Edit tour

Linux Analysis Report
Kloki.mips.elf

Overview

General Information

Sample name:Kloki.mips.elf
Analysis ID:1594497
MD5:28e2ed00876520c9d7702cdb33281937
SHA1:22c2d7c21f246b4a1021314a31c443763b2487b5
SHA256:358fe1f21475d8c341f57165fe6d95f10d54128765a3b9a6c6fd67889c6585ce
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594497
Start date and time:2025-01-19 03:27:04 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.mips.elf
Detection:MAL
Classification:mal52.spre.linELF@0/0@1/0
Command:/tmp/Kloki.mips.elf
PID:6263
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 6288, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • gsd-sharing (PID: 6288, Parent: 1477, MD5: e29d9025d98590fbb69f89fdbd4438b3) Arguments: /usr/libexec/gsd-sharing
  • sh (PID: 6291, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 6291, Parent: 1477, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 6292, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • sh (PID: 6293, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gdm3 New Fork (PID: 6296, Parent: 1320)
  • Default (PID: 6296, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 6300, Parent: 1320)
  • Default (PID: 6300, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T03:27:55.358286+010025000342Misc Attack83.222.191.9013566192.168.2.2342704TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.mips.elfAvira: detected
Source: Kloki.mips.elfString: ppid/proc/net/tcp/proc/self/exe/proc//status/fd//dev/null/dev/consolesocket05/proc/%d/exepkillkillkillallechowgetcurlpsbusyboxiptablesrebootshutdownhaltpoweroffinitsystemctltelinitcatgrepshashbashzshcshkshdashfish
Source: global trafficTCP traffic: 192.168.2.23:38010 -> 83.222.73.156:13566
Source: global trafficTCP traffic: 192.168.2.23:35448 -> 83.222.29.148:13566
Source: global trafficTCP traffic: 192.168.2.23:43048 -> 83.222.232.116:13566
Source: global trafficTCP traffic: 192.168.2.23:59724 -> 83.222.227.66:13566
Source: global trafficTCP traffic: 192.168.2.23:58464 -> 83.222.231.200:13566
Source: global trafficTCP traffic: 192.168.2.23:51842 -> 83.222.213.18:13566
Source: global trafficTCP traffic: 192.168.2.23:55128 -> 83.222.149.108:13566
Source: global trafficTCP traffic: 192.168.2.23:51722 -> 83.222.23.247:13566
Source: global trafficTCP traffic: 192.168.2.23:56410 -> 83.222.125.239:13566
Source: global trafficTCP traffic: 192.168.2.23:43358 -> 83.222.227.120:13566
Source: global trafficTCP traffic: 192.168.2.23:47306 -> 83.222.85.122:13566
Source: global trafficTCP traffic: 192.168.2.23:40874 -> 83.222.238.39:13566
Source: global trafficTCP traffic: 192.168.2.23:45044 -> 83.222.97.82:13566
Source: global trafficTCP traffic: 192.168.2.23:55692 -> 83.222.67.148:13566
Source: global trafficTCP traffic: 192.168.2.23:39430 -> 83.222.33.17:13566
Source: global trafficTCP traffic: 192.168.2.23:36654 -> 83.222.187.106:13566
Source: global trafficTCP traffic: 192.168.2.23:44728 -> 83.222.174.216:13566
Source: global trafficTCP traffic: 192.168.2.23:33390 -> 83.222.254.150:13566
Source: global trafficTCP traffic: 192.168.2.23:44082 -> 83.222.77.226:13566
Source: global trafficTCP traffic: 192.168.2.23:52670 -> 83.222.216.52:13566
Source: global trafficTCP traffic: 192.168.2.23:35988 -> 83.222.170.174:13566
Source: global trafficTCP traffic: 192.168.2.23:39292 -> 83.222.70.63:13566
Source: global trafficTCP traffic: 192.168.2.23:35394 -> 83.222.26.93:13566
Source: global trafficTCP traffic: 192.168.2.23:44962 -> 83.222.54.151:13566
Source: global trafficTCP traffic: 192.168.2.23:38068 -> 83.222.77.26:13566
Source: global trafficTCP traffic: 192.168.2.23:41272 -> 83.222.15.162:13566
Source: global trafficTCP traffic: 192.168.2.23:44216 -> 83.222.148.253:13566
Source: global trafficTCP traffic: 192.168.2.23:43272 -> 83.222.202.245:13566
Source: global trafficTCP traffic: 192.168.2.23:52052 -> 83.222.80.13:13566
Source: global trafficTCP traffic: 192.168.2.23:56430 -> 83.222.137.113:13566
Source: global trafficTCP traffic: 192.168.2.23:48916 -> 83.222.31.69:13566
Source: global trafficTCP traffic: 192.168.2.23:45534 -> 83.222.220.205:13566
Source: global trafficTCP traffic: 192.168.2.23:38438 -> 83.222.29.218:13566
Source: global trafficTCP traffic: 192.168.2.23:37204 -> 83.222.99.106:13566
Source: global trafficTCP traffic: 192.168.2.23:36036 -> 83.222.188.59:13566
Source: global trafficTCP traffic: 192.168.2.23:52846 -> 83.222.159.102:13566
Source: global trafficTCP traffic: 192.168.2.23:38096 -> 83.222.233.229:13566
Source: global trafficTCP traffic: 192.168.2.23:36394 -> 83.222.166.4:13566
Source: global trafficTCP traffic: 192.168.2.23:54314 -> 83.222.67.220:13566
Source: global trafficTCP traffic: 192.168.2.23:56780 -> 83.222.155.144:13566
Source: global trafficTCP traffic: 192.168.2.23:52488 -> 83.222.246.171:13566
Source: global trafficTCP traffic: 192.168.2.23:49912 -> 83.222.50.139:13566
Source: global trafficTCP traffic: 192.168.2.23:54740 -> 83.222.168.252:13566
Source: global trafficTCP traffic: 192.168.2.23:35036 -> 83.222.128.248:13566
Source: global trafficTCP traffic: 192.168.2.23:60936 -> 83.222.10.10:13566
Source: global trafficTCP traffic: 192.168.2.23:46146 -> 83.222.106.41:13566
Source: global trafficTCP traffic: 192.168.2.23:39108 -> 83.222.79.70:13566
Source: global trafficTCP traffic: 192.168.2.23:59812 -> 83.222.246.108:13566
Source: global trafficTCP traffic: 192.168.2.23:53456 -> 83.222.32.89:13566
Source: global trafficTCP traffic: 192.168.2.23:52708 -> 83.222.215.221:13566
Source: global trafficTCP traffic: 192.168.2.23:45660 -> 83.222.148.118:13566
Source: global trafficTCP traffic: 192.168.2.23:43522 -> 83.222.67.126:13566
Source: global trafficTCP traffic: 192.168.2.23:50950 -> 83.222.91.233:13566
Source: global trafficTCP traffic: 192.168.2.23:47456 -> 83.222.130.158:13566
Source: global trafficTCP traffic: 192.168.2.23:46172 -> 83.222.198.29:13566
Source: global trafficTCP traffic: 192.168.2.23:54904 -> 83.222.46.188:13566
Source: global trafficTCP traffic: 192.168.2.23:39716 -> 83.222.200.97:13566
Source: global trafficTCP traffic: 192.168.2.23:34138 -> 83.222.71.113:13566
Source: global trafficTCP traffic: 192.168.2.23:40854 -> 83.222.93.200:13566
Source: global trafficTCP traffic: 192.168.2.23:43522 -> 83.222.105.103:13566
Source: global trafficTCP traffic: 192.168.2.23:33120 -> 83.222.210.211:13566
Source: global trafficTCP traffic: 192.168.2.23:58736 -> 83.222.144.33:13566
Source: global trafficTCP traffic: 192.168.2.23:52696 -> 83.222.25.134:13566
Source: global trafficTCP traffic: 192.168.2.23:41286 -> 83.222.141.58:13566
Source: global trafficTCP traffic: 192.168.2.23:45866 -> 83.222.223.100:13566
Source: global trafficTCP traffic: 192.168.2.23:50226 -> 83.222.23.116:13566
Source: global trafficTCP traffic: 192.168.2.23:57156 -> 83.222.218.90:13566
Source: global trafficTCP traffic: 192.168.2.23:44978 -> 83.222.242.54:13566
Source: global trafficTCP traffic: 192.168.2.23:50174 -> 83.222.68.116:13566
Source: global trafficTCP traffic: 192.168.2.23:58060 -> 83.222.212.10:13566
Source: global trafficTCP traffic: 192.168.2.23:46388 -> 83.222.145.3:13566
Source: global trafficTCP traffic: 192.168.2.23:41150 -> 83.222.198.90:13566
Source: global trafficTCP traffic: 192.168.2.23:37532 -> 83.222.100.14:13566
Source: global trafficTCP traffic: 192.168.2.23:49482 -> 83.222.203.193:13566
Source: global trafficTCP traffic: 192.168.2.23:52928 -> 83.222.214.52:13566
Source: global trafficTCP traffic: 192.168.2.23:44858 -> 83.222.41.168:13566
Source: global trafficTCP traffic: 192.168.2.23:54258 -> 83.222.8.185:13566
Source: global trafficTCP traffic: 192.168.2.23:42704 -> 83.222.191.90:13566
Source: /tmp/Kloki.mips.elf (PID: 6263)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.23:42704
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.156
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.156
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.156
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.29.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.156
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.29.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.29.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.29.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.232.116
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.227.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.231.200
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.232.116
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.227.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.18
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.149.108
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.231.200
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.18
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.23.247
