01:41.212708950 CET5339213566192.168.2.1383.222.178.168
      Jan 19, 2025 03:01:41.217489958 CET135665339283.222.178.168192.168.2.13
      Jan 19, 2025 03:01:41.217534065 CET5339213566192.168.2.1383.222.178.168
      Jan 19, 2025 03:01:41.217670918 CET5404813566192.168.2.1383.222.50.71
      Jan 19, 2025 03:01:41.222608089 CET135665404883.222.50.71192.168.2.13
      Jan 19, 2025 03:01:41.222676992 CET5404813566192.168.2.1383.222.50.71
      Jan 19, 2025 03:01:41.223540068 CET3334013566192.168.2.1383.222.165.151
      Jan 19, 2025 03:01:41.228403091 CET135663334083.222.165.151192.168.2.13
      Jan 19, 2025 03:01:41.228441954 CET3334013566192.168.2.1383.222.165.151
      Jan 19, 2025 03:01:41.229279995 CET4967813566192.168.2.1383.222.195.237
      Jan 19, 2025 03:01:41.234160900 CET135664967883.222.195.237192.168.2.13
      Jan 19, 2025 03:01:41.234204054 CET4967813566192.168.2.1383.222.195.237
      Jan 19, 2025 03:01:41.234802961 CET5726013566192.168.2.1383.222.122.157
      Jan 19, 2025 03:01:41.238372087 CET3569813566192.168.2.1383.222.238.211
      Jan 19, 2025 03:01:41.239289045 CET5344013566192.168.2.1383.222.81.164
      Jan 19, 2025 03:01:41.239625931 CET135665726083.222.122.157192.168.2.13
      Jan 19, 2025 03:01:41.239667892 CET5726013566192.168.2.1383.222.122.157
      Jan 19, 2025 03:01:41.243208885 CET135663569883.222.238.211192.168.2.13
      Jan 19, 2025 03:01:41.243262053 CET3569813566192.168.2.1383.222.238.211
      Jan 19, 2025 03:01:41.243437052 CET5822413566192.168.2.1383.222.176.225
      Jan 19, 2025 03:01:41.244194031 CET135665344083.222.81.164192.168.2.13
      Jan 19, 2025 03:01:41.244241953 CET5344013566192.168.2.1383.222.81.164
      Jan 19, 2025 03:01:41.246035099 CET4641213566192.168.2.1383.222.83.0
      Jan 19, 2025 03:01:41.248279095 CET5418613566192.168.2.1383.222.159.6
      Jan 19, 2025 03:01:41.248375893 CET135665822483.222.176.225192.168.2.13
      Jan 19, 2025 03:01:41.248420000 CET5822413566192.168.2.1383.222.176.225
      Jan 19, 2025 03:01:41.250864029 CET135664641283.222.83.0192.168.2.13
      Jan 19, 2025 03:01:41.250900984 CET4641213566192.168.2.1383.222.83.0
      Jan 19, 2025 03:01:41.253091097 CET135665418683.222.159.6192.168.2.13
      Jan 19, 2025 03:01:41.253134966 CET5418613566192.168.2.1383.222.159.6
      Jan 19, 2025 03:01:41.263799906 CET5418613566192.168.2.1383.222.159.6
      Jan 19, 2025 03:01:41.264558077 CET3475813566192.168.2.1383.222.8.74
      Jan 19, 2025 03:01:41.268729925 CET135665418683.222.159.6192.168.2.13
      Jan 19, 2025 03:01:41.268825054 CET5418613566192.168.2.1383.222.159.6
      Jan 19, 2025 03:01:41.269426107 CET135663475883.222.8.74192.168.2.13
      Jan 19, 2025 03:01:41.269479990 CET3475813566192.168.2.1383.222.8.74
      Jan 19, 2025 03:01:41.271914959 CET3475813566192.168.2.1383.222.8.74
      Jan 19, 2025 03:01:41.276783943 CET135663475883.222.8.74192.168.2.13
      Jan 19, 2025 03:01:41.276844025 CET3475813566192.168.2.1383.222.8.74
      Jan 19, 2025 03:01:41.280796051 CET3895213566192.168.2.1383.222.45.226
      Jan 19, 2025 03:01:41.285670996 CET135663895283.222.45.226192.168.2.13
      Jan 19, 2025 03:01:41.285720110 CET3895213566192.168.2.1383.222.45.226
      Jan 19, 2025 03:01:41.293560028 CET5805813566192.168.2.1383.222.165.140
      Jan 19, 2025 03:01:41.298593998 CET135665805883.222.165.140192.168.2.13
      Jan 19, 2025 03:01:41.298645020 CET5805813566192.168.2.1383.222.165.140