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.149.108
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.125.239
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.23.247
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.227.120
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.125.239
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.85.122
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.227.120
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.85.122
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.39
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.97.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.238.39
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.97.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.97.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.67.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.97.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.67.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.67.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.67.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.106
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.174.216
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.106
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.174.216
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.254.150
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.254.150
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.77.226
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.77.226
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.216.52
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.170.174
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.216.52
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 904, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 912, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 918, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1532, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1983, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 2302, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6244, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6288, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6291, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6292, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6293, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6296, result: no such processJump to behavior
Source: Initial sampleString containing 'busybox' found: busybox
Source: Initial sampleString containing 'busybox' found: ppid/proc/net/tcp/proc/self/exe/proc//status/fd//dev/null/dev/consolesocket05/proc/%d/exepkillkillkillallechowgetcurlpsbusyboxiptablesrebootshutdownhaltpoweroffinitsystemctltelinitcatgrepshashbashzshcshkshdashfish
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 904, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 912, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 918, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1532, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 1983, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 2302, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6244, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6288, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6291, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6292, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6293, result: successfulJump to behavior
Source: /tmp/Kloki.mips.elf (PID: 6269)SIGKILL sent: pid: 6296, result: no such processJump to behavior
Source: classification engineClassification label: mal52.spre.linELF@0/0@1/0
Source: /tmp/Kloki.mips.elf (PID: 6263)Queries kernel information via 'uname': Jump to behavior
Source: Kloki.mips.elf, 6263.1.00007ffd2c62a000.00007ffd2c64b000.rw-.sdmp, Kloki.mips.elf, 6265.1.00007ffd2c62a000.00007ffd2c64b000.rw-.sdmpBinary or memory string: @x86_64/usr/bin/qemu-mips/tmp/Kloki.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Kloki.mips.elf
Source: Kloki.mips.elf, 6263.1.0000564531825000.00005645318cd000.rw-.sdmp, Kloki.mips.elf, 6265.1.0000564531825000.00005645318ac000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: Kloki.mips.elf, 6263.1.00007ffd2c62a000.00007ffd2c64b000.rw-.sdmp, Kloki.mips.elf, 6265.1.00007ffd2c62a000.00007ffd2c64b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: Kloki.mips.elf, 6263.1.0000564531825000.00005645318cd000.rw-.sdmp, Kloki.mips.elf, 6265.1.0000564531825000.00005645318ac000.rw-.sdmpBinary or memory string: 1EV!/etc/qemu-binfmt/mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594497 Sample: Kloki.mips.elf Startdate: 19/01/2025 Architecture: LINUX Score: 52 23 83.222.125.239, 13566, 56410 TRI-ASTrueRecordsIncES Russian Federation 2->23 25 83.222.198.29, 13566, 46172 SYNTERRA-ASRU Russian Federation 2->25 27 79 other IPs or domains 2->27 29 Antivirus / Scanner detection for submitted sample 2->29 8 Kloki.mips.elf 2->8         started        10 gnome-session-binary sh gsd-sharing 2->10         started        12 gnome-session-binary sh gnome-shell 2->12         started        14 4 other processes 2->14 signatures3 process4 process5 16 Kloki.mips.elf 8->16         started        18 Kloki.mips.elf 8->18         started        process6 20 Kloki.mips.elf 16->20         started        signatures7 31 Sample tries to kill multiple processes (SIGKILL) 20->31
SourceDetectionScannerLabelLink
Kloki.mips.elf100%AviraEXP/ELF.Mirai.W
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.213.18
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.246.171
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.100.14
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.238.39
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.227.66
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.223.100
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.144.33
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.198.90
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.50.139
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.227.120
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.188.59
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.32.89
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.26.93
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.187.106
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.33.17
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.242.54
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.71.113
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.54.151
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.77.226
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.215.221
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.202.245
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.137.113
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.8.185
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    83.222.67.126
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.29.148
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.10.10
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.41.168
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.125.239
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.46.188
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.106.41
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.220.205
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.159.102
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.166.4
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.216.52
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.148.253
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.80.13
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.97.82
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.130.158
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.141.58
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.79.70
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.212.10
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.254.150
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.198.29
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.73.156
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.23.247
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.68.116
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.170.174
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.29.218
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.145.3
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.231.200
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.155.144
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.203.193
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.218.90
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.70.63
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.99.106
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.91.233
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.85.122
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.23.116
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.105.103
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.67.148
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.15.162
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.67.220
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.168.252
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.200.97
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.148.118
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.210.211
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    83.222.233.229
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.77.26
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.93.200
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.25.134
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.246.108
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.214.52
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.149.108
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.31.69
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.174.216
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.232.116
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.128.248
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.246.171Kloki.mpsl.elfGet hashmaliciousUnknownBrowse
      83.222.32.89Kloki.arm5.elfGet hashmaliciousUnknownBrowse
        83.222.26.93Kloki.arm7.elfGet hashmaliciousMiraiBrowse
          91.189.91.43loki.arm7.elfGet hashmaliciousMiraiBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              loki.arc.elfGet hashmaliciousUnknownBrowse
                Kloki.arm5.elfGet hashmaliciousUnknownBrowse
                  Kloki.arm7.elfGet hashmaliciousMiraiBrowse
                    arm7.elfGet hashmaliciousUnknownBrowse
                      ppc.elfGet hashmaliciousUnknownBrowse
                        arm.elfGet hashmaliciousUnknownBrowse
                          mips.elfGet hashmaliciousUnknownBrowse
                            arm6.elfGet hashmaliciousUnknownBrowse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              secure-network-rebirthltd.ruKloki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              loki.arm7.elfGet hashmaliciousMiraiBrowse
                              • 83.222.191.90
                              Kloki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              loki.mpsl.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              loki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              loki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              loki.m68k.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              loki.spc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              Kloki.x86.elfGet hashmaliciousUnknownBrowse
                              • 83.222.191.90
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              COGECO-PEER1CAKloki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.224.99
                              loki.arm7.elfGet hashmaliciousMiraiBrowse
                              • 83.222.247.103
                              Kloki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.224.152
                              Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.243.167
                              loki.mpsl.elfGet hashmaliciousUnknownBrowse
                              • 83.222.228.152
                              loki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.254.156
                              loki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.233.216
                              loki.m68k.elfGet hashmaliciousUnknownBrowse
                              • 83.222.240.133
                              loki.spc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.243.125
                              Kloki.x86.elfGet hashmaliciousUnknownBrowse
                              • 83.222.239.59
                              SONICDUO-ASRUKloki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.212.206
                              loki.arm7.elfGet hashmaliciousMiraiBrowse
                              • 83.222.215.159
                              Kloki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.219.231
                              Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.223.135
                              loki.mpsl.elfGet hashmaliciousUnknownBrowse
                              • 83.222.214.233
                              loki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.213.184
                              loki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.218.90
                              loki.m68k.elfGet hashmaliciousUnknownBrowse
                              • 83.222.216.188
                              loki.spc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.219.136
                              Kloki.x86.elfGet hashmaliciousUnknownBrowse
                              • 83.222.223.136
                              COGECO-PEER1CAKloki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.224.99
                              loki.arm7.elfGet hashmaliciousMiraiBrowse
                              • 83.222.247.103
                              Kloki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.224.152
                              Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.243.167
                              loki.mpsl.elfGet hashmaliciousUnknownBrowse
                              • 83.222.228.152
                              loki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.254.156
                              loki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.233.216
                              loki.m68k.elfGet hashmaliciousUnknownBrowse
                              • 83.222.240.133
                              loki.spc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.243.125
                              Kloki.x86.elfGet hashmaliciousUnknownBrowse
                              • 83.222.239.59
                              MNOGOBYTE-ASMoscowRussiaRUKloki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.118.158
                              loki.arm7.elfGet hashmaliciousMiraiBrowse
                              • 83.222.117.74
                              Kloki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.109.209
                              Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.102.176
                              loki.mpsl.elfGet hashmaliciousUnknownBrowse
                              • 83.222.115.205
                              loki.i486.elfGet hashmaliciousUnknownBrowse
                              • 83.222.114.114
                              loki.sh4.elfGet hashmaliciousUnknownBrowse
                              • 83.222.101.124
                              loki.m68k.elfGet hashmaliciousUnknownBrowse
                              • 83.222.98.5
                              loki.spc.elfGet hashmaliciousUnknownBrowse
                              • 83.222.118.190
                              Kloki.x86.elfGet hashmaliciousUnknownBrowse
                              • 83.222.115.165
                              No context
                              No context
                              No created / dropped files found
                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                              Entropy (8bit):5.522097915773244
                              TrID:
                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                              File name:Kloki.mips.elf
                              File size:80'700 bytes
                              MD5:28e2ed00876520c9d7702cdb33281937
                              SHA1:22c2d7c21f246b4a1021314a31c443763b2487b5
                              SHA256:358fe1f21475d8c341f57165fe6d95f10d54128765a3b9a6c6fd67889c6585ce
                              SHA512:a127a7189b4b80ff8fd81bca868602500c5e366d6235e5f92af33272b225464329d7328321a314da0164e6f4454d014c482a5c7e58034c6ce0565405fb976eda
                              SSDEEP:1536:SgezupKOUUj+/vzsx8gFRQHLQHLiiLu3BerXJ7dAeiXOHP:U2KOM/vzs7R8erXJ7dKOHP
                              TLSH:F773E81A6E258FEDF768833447B78E21A79833D626E1D685E25CD6001E6034E641FFE8
                              File Content Preview:.ELF.....................@.`...4..9......4. ...(.............@...@..../.../...............0..E0..E0.......:x........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'..X...!........'9.