      Jan 19, 2025 03:01:41.300209045 CET5566813566192.168.2.1383.222.55.60
      Jan 19, 2025 03:01:41.303603888 CET4266413566192.168.2.1383.222.77.65
      Jan 19, 2025 03:01:41.305275917 CET135665566883.222.55.60192.168.2.13
      Jan 19, 2025 03:01:41.305327892 CET5566813566192.168.2.1383.222.55.60
      Jan 19, 2025 03:01:41.306039095 CET4280413566192.168.2.1383.222.95.255
      Jan 19, 2025 03:01:41.308137894 CET5028413566192.168.2.1383.222.233.145
      Jan 19, 2025 03:01:41.308523893 CET135664266483.222.77.65192.168.2.13
      Jan 19, 2025 03:01:41.308573008 CET4266413566192.168.2.1383.222.77.65
      Jan 19, 2025 03:01:41.309089899 CET5549013566192.168.2.1383.222.70.143
      Jan 19, 2025 03:01:41.311021090 CET135664280483.222.95.255192.168.2.13
      Jan 19, 2025 03:01:41.311072111 CET4280413566192.168.2.1383.222.95.255
      Jan 19, 2025 03:01:41.313033104 CET135665028483.222.233.145192.168.2.13
      Jan 19, 2025 03:01:41.313105106 CET5028413566192.168.2.1383.222.233.145
      Jan 19, 2025 03:01:41.313982010 CET135665549083.222.70.143192.168.2.13
      Jan 19, 2025 03:01:41.314034939 CET5549013566192.168.2.1383.222.70.143
      Jan 19, 2025 03:01:41.316823006 CET4277613566192.168.2.1383.222.41.9
      Jan 19, 2025 03:01:41.321682930 CET135664277683.222.41.9192.168.2.13
      Jan 19, 2025 03:01:41.321795940 CET4277613566192.168.2.1383.222.41.9
      Jan 19, 2025 03:01:41.324099064 CET4277613566192.168.2.1383.222.41.9
      Jan 19, 2025 03:01:41.324991941 CET5338013566192.168.2.1383.222.124.163
      Jan 19, 2025 03:01:41.328979969 CET135664277683.222.41.9192.168.2.13
      Jan 19, 2025 03:01:41.329025984 CET4277613566192.168.2.1383.222.41.9
      Jan 19, 2025 03:01:41.329916954 CET135665338083.222.124.163192.168.2.13
      Jan 19, 2025 03:01:41.329973936 CET5338013566192.168.2.1383.222.124.163
      Jan 19, 2025 03:01:41.331621885 CET5338013566192.168.2.1383.222.124.163
      Jan 19, 2025 03:01:41.333488941 CET4114813566192.168.2.1383.222.166.107
      Jan 19, 2025 03:01:41.334682941 CET4426013566192.168.2.1383.222.119.247
      Jan 19, 2025 03:01:41.336500883 CET135665338083.222.124.163192.168.2.13
      Jan 19, 2025 03:01:41.336546898 CET5338013566192.168.2.1383.222.124.163
      Jan 19, 2025 03:01:41.338310003 CET135664114883.222.166.107192.168.2.13
      Jan 19, 2025 03:01:41.338395119 CET4114813566192.168.2.1383.222.166.107
      Jan 19, 2025 03:01:41.339538097 CET135664426083.222.119.247192.168.2.13
      Jan 19, 2025 03:01:41.339581013 CET4426013566192.168.2.1383.222.119.247
      Jan 19, 2025 03:01:41.345319033 CET4426013566192.168.2.1383.222.119.247
      Jan 19, 2025 03:01:41.350161076 CET135664426083.222.119.247192.168.2.13
      Jan 19, 2025 03:01:41.350229979 CET4426013566192.168.2.1383.222.119.247
      Jan 19, 2025 03:01:41.351831913 CET4431013566192.168.2.1383.222.15.39
      Jan 19, 2025 03:01:41.354448080 CET5637013566192.168.2.1383.222.217.98
      Jan 19, 2025 03:01:41.356676102 CET135664431083.222.15.39192.168.2.13
      Jan 19, 2025 03:01:41.356719017 CET4431013566192.168.2.1383.222.15.39
      Jan 19, 2025 03:01:41.356864929 CET4758613566192.168.2.1383.222.39.120
      Jan 19, 2025 03:01:41.358856916 CET5025213566192.168.2.1383.222.104.47
      Jan 19, 2025 03:01:41.359251022 CET135665637083.222.217.98192.168.2.13
      Jan 19, 2025 03:01:41.359287977 CET5637013566192.168.2.1383.222.217.98