                              ELF header

                              Class:ELF32
                              Data:2's complement, big endian
                              Version:1 (current)
                              Machine:MIPS R3000
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:UNIX - System V
                              ABI Version:0
                              Entry Point Address:0x400260
                              Flags:0x1007
                              ELF Header Size:52
                              Program Header Offset:52
                              Program Header Size:32
                              Number of Program Headers:3
                              Section Header Offset:80140
                              Section Header Size:40
                              Number of Section Headers:14
                              Header String Table Index:13
                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                              NULL0x00x00x00x00x0000
                              .initPROGBITS0x4000940x940x8c0x00x6AX004
                              .textPROGBITS0x4001200x1200x11a300x00x6AX0016
                              .finiPROGBITS0x411b500x11b500x5c0x00x6AX004
                              .rodataPROGBITS0x411bb00x11bb00x14000x00x2A0016
                              .ctorsPROGBITS0x4530000x130000x80x00x3WA004
                              .dtorsPROGBITS0x4530080x130080x80x00x3WA004
                              .data.rel.roPROGBITS0x4530140x130140x740x00x3WA004
                              .dataPROGBITS0x4530900x130900x3c00x00x3WA0016
                              .gotPROGBITS0x4534500x134500x4580x40x10000003WAp0016
                              .sbssNOBITS0x4538a80x138a80x1c0x00x10000003WAp004
                              .bssNOBITS0x4538d00x138a80x31a80x00x3WA0016
                              .mdebug.abi32PROGBITS0x9fc0x138a80x00x00x0001
                              .shstrtabSTRTAB0x00x138a80x640x00x0001
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x4000000x4000000x12fb00x12fb05.54920x5R E0x10000.init .text .fini .rodata
                              LOAD0x130000x4530000x4530000x8a80x3a784.03840x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                              Download Network PCAP: filteredfull

                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                              2025-01-19T03:27:55.358286+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.2342704TCP
                              • Total Packets: 180
                              • 13566 undefined
                              • 443 (HTTPS)
                              • 80 (HTTP)
                              • 53 (DNS)
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 19, 2025 03:27:53.536696911 CET43928443192.168.2.2391.189.91.42
                              Jan 19, 2025 03:27:54.910422087 CET3801013566192.168.2.2383.222.73.156
                              Jan 19, 2025 03:27:54.916722059 CET135663801083.222.73.156192.168.2.23
                              Jan 19, 2025 03:27:54.916783094 CET3801013566192.168.2.2383.222.73.156
                              Jan 19, 2025 03:27:54.934442997 CET3801013566192.168.2.2383.222.73.156
                              Jan 19, 2025 03:27:54.938491106 CET3544813566192.168.2.2383.222.29.148
                              Jan 19, 2025 03:27:54.940746069 CET135663801083.222.73.156192.168.2.23
                              Jan 19, 2025 03:27:54.940799952 CET3801013566192.168.2.2383.222.73.156
                              Jan 19, 2025 03:27:54.943767071 CET135663544883.222.29.148192.168.2.23
                              Jan 19, 2025 03:27:54.943819046 CET3544813566192.168.2.2383.222.29.148
                              Jan 19, 2025 03:27:54.955193996 CET3544813566192.168.2.2383.222.29.148
                              Jan 19, 2025 03:27:54.961255074 CET135663544883.222.29.148192.168.2.23
                              Jan 19, 2025 03:27:54.961343050 CET3544813566192.168.2.2383.222.29.148
                              Jan 19, 2025 03:27:54.976733923 CET4304813566192.168.2.2383.222.232.116
                              Jan 19, 2025 03:27:54.980217934 CET5972413566192.168.2.2383.222.227.66
                              Jan 19, 2025 03:27:54.982563019 CET5846413566192.168.2.2383.222.231.200
                              Jan 19, 2025 03:27:54.982759953 CET135664304883.222.232.116192.168.2.23
                              Jan 19, 2025 03:27:54.982831001 CET4304813566192.168.2.2383.222.232.116
                              Jan 19, 2025 03:27:54.985141993 CET135665972483.222.227.66192.168.2.23
                              Jan 19, 2025 03:27:54.985340118 CET5972413566192.168.2.2383.222.227.66
                              Jan 19, 2025 03:27:54.986067057 CET5184213566192.168.2.2383.222.213.18
                              Jan 19, 2025 03:27:54.989717007 CET5512813566192.168.2.2383.222.149.108
                              Jan 19, 2025 03:27:54.990504026 CET135665846483.222.231.200192.168.2.23
                              Jan 19, 2025 03:27:54.990679979 CET5846413566192.168.2.2383.222.231.200
                              Jan 19, 2025 03:27:54.991799116 CET135665184283.222.213.18192.168.2.23
                              Jan 19, 2025 03:27:54.991892099 CET5184213566192.168.2.2383.222.213.18
                              Jan 19, 2025 03:27:54.994257927 CET5172213566192.168.2.2383.222.23.247
                              Jan 19, 2025 03:27:54.995598078 CET135665512883.222.149.108192.168.2.23
                              Jan 19, 2025 03:27:54.995659113 CET5512813566192.168.2.2383.222.149.108
                              Jan 19, 2025 03:27:54.998481989 CET5641013566192.168.2.2383.222.125.239
                              Jan 19, 2025 03:27:55.000142097 CET135665172283.222.23.247192.168.2.23
                              Jan 19, 2025 03:27:55.000206947 CET5172213566192.168.2.2383.222.23.247
                              Jan 19, 2025 03:27:55.003470898 CET4335813566192.168.2.2383.222.227.120
                              Jan 19, 2025 03:27:55.004322052 CET135665641083.222.125.239192.168.2.23
                              Jan 19, 2025 03:27:55.004394054 CET5641013566192.168.2.2383.222.125.239
                              Jan 19, 2025 03:27:55.008368969 CET4730613566192.168.2.2383.222.85.122
                              Jan 19, 2025 03:27:55.009536028 CET135664335883.222.227.120192.168.2.23
                              Jan 19, 2025 03:27:55.009601116 CET4335813566192.168.2.2383.222.227.120
                              Jan 19, 2025 03:27:55.014250994 CET135664730683.222.85.122192.168.2.23
                              Jan 19, 2025 03:27:55.014298916 CET4730613566192.168.2.2383.222.85.122
                              Jan 19, 2025 03:27:55.014915943 CET4087413566192.168.2.2383.222.238.39
                              Jan 19, 2025 03:27:55.018975973 CET4504413566192.168.2.2383.222.97.82
                              Jan 19, 2025 03:27:55.020828962 CET135664087483.222.238.39192.168.2.23
                              Jan 19, 2025 03:27:55.021009922 CET4087413566192.168.2.2383.222.238.39
                              Jan 19, 2025 03:27:55.023966074 CET135664504483.222.97.82192.168.2.23
                              Jan 19, 2025 03:27:55.024025917 CET4504413566192.168.2.2383.222.97.82
                              Jan 19, 2025 03:27:55.026216984 CET4504413566192.168.2.2383.222.97.82
                              Jan 19, 2025 03:27:55.029082060 CET5569213566192.168.2.2383.222.67.148
                              Jan 19, 2025 03:27:55.031917095 CET135664504483.222.97.82192.168.2.23
                              Jan 19, 2025 03:27:55.031999111 CET4504413566192.168.2.2383.222.97.82
                              Jan 19, 2025 03:27:55.035008907 CET135665569283.222.67.148192.168.2.23
                              Jan 19, 2025 03:27:55.035074949 CET5569213566192.168.2.2383.222.67.148
                              Jan 19, 2025 03:27:55.050096989 CET5569213566192.168.2.2383.222.67.148
                              Jan 19, 2025 03:27:55.050508022 CET3943013566192.168.2.2383.222.33.17
                              Jan 19, 2025 03:27:55.054944038 CET135665569283.222.67.148192.168.2.23
                              Jan 19, 2025 03:27:55.055015087 CET5569213566192.168.2.2383.222.67.148
                              Jan 19, 2025 03:27:55.055310011 CET135663943083.222.33.17192.168.2.23
                              Jan 19, 2025 03:27:55.055380106 CET3943013566192.168.2.2383.222.33.17
                              Jan 19, 2025 03:27:55.066498041 CET3665413566192.168.2.2383.222.187.106
                              Jan 19, 2025 03:27:55.067120075 CET4472813566192.168.2.2383.222.174.216
                              Jan 19, 2025 03:27:55.071391106 CET135663665483.222.187.106192.168.2.23
                              Jan 19, 2025 03:27:55.071449041 CET3665413566192.168.2.2383.222.187.106
                              Jan 19, 2025 03:27:55.071892023 CET135664472883.222.174.216192.168.2.23
                              Jan 19, 2025 03:27:55.071943998 CET4472813566192.168.2.2383.222.174.216
                              Jan 19, 2025 03:27:55.088388920 CET3339013566192.168.2.2383.222.254.150
                              Jan 19, 2025 03:27:55.093275070 CET135663339083.222.254.150192.168.2.23
                              Jan 19, 2025 03:27:55.093334913 CET3339013566192.168.2.2383.222.254.150
                              Jan 19, 2025 03:27:55.094767094 CET4408213566192.168.2.2383.222.77.226
                              Jan 19, 2025 03:27:55.099564075 CET135664408283.222.77.226192.168.2.23
                              Jan 19, 2025 03:27:55.099623919 CET4408213566192.168.2.2383.222.77.226
                              Jan 19, 2025 03:27:55.112695932 CET5267013566192.168.2.2383.222.216.52
                              Jan 19, 2025 03:27:55.117144108 CET3598813566192.168.2.2383.222.170.174
                              Jan 19, 2025 03:27:55.117583036 CET135665267083.222.216.52192.168.2.23
                              Jan 19, 2025 03:27:55.117634058 CET5267013566192.168.2.2383.222.216.52
                              Jan 19, 2025 03:27:55.122049093 CET135663598883.222.170.174192.168.2.23
                              Jan 19, 2025 03:27:55.122097969 CET3598813566192.168.2.2383.222.170.174
                              Jan 19, 2025 03:27:55.136037111 CET3929213566192.168.2.2383.222.70.63
                              Jan 19, 2025 03:27:55.140933037 CET135663929283.222.70.63192.168.2.23
                              Jan 19, 2025 03:27:55.140990973 CET3929213566192.168.2.2383.222.70.63
                              Jan 19, 2025 03:27:55.141216993 CET3539413566192.168.2.2383.222.26.93
                              Jan 19, 2025 03:27:55.146159887 CET4496213566192.168.2.2383.222.54.151
                              Jan 19, 2025 03:27:55.146639109 CET135663539483.222.26.93192.168.2.23
                              Jan 19, 2025 03:27:55.146688938 CET3539413566192.168.2.2383.222.26.93
                              Jan 19, 2025 03:27:55.150398970 CET3806813566192.168.2.2383.222.77.26
                              Jan 19, 2025 03:27:55.151576996 CET135664496283.222.54.151192.168.2.23
                              Jan 19, 2025 03:27:55.151650906 CET4496213566192.168.2.2383.222.54.151
                              Jan 19, 2025 03:27:55.155114889 CET4127213566192.168.2.2383.222.15.162
                              Jan 19, 2025 03:27:55.155978918 CET135663806883.222.77.26192.168.2.23
                              Jan 19, 2025 03:27:55.156043053 CET3806813566192.168.2.2383.222.77.26
                              Jan 19, 2025 03:27:55.157968044 CET4421613566192.168.2.2383.222.148.253
                              Jan 19, 2025 03:27:55.160041094 CET135664127283.222.15.162192.168.2.23
                              Jan 19, 2025 03:27:55.160099983 CET4127213566192.168.2.2383.222.15.162
                              Jan 19, 2025 03:27:55.162441015 CET4327213566192.168.2.2383.222.202.245
                              Jan 19, 2025 03:27:55.162779093 CET135664421683.222.148.253192.168.2.23
                              Jan 19, 2025 03:27:55.162833929 CET4421613566192.168.2.2383.222.148.253
                              Jan 19, 2025 03:27:55.165754080 CET5205213566192.168.2.2383.222.80.13
                              Jan 19, 2025 03:27:55.167345047 CET135664327283.222.202.245192.168.2.23
                              Jan 19, 2025 03:27:55.167396069 CET4327213566192.168.2.2383.222.202.245
                              Jan 19, 2025 03:27:55.170408964 CET5643013566192.168.2.2383.222.137.113
                              Jan 19, 2025 03:27:55.170566082 CET135665205283.222.80.13192.168.2.23
                              Jan 19, 2025 03:27:55.170605898 CET5205213566192.168.2.2383.222.80.13
                              Jan 19, 2025 03:27:55.173605919 CET4891613566192.168.2.2383.222.31.69
                              Jan 19, 2025 03:27:55.175231934 CET135665643083.222.137.113192.168.2.23
                              Jan 19, 2025 03:27:55.175287962 CET5643013566192.168.2.2383.222.137.113
                              Jan 19, 2025 03:27:55.177014112 CET4553413566192.168.2.2383.222.220.205
                              Jan 19, 2025 03:27:55.178047895 CET3843813566192.168.2.2383.222.29.218