      Jan 19, 2025 03:01:41.361445904 CET6085613566192.168.2.1383.222.195.150
      Jan 19, 2025 03:01:41.361732006 CET135664758683.222.39.120192.168.2.13
      Jan 19, 2025 03:01:41.361779928 CET4758613566192.168.2.1383.222.39.120
      Jan 19, 2025 03:01:41.363734961 CET135665025283.222.104.47192.168.2.13
      Jan 19, 2025 03:01:41.363785028 CET5025213566192.168.2.1383.222.104.47
      Jan 19, 2025 03:01:41.363972902 CET5626013566192.168.2.1383.222.17.104
      Jan 19, 2025 03:01:41.366257906 CET135666085683.222.195.150192.168.2.13
      Jan 19, 2025 03:01:41.366311073 CET6085613566192.168.2.1383.222.195.150
      Jan 19, 2025 03:01:41.366837025 CET3591213566192.168.2.1383.222.34.72
      Jan 19, 2025 03:01:41.368839025 CET135665626083.222.17.104192.168.2.13
      Jan 19, 2025 03:01:41.368882895 CET5626013566192.168.2.1383.222.17.104
      Jan 19, 2025 03:01:41.369319916 CET5456413566192.168.2.1383.222.164.111
      Jan 19, 2025 03:01:41.371690989 CET135663591283.222.34.72192.168.2.13
      Jan 19, 2025 03:01:41.371733904 CET3591213566192.168.2.1383.222.34.72
      Jan 19, 2025 03:01:41.372253895 CET3628613566192.168.2.1383.222.137.3
      Jan 19, 2025 03:01:41.374176979 CET135665456483.222.164.111192.168.2.13
      Jan 19, 2025 03:01:41.374212980 CET3358213566192.168.2.1383.222.110.115
      Jan 19, 2025 03:01:41.374226093 CET5456413566192.168.2.1383.222.164.111
      Jan 19, 2025 03:01:41.377141953 CET135663628683.222.137.3192.168.2.13
      Jan 19, 2025 03:01:41.377142906 CET5574213566192.168.2.1383.222.149.180
      Jan 19, 2025 03:01:41.377237082 CET3628613566192.168.2.1383.222.137.3
      Jan 19, 2025 03:01:41.379178047 CET135663358283.222.110.115192.168.2.13
      Jan 19, 2025 03:01:41.379251003 CET3358213566192.168.2.1383.222.110.115
      Jan 19, 2025 03:01:41.380166054 CET5269413566192.168.2.1383.222.2.190
      Jan 19, 2025 03:01:41.382009983 CET135665574283.222.149.180192.168.2.13
      Jan 19, 2025 03:01:41.382054090 CET5574213566192.168.2.1383.222.149.180
      Jan 19, 2025 03:01:41.382369041 CET4712413566192.168.2.1383.222.189.126
      Jan 19, 2025 03:01:41.384710073 CET4658613566192.168.2.1383.222.97.100
      Jan 19, 2025 03:01:41.385092974 CET135665269483.222.2.190192.168.2.13
      Jan 19, 2025 03:01:41.385147095 CET5269413566192.168.2.1383.222.2.190
      Jan 19, 2025 03:01:41.386501074 CET5547613566192.168.2.1383.222.233.216
      Jan 19, 2025 03:01:41.387172937 CET135664712483.222.189.126192.168.2.13
      Jan 19, 2025 03:01:41.387213945 CET4712413566192.168.2.1383.222.189.126
      Jan 19, 2025 03:01:41.388761997 CET4858413566192.168.2.1383.222.91.248
      Jan 19, 2025 03:01:41.389627934 CET135664658683.222.97.100192.168.2.13
      Jan 19, 2025 03:01:41.389672041 CET4658613566192.168.2.1383.222.97.100
      Jan 19, 2025 03:01:41.390791893 CET5584213566192.168.2.1383.222.0.52
      Jan 19, 2025 03:01:41.391370058 CET135665547683.222.233.216192.168.2.13
      Jan 19, 2025 03:01:41.391413927 CET5547613566192.168.2.1383.222.233.216
      Jan 19, 2025 03:01:41.393404961 CET5459013566192.168.2.1383.222.90.39
      Jan 19, 2025 03:01:41.393615007 CET135664858483.222.91.248192.168.2.13
      Jan 19, 2025 03:01:41.393661022 CET4858413566192.168.2.1383.222.91.248
      Jan 19, 2025 03:01:41.395567894 CET135665584283.222.0.52192.168.2.13
      Jan 19, 2025 03:01:41.395612955 CET5584213566192.168.2.1383.222.0.52