                              Jan 19, 2025 03:27:55.178491116 CET135664891683.222.31.69192.168.2.23
                              Jan 19, 2025 03:27:55.178544998 CET4891613566192.168.2.2383.222.31.69
                              Jan 19, 2025 03:27:55.181870937 CET135664553483.222.220.205192.168.2.23
                              Jan 19, 2025 03:27:55.181931019 CET4553413566192.168.2.2383.222.220.205
                              Jan 19, 2025 03:27:55.182260036 CET3720413566192.168.2.2383.222.99.106
                              Jan 19, 2025 03:27:55.182863951 CET135663843883.222.29.218192.168.2.23
                              Jan 19, 2025 03:27:55.182914019 CET3843813566192.168.2.2383.222.29.218
                              Jan 19, 2025 03:27:55.184006929 CET3603613566192.168.2.2383.222.188.59
                              Jan 19, 2025 03:27:55.185563087 CET5284613566192.168.2.2383.222.159.102
                              Jan 19, 2025 03:27:55.186418056 CET3809613566192.168.2.2383.222.233.229
                              Jan 19, 2025 03:27:55.187079906 CET135663720483.222.99.106192.168.2.23
                              Jan 19, 2025 03:27:55.187134981 CET3720413566192.168.2.2383.222.99.106
                              Jan 19, 2025 03:27:55.187634945 CET3639413566192.168.2.2383.222.166.4
                              Jan 19, 2025 03:27:55.188529968 CET5431413566192.168.2.2383.222.67.220
                              Jan 19, 2025 03:27:55.188805103 CET135663603683.222.188.59192.168.2.23
                              Jan 19, 2025 03:27:55.188852072 CET3603613566192.168.2.2383.222.188.59
                              Jan 19, 2025 03:27:55.189146996 CET5678013566192.168.2.2383.222.155.144
                              Jan 19, 2025 03:27:55.189760923 CET5248813566192.168.2.2383.222.246.171
                              Jan 19, 2025 03:27:55.190387964 CET135665284683.222.159.102192.168.2.23
                              Jan 19, 2025 03:27:55.190432072 CET5284613566192.168.2.2383.222.159.102
                              Jan 19, 2025 03:27:55.191211939 CET135663809683.222.233.229192.168.2.23
                              Jan 19, 2025 03:27:55.191265106 CET3809613566192.168.2.2383.222.233.229
                              Jan 19, 2025 03:27:55.191948891 CET4991213566192.168.2.2383.222.50.139
                              Jan 19, 2025 03:27:55.192473888 CET135663639483.222.166.4192.168.2.23
                              Jan 19, 2025 03:27:55.192526102 CET3639413566192.168.2.2383.222.166.4
                              Jan 19, 2025 03:27:55.193304062 CET135665431483.222.67.220192.168.2.23
                              Jan 19, 2025 03:27:55.193353891 CET5431413566192.168.2.2383.222.67.220
                              Jan 19, 2025 03:27:55.193949938 CET135665678083.222.155.144192.168.2.23
                              Jan 19, 2025 03:27:55.193991899 CET5678013566192.168.2.2383.222.155.144
                              Jan 19, 2025 03:27:55.194084883 CET5474013566192.168.2.2383.222.168.252
                              Jan 19, 2025 03:27:55.194550991 CET135665248883.222.246.171192.168.2.23
                              Jan 19, 2025 03:27:55.194598913 CET5248813566192.168.2.2383.222.246.171
                              Jan 19, 2025 03:27:55.196789980 CET135664991283.222.50.139192.168.2.23
                              Jan 19, 2025 03:27:55.196841002 CET4991213566192.168.2.2383.222.50.139
                              Jan 19, 2025 03:27:55.196886063 CET3503613566192.168.2.2383.222.128.248
                              Jan 19, 2025 03:27:55.198872089 CET135665474083.222.168.252192.168.2.23
                              Jan 19, 2025 03:27:55.198925018 CET5474013566192.168.2.2383.222.168.252
                              Jan 19, 2025 03:27:55.199556112 CET6093613566192.168.2.2383.222.10.10
                              Jan 19, 2025 03:27:55.201721907 CET135663503683.222.128.248192.168.2.23
                              Jan 19, 2025 03:27:55.201776028 CET3503613566192.168.2.2383.222.128.248
                              Jan 19, 2025 03:27:55.202080965 CET4614613566192.168.2.2383.222.106.41
                              Jan 19, 2025 03:27:55.204421043 CET135666093683.222.10.10192.168.2.23
                              Jan 19, 2025 03:27:55.204474926 CET6093613566192.168.2.2383.222.10.10
                              Jan 19, 2025 03:27:55.204657078 CET3910813566192.168.2.2383.222.79.70
                              Jan 19, 2025 03:27:55.206881046 CET135664614683.222.106.41192.168.2.23
                              Jan 19, 2025 03:27:55.206933975 CET4614613566192.168.2.2383.222.106.41
                              Jan 19, 2025 03:27:55.207212925 CET5981213566192.168.2.2383.222.246.108
                              Jan 19, 2025 03:27:55.209423065 CET5345613566192.168.2.2383.222.32.89
                              Jan 19, 2025 03:27:55.209471941 CET135663910883.222.79.70192.168.2.23
                              Jan 19, 2025 03:27:55.209527969 CET3910813566192.168.2.2383.222.79.70
                              Jan 19, 2025 03:27:55.211271048 CET5270813566192.168.2.2383.222.215.221
                              Jan 19, 2025 03:27:55.212143898 CET135665981283.222.246.108192.168.2.23
                              Jan 19, 2025 03:27:55.212198019 CET5981213566192.168.2.2383.222.246.108
                              Jan 19, 2025 03:27:55.212407112 CET4566013566192.168.2.2383.222.148.118
                              Jan 19, 2025 03:27:55.214297056 CET135665345683.222.32.89192.168.2.23
                              Jan 19, 2025 03:27:55.214358091 CET5345613566192.168.2.2383.222.32.89
                              Jan 19, 2025 03:27:55.215431929 CET4352213566192.168.2.2383.222.67.126
                              Jan 19, 2025 03:27:55.216161013 CET135665270883.222.215.221192.168.2.23
                              Jan 19, 2025 03:27:55.216208935 CET5270813566192.168.2.2383.222.215.221
                              Jan 19, 2025 03:27:55.217272043 CET135664566083.222.148.118192.168.2.23
                              Jan 19, 2025 03:27:55.217324972 CET4566013566192.168.2.2383.222.148.118
                              Jan 19, 2025 03:27:55.218080044 CET5095013566192.168.2.2383.222.91.233
                              Jan 19, 2025 03:27:55.220336914 CET135664352283.222.67.126192.168.2.23
                              Jan 19, 2025 03:27:55.220396996 CET4352213566192.168.2.2383.222.67.126
                              Jan 19, 2025 03:27:55.220695972 CET4745613566192.168.2.2383.222.130.158
                              Jan 19, 2025 03:27:55.222953081 CET135665095083.222.91.233192.168.2.23
                              Jan 19, 2025 03:27:55.223000050 CET5095013566192.168.2.2383.222.91.233
                              Jan 19, 2025 03:27:55.223537922 CET4617213566192.168.2.2383.222.198.29
                              Jan 19, 2025 03:27:55.225486994 CET135664745683.222.130.158192.168.2.23
                              Jan 19, 2025 03:27:55.225533962 CET4745613566192.168.2.2383.222.130.158
                              Jan 19, 2025 03:27:55.226428986 CET5490413566192.168.2.2383.222.46.188
                              Jan 19, 2025 03:27:55.228384972 CET135664617283.222.198.29192.168.2.23
                              Jan 19, 2025 03:27:55.228436947 CET4617213566192.168.2.2383.222.198.29
                              Jan 19, 2025 03:27:55.229310036 CET3971613566192.168.2.2383.222.200.97
                              Jan 19, 2025 03:27:55.231218100 CET135665490483.222.46.188192.168.2.23
                              Jan 19, 2025 03:27:55.231264114 CET5490413566192.168.2.2383.222.46.188
                              Jan 19, 2025 03:27:55.231556892 CET3413813566192.168.2.2383.222.71.113
                              Jan 19, 2025 03:27:55.234987974 CET135663971683.222.200.97192.168.2.23
                              Jan 19, 2025 03:27:55.235052109 CET3971613566192.168.2.2383.222.200.97
                              Jan 19, 2025 03:27:55.236017942 CET4085413566192.168.2.2383.222.93.200
                              Jan 19, 2025 03:27:55.237235069 CET135663413883.222.71.113192.168.2.23
                              Jan 19, 2025 03:27:55.238457918 CET3413813566192.168.2.2383.222.71.113
                              Jan 19, 2025 03:27:55.241750956 CET135664085483.222.93.200192.168.2.23
                              Jan 19, 2025 03:27:55.241822958 CET4085413566192.168.2.2383.222.93.200
                              Jan 19, 2025 03:27:55.242583990 CET4352213566192.168.2.2383.222.105.103
                              Jan 19, 2025 03:27:55.247859001 CET3312013566192.168.2.2383.222.210.211
                              Jan 19, 2025 03:27:55.248464108 CET135664352283.222.105.103192.168.2.23
                              Jan 19, 2025 03:27:55.248528004 CET4352213566192.168.2.2383.222.105.103
                              Jan 19, 2025 03:27:55.252126932 CET5873613566192.168.2.2383.222.144.33
                              Jan 19, 2025 03:27:55.253520012 CET135663312083.222.210.211192.168.2.23
                              Jan 19, 2025 03:27:55.253571033 CET3312013566192.168.2.2383.222.210.211
                              Jan 19, 2025 03:27:55.256083012 CET5269613566192.168.2.2383.222.25.134
                              Jan 19, 2025 03:27:55.256988049 CET135665873683.222.144.33192.168.2.23
                              Jan 19, 2025 03:27:55.257046938 CET5873613566192.168.2.2383.222.144.33
                              Jan 19, 2025 03:27:55.260396004 CET4128613566192.168.2.2383.222.141.58
                              Jan 19, 2025 03:27:55.260902882 CET135665269683.222.25.134192.168.2.23
                              Jan 19, 2025 03:27:55.260972977 CET5269613566192.168.2.2383.222.25.134
                              Jan 19, 2025 03:27:55.265258074 CET135664128683.222.141.58192.168.2.23
                              Jan 19, 2025 03:27:55.265338898 CET4128613566192.168.2.2383.222.141.58
                              Jan 19, 2025 03:27:55.265345097 CET4586613566192.168.2.2383.222.223.100
                              Jan 19, 2025 03:27:55.270155907 CET135664586683.222.223.100192.168.2.23
                              Jan 19, 2025 03:27:55.270216942 CET4586613566192.168.2.2383.222.223.100
                              Jan 19, 2025 03:27:55.270858049 CET5022613566192.168.2.2383.222.23.116
                              Jan 19, 2025 03:27:55.275804996 CET135665022683.222.23.116192.168.2.23
                              Jan 19, 2025 03:27:55.275883913 CET5022613566192.168.2.2383.222.23.116
                              Jan 19, 2025 03:27:55.276602030 CET5715613566192.168.2.2383.222.218.90
                              Jan 19, 2025 03:27:55.281502008 CET135665715683.222.218.90192.168.2.23
                              Jan 19, 2025 03:27:55.281565905 CET5715613566192.168.2.2383.222.218.90
                              Jan 19, 2025 03:27:55.281999111 CET4497813566192.168.2.2383.222.242.54
                              Jan 19, 2025 03:27:55.286545992 CET5017413566192.168.2.2383.222.68.116
                              Jan 19, 2025 03:27:55.286889076 CET135664497883.222.242.54192.168.2.23
                              Jan 19, 2025 03:27:55.286931038 CET4497813566192.168.2.2383.222.242.54
                              Jan 19, 2025 03:27:55.291414976 CET135665017483.222.68.116192.168.2.23
                              Jan 19, 2025 03:27:55.291462898 CET5017413566192.168.2.2383.222.68.116
                              Jan 19, 2025 03:27:55.291976929 CET5806013566192.168.2.2383.222.212.10
                              Jan 19, 2025 03:27:55.295445919 CET4638813566192.168.2.2383.222.145.3
                              Jan 19, 2025 03:27:55.296897888 CET135665806083.222.212.10192.168.2.23
                              Jan 19, 2025 03:27:55.296956062 CET5806013566192.168.2.2383.222.212.10
                              Jan 19, 2025 03:27:55.299765110 CET4115013566192.168.2.2383.222.198.90
                              Jan 19, 2025 03:27:55.300317049 CET135664638883.222.145.3192.168.2.23
                              Jan 19, 2025 03:27:55.300535917 CET4638813566192.168.2.2383.222.145.3
                              Jan 19, 2025 03:27:55.303692102 CET3753213566192.168.2.2383.222.100.14
                              Jan 19, 2025 03:27:55.304640055 CET135664115083.222.198.90192.168.2.23
                              Jan 19, 2025 03:27:55.304706097 CET4115013566192.168.2.2383.222.198.90
                              Jan 19, 2025 03:27:55.308368921 CET4948213566192.168.2.2383.222.203.193
                              Jan 19, 2025 03:27:55.308562040 CET135663753283.222.100.14192.168.2.23
                              Jan 19, 2025 03:27:55.308636904 CET3753213566192.168.2.2383.222.100.14
                              Jan 19, 2025 03:27:55.312422037 CET5292813566192.168.2.2383.222.214.52
                              Jan 19, 2025 03:27:55.313275099 CET135664948283.222.203.193192.168.2.23
                              Jan 19, 2025 03:27:55.313321114 CET4948213566192.168.2.2383.222.203.193
                              Jan 19, 2025 03:27:55.317276955 CET4485813566192.168.2.2383.222.41.168
                              Jan 19, 2025 03:27:55.317348957 CET135665292883.222.214.52192.168.2.23
                              Jan 19, 2025 03:27:55.317410946 CET5292813566192.168.2.2383.222.214.52