      Jan 19, 2025 03:01:41.396321058 CET5071613566192.168.2.1383.222.173.195
      Jan 19, 2025 03:01:41.398222923 CET135665459083.222.90.39192.168.2.13
      Jan 19, 2025 03:01:41.398272038 CET5459013566192.168.2.1383.222.90.39
      Jan 19, 2025 03:01:41.400361061 CET3955613566192.168.2.1383.222.87.112
      Jan 19, 2025 03:01:41.401166916 CET135665071683.222.173.195192.168.2.13
      Jan 19, 2025 03:01:41.401213884 CET5071613566192.168.2.1383.222.173.195
      Jan 19, 2025 03:01:41.404619932 CET6040013566192.168.2.1383.222.89.104
      Jan 19, 2025 03:01:41.405224085 CET135663955683.222.87.112192.168.2.13
      Jan 19, 2025 03:01:41.405286074 CET3955613566192.168.2.1383.222.87.112
      Jan 19, 2025 03:01:41.408468008 CET4261213566192.168.2.1383.222.216.123
      Jan 19, 2025 03:01:41.409512043 CET135666040083.222.89.104192.168.2.13
      Jan 19, 2025 03:01:41.409558058 CET6040013566192.168.2.1383.222.89.104
      Jan 19, 2025 03:01:41.411482096 CET4188813566192.168.2.1383.222.177.124
      Jan 19, 2025 03:01:41.413192034 CET4336613566192.168.2.1383.222.235.58
      Jan 19, 2025 03:01:41.413305044 CET135664261283.222.216.123192.168.2.13
      Jan 19, 2025 03:01:41.413341999 CET4261213566192.168.2.1383.222.216.123
      Jan 19, 2025 03:01:41.414064884 CET4544013566192.168.2.1383.222.127.89
      Jan 19, 2025 03:01:41.415071011 CET5365613566192.168.2.1383.222.173.20
      Jan 19, 2025 03:01:41.416089058 CET4382013566192.168.2.1383.222.14.175
      Jan 19, 2025 03:01:41.416450977 CET135664188883.222.177.124192.168.2.13
      Jan 19, 2025 03:01:41.416655064 CET4188813566192.168.2.1383.222.177.124
      Jan 19, 2025 03:01:41.417105913 CET4770613566192.168.2.1383.222.210.203
      Jan 19, 2025 03:01:41.417937994 CET3610613566192.168.2.1383.222.46.52
      Jan 19, 2025 03:01:41.418104887 CET135664336683.222.235.58192.168.2.13
      Jan 19, 2025 03:01:41.418158054 CET4336613566192.168.2.1383.222.235.58
      Jan 19, 2025 03:01:41.418931007 CET3444013566192.168.2.1383.222.47.23
      Jan 19, 2025 03:01:41.419083118 CET135664544083.222.127.89192.168.2.13
      Jan 19, 2025 03:01:41.419133902 CET4544013566192.168.2.1383.222.127.89
      Jan 19, 2025 03:01:41.419765949 CET4338213566192.168.2.1383.222.12.139
      Jan 19, 2025 03:01:41.419946909 CET135665365683.222.173.20192.168.2.13
      Jan 19, 2025 03:01:41.419990063 CET5365613566192.168.2.1383.222.173.20
      Jan 19, 2025 03:01:41.420746088 CET4060013566192.168.2.1383.222.16.12
      Jan 19, 2025 03:01:41.420985937 CET135664382083.222.14.175192.168.2.13
      Jan 19, 2025 03:01:41.421037912 CET4382013566192.168.2.1383.222.14.175
      Jan 19, 2025 03:01:41.421675920 CET4766813566192.168.2.1383.222.191.106
      Jan 19, 2025 03:01:41.421951056 CET135664770683.222.210.203192.168.2.13
      Jan 19, 2025 03:01:41.421993971 CET4770613566192.168.2.1383.222.210.203
      Jan 19, 2025 03:01:41.422805071 CET135663610683.222.46.52192.168.2.13
      Jan 19, 2025 03:01:41.422847033 CET3610613566192.168.2.1383.222.46.52
      Jan 19, 2025 03:01:41.422955036 CET4064213566192.168.2.1383.222.52.108
      Jan 19, 2025 03:01:41.423948050 CET135663444083.222.47.23192.168.2.13
      Jan 19, 2025 03:01:41.423978090 CET5409413566192.168.2.1383.222.45.139
      Jan 19, 2025 03:01:41.423983097 CET3444013566192.168.2.1383.222.47.23
      Jan 19, 2025 03:01:41.424846888 CET135664338283.222.12.139192.168.2.13