                              Jan 19, 2025 03:27:55.321479082 CET5425813566192.168.2.2383.222.8.185
                              Jan 19, 2025 03:27:55.322257042 CET135664485883.222.41.168192.168.2.23
                              Jan 19, 2025 03:27:55.322302103 CET4485813566192.168.2.2383.222.41.168
                              Jan 19, 2025 03:27:55.326313972 CET135665425883.222.8.185192.168.2.23
                              Jan 19, 2025 03:27:55.326379061 CET5425813566192.168.2.2383.222.8.185
                              Jan 19, 2025 03:27:55.352912903 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:27:55.358285904 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:27:55.358339071 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:27:55.359301090 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:27:55.364125013 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:27:55.364180088 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:27:55.369154930 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:27:59.167937994 CET42836443192.168.2.2391.189.91.43
                              Jan 19, 2025 03:27:59.935828924 CET4251680192.168.2.23109.202.202.202
                              Jan 19, 2025 03:28:05.367177963 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:28:05.372348070 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:28:05.869132042 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:28:05.869204998 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:28:05.996350050 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:28:05.996428967 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:28:14.273900986 CET43928443192.168.2.2391.189.91.42
                              Jan 19, 2025 03:28:26.556360960 CET42836443192.168.2.2391.189.91.43
                              Jan 19, 2025 03:28:30.655765057 CET4251680192.168.2.23109.202.202.202
                              Jan 19, 2025 03:28:55.224476099 CET43928443192.168.2.2391.189.91.42
                              Jan 19, 2025 03:29:06.048928976 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:29:06.054464102 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:29:06.250765085 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:29:06.251183033 CET4270413566192.168.2.2383.222.191.90
                              Jan 19, 2025 03:29:06.932406902 CET135664270483.222.191.90192.168.2.23
                              Jan 19, 2025 03:29:06.932636023 CET4270413566192.168.2.2383.222.191.90
                              TimestampSource PortDest PortSource IPDest IP
                              Jan 19, 2025 03:27:55.339375019 CET4978453192.168.2.238.8.8.8
                              Jan 19, 2025 03:27:55.348695993 CET53497848.8.8.8192.168.2.23
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Jan 19, 2025 03:27:55.339375019 CET192.168.2.238.8.8.80xf50dStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Jan 19, 2025 03:27:55.348695993 CET8.8.8.8192.168.2.230xf50dNo error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

                              System Behavior

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/tmp/Kloki.mips.elf
                              Arguments:/tmp/Kloki.mips.elf
                              File size:5777432 bytes
                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/tmp/Kloki.mips.elf
                              Arguments:-
                              File size:5777432 bytes
                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/tmp/Kloki.mips.elf
                              Arguments:-
                              File size:5777432 bytes
                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/tmp/Kloki.mips.elf
                              Arguments:-
                              File size:5777432 bytes
                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/usr/libexec/gnome-session-binary
                              Arguments:-
                              File size:334664 bytes
                              MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/bin/sh
                              Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/usr/libexec/gsd-sharing
                              Arguments:/usr/libexec/gsd-sharing
                              File size:35424 bytes
                              MD5 hash:e29d9025d98590fbb69f89fdbd4438b3

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/usr/libexec/gnome-session-binary
                              Arguments:-
                              File size:334664 bytes
                              MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/bin/sh
                              Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/usr/bin/gnome-shell
                              Arguments:/usr/bin/gnome-shell
                              File size:23168 bytes
                              MD5 hash:da7a257239677622fe4b3a65972c9e87

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/usr/libexec/gnome-session-binary
                              Arguments:-
                              File size:334664 bytes
                              MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                              Start time (UTC):02:27:53
                              Start date (UTC):19/01/2025
                              Path:/bin/sh
                              Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/usr/libexec/gnome-session-binary
                              Arguments:-
                              File size:334664 bytes
                              MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/bin/sh
                              Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/usr/sbin/gdm3
                              Arguments:-
                              File size:453296 bytes
                              MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/etc/gdm3/PrimeOff/Default
                              Arguments:/etc/gdm3/PrimeOff/Default
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/usr/sbin/gdm3
                              Arguments:-
                              File size:453296 bytes
                              MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                              Start time (UTC):02:27:54
                              Start date (UTC):19/01/2025
                              Path:/etc/gdm3/PrimeOff/Default
                              Arguments:/etc/gdm3/PrimeOff/Default
                              File size:129816 bytes
                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c