      Jan 19, 2025 03:01:41.424940109 CET4338213566192.168.2.1383.222.12.139
      Jan 19, 2025 03:01:41.425422907 CET3596413566192.168.2.1383.222.220.134
      Jan 19, 2025 03:01:41.425838947 CET135664060083.222.16.12192.168.2.13
      Jan 19, 2025 03:01:41.425878048 CET4060013566192.168.2.1383.222.16.12
      Jan 19, 2025 03:01:41.426649094 CET135664766883.222.191.106192.168.2.13
      Jan 19, 2025 03:01:41.426692963 CET4766813566192.168.2.1383.222.191.106
      Jan 19, 2025 03:01:41.426810026 CET4045613566192.168.2.1383.222.243.180
      Jan 19, 2025 03:01:41.427761078 CET135664064283.222.52.108192.168.2.13
      Jan 19, 2025 03:01:41.427810907 CET4064213566192.168.2.1383.222.52.108
      Jan 19, 2025 03:01:41.428406954 CET4466613566192.168.2.1383.222.2.164
      Jan 19, 2025 03:01:41.428879023 CET135665409483.222.45.139192.168.2.13
      Jan 19, 2025 03:01:41.428982973 CET5409413566192.168.2.1383.222.45.139
      Jan 19, 2025 03:01:41.429630041 CET4055013566192.168.2.1383.222.48.237
      Jan 19, 2025 03:01:41.430202961 CET135663596483.222.220.134192.168.2.13
      Jan 19, 2025 03:01:41.430248976 CET3596413566192.168.2.1383.222.220.134
      Jan 19, 2025 03:01:41.431600094 CET3372213566192.168.2.1383.222.223.176
      Jan 19, 2025 03:01:41.431624889 CET135664045683.222.243.180192.168.2.13
      Jan 19, 2025 03:01:41.431678057 CET4045613566192.168.2.1383.222.243.180
      Jan 19, 2025 03:01:41.433262110 CET135664466683.222.2.164192.168.2.13
      Jan 19, 2025 03:01:41.433393955 CET4466613566192.168.2.1383.222.2.164
      Jan 19, 2025 03:01:41.433520079 CET5675013566192.168.2.1383.222.70.140
      Jan 19, 2025 03:01:41.434494019 CET135664055083.222.48.237192.168.2.13
      Jan 19, 2025 03:01:41.434784889 CET4055013566192.168.2.1383.222.48.237
      Jan 19, 2025 03:01:41.435578108 CET4123813566192.168.2.1383.222.196.84
      Jan 19, 2025 03:01:41.436460018 CET135663372283.222.223.176192.168.2.13
      Jan 19, 2025 03:01:41.436537981 CET3372213566192.168.2.1383.222.223.176
      Jan 19, 2025 03:01:41.437274933 CET4680413566192.168.2.1383.222.60.151
      Jan 19, 2025 03:01:41.438360929 CET135665675083.222.70.140192.168.2.13
      Jan 19, 2025 03:01:41.438415051 CET5675013566192.168.2.1383.222.70.140
      Jan 19, 2025 03:01:41.438716888 CET5642013566192.168.2.1383.222.32.106
      Jan 19, 2025 03:01:41.440241098 CET4257013566192.168.2.1383.222.203.79
      Jan 19, 2025 03:01:41.440428972 CET135664123883.222.196.84192.168.2.13
      Jan 19, 2025 03:01:41.440485001 CET4123813566192.168.2.1383.222.196.84
      Jan 19, 2025 03:01:41.442148924 CET135664680483.222.60.151192.168.2.13
      Jan 19, 2025 03:01:41.442198992 CET4680413566192.168.2.1383.222.60.151
      Jan 19, 2025 03:01:41.442389011 CET3705013566192.168.2.1383.222.129.215
      Jan 19, 2025 03:01:41.443563938 CET135665642083.222.32.106192.168.2.13
      Jan 19, 2025 03:01:41.443682909 CET5642013566192.168.2.1383.222.32.106
      Jan 19, 2025 03:01:41.444569111 CET5253613566192.168.2.1383.222.218.145
      Jan 19, 2025 03:01:41.445039034 CET135664257083.222.203.79192.168.2.13
      Jan 19, 2025 03:01:41.445099115 CET4257013566192.168.2.1383.222.203.79
      Jan 19, 2025 03:01:41.446564913 CET4170413566192.168.2.1383.222.228.154
      Jan 19, 2025 03:01:41.447218895 CET135663705083.222.129.215192.168.2.13
      Jan 19, 2025 03:01:41.447257042 CET3705013566192.168.2.1383.222.129.215
      Jan 19, 2025 03:01:41.448225975 CET4187413566192.168.2.1383.222.252.24
      Jan 19, 2025 03:01:41.449338913 CET135665253683.222.218.145192.168.2.13
      Jan 19, 2025 03:01:41.449377060 CET5253613566192.168.2.1383.222.218.145
      Jan 19, 2025 03:01:41.449886084 CET5278213566192.168.2.1383.222.6.41
      Jan 19, 2025 03:01:41.451445103 CET135664170483.222.228.154192.168.2.13
      Jan 19, 2025 03:01:41.451488972 CET4170413566192.168.2.1383.222.228.154
      Jan 19, 2025 03:01:41.451833963 CET4497813566192.168.2.1383.222.163.227
      Jan 19, 2025 03:01:41.453119993 CET135664187483.222.252.24192.168.2.13
      Jan 19, 2025 03:01:41.453167915 CET4187413566192.168.2.1383.222.252.24
      Jan 19, 2025 03:01:41.453237057 CET4687013566192.168.2.1383.222.176.150
      Jan 19, 2025 03:01:41.454618931 CET4472013566192.168.2.1383.222.151.178
      Jan 19, 2025 03:01:41.454699993 CET135665278283.222.6.41192.168.2.13
      Jan 19, 2025 03:01:41.454749107 CET5278213566192.168.2.1383.222.6.41
      Jan 19, 2025 03:01:41.456159115 CET3845413566192.168.2.1383.222.59.200
      Jan 19, 2025 03:01:41.456873894 CET135664497883.222.163.227192.168.2.13
      Jan 19, 2025 03:01:41.456917048 CET4497813566192.168.2.1383.222.163.227
      Jan 19, 2025 03:01:41.457557917 CET3370813566192.168.2.1383.222.159.26
      Jan 19, 2025 03:01:41.458417892 CET135664687083.222.176.150192.168.2.13
      Jan 19, 2025 03:01:41.458465099 CET4687013566192.168.2.1383.222.176.150
      Jan 19, 2025 03:01:41.458848000 CET5539013566192.168.2.1383.222.120.229
      Jan 19, 2025 03:01:41.460035086 CET135664472083.222.151.178192.168.2.13
      Jan 19, 2025 03:01:41.460073948 CET4472013566192.168.2.1383.222.151.178
      Jan 19, 2025 03:01:41.460562944 CET3940213566192.168.2.1383.222.166.60
      Jan 19, 2025 03:01:41.461139917 CET135663845483.222.59.200192.168.2.13
      Jan 19, 2025 03:01:41.461188078 CET3845413566192.168.2.1383.222.59.200
      Jan 19, 2025 03:01:41.461946964 CET4265013566192.168.2.1383.222.58.226
      Jan 19, 2025 03:01:41.462698936 CET135663370883.222.159.26192.168.2.13
      Jan 19, 2025 03:01:41.462747097 CET3370813566192.168.2.1383.222.159.26
      Jan 19, 2025 03:01:41.463929892 CET135665539083.222.120.229192.168.2.13
      Jan 19, 2025 03:01:41.463980913 CET5539013566192.168.2.1383.222.120.229
      Jan 19, 2025 03:01:41.465655088 CET135663940283.222.166.60192.168.2.13
      Jan 19, 2025 03:01:41.465694904 CET3940213566192.168.2.1383.222.166.60
      Jan 19, 2025 03:01:41.467210054 CET135664265083.222.58.226192.168.2.13
      Jan 19, 2025 03:01:41.467293978 CET4265013566192.168.2.1383.222.58.226
      Jan 19, 2025 03:01:41.467497110 CET3805413566192.168.2.1383.222.211.90
      Jan 19, 2025 03:01:41.468750954 CET5574013566192.168.2.1383.222.76.158
      Jan 19, 2025 03:01:41.469907045 CET3504613566192.168.2.1383.222.169.206
      Jan 19, 2025 03:01:41.471755981 CET3935213566192.168.2.1383.222.118.132
      Jan 19, 2025 03:01:41.472881079 CET135663805483.222.211.90192.168.2.13
      Jan 19, 2025 03:01:41.472925901 CET3805413566192.168.2.1383.222.211.90
      Jan 19, 2025 03:01:41.473331928 CET4508013566192.168.2.1383.222.95.90
      Jan 19, 2025 03:01:41.474039078 CET135665574083.222.76.158192.168.2.13
      Jan 19, 2025 03:01:41.474081039 CET5574013566192.168.2.1383.222.76.158
      Jan 19, 2025 03:01:41.475197077 CET135663504683.222.169.206192.168.2.13
      Jan 19, 2025 03:01:41.475239992 CET3504613566192.168.2.1383.222.169.206
      Jan 19, 2025 03:01:41.475281000 CET3337213566192.168.2.1383.222.30.91
      Jan 19, 2025 03:01:41.476758003 CET135663935283.222.118.132192.168.2.13
      Jan 19, 2025 03:01:41.476810932 CET3935213566192.168.2.1383.222.118.132
      Jan 19, 2025 03:01:41.477149963 CET5811013566192.168.2.1383.222.114.36
      Jan 19, 2025 03:01:41.478458881 CET135664508083.222.95.90192.168.2.13
      Jan 19, 2025 03:01:41.478928089 CET4508013566192.168.2.1383.222.95.90
      Jan 19, 2025 03:01:41.480338097 CET135663337283.222.30.91192.168.2.13
      Jan 19, 2025 03:01:41.480395079 CET3337213566192.168.2.1383.222.30.91
      Jan 19, 2025 03:01:41.482215881 CET135665811083.222.114.36192.168.2.13
      Jan 19, 2025 03:01:41.482264042 CET5811013566192.168.2.1383.222.114.36
      Jan 19, 2025 03:01:41.488782883 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:01:41.493720055 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:01:41.493915081 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:01:41.495269060 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:01:41.500078917 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:01:41.500137091 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:01:41.504930973 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:01:51.257222891 CET48202443192.168.2.13185.125.190.26
      Jan 19, 2025 03:01:51.500493050 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:01:51.505409956 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:01:51.707825899 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:01:51.708025932 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:01:52.431551933 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:01:52.431823969 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:02:22.745238066 CET48202443192.168.2.13185.125.190.26
      Jan 19, 2025 03:02:52.490492105 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:02:52.498178959 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:02:52.703161001 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:02:52.703371048 CET4285813566192.168.2.1383.222.191.90
      Jan 19, 2025 03:02:53.085557938 CET135664285883.222.191.90192.168.2.13
      Jan 19, 2025 03:02:53.085843086 CET4285813566192.168.2.1383.222.191.90
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 03:01:41.480676889 CET4685353192.168.2.138.8.8.8
      Jan 19, 2025 03:01:41.487687111 CET53468538.8.8.8192.168.2.13
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 19, 2025 03:01:41.480676889 CET192.168.2.138.8.8.80xfd72Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 19, 2025 03:01:41.487687111 CET8.8.8.8192.168.2.130xfd72No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

      System Behavior

      Start time (UTC):02:01:39
      Start date (UTC):19/01/2025
      Path:/tmp/loki.sh4.elf
      Arguments:/tmp/loki.sh4.elf
      File size:4139976 bytes
      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

      Start time (UTC):02:01:40
      Start date (UTC):19/01/2025
      Path:/tmp/loki.sh4.elf
      Arguments:-
      File size:4139976 bytes
      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

      Start time (UTC):02:01:40
      Start date (UTC):19/01/2025
      Path:/tmp/loki.sh4.elf
      Arguments:-
      File size:4139976 bytes
      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9