Edit tour

Linux Analysis Report
loki.x86.elf

Overview

General Information

Sample name:loki.x86.elf
Analysis ID:1594500
MD5:d3f5b03d0c1f593d02669ad6c84ce650
SHA1:b6b5361e1b28b1f26519da89a1c71ac7f2c12f6b
SHA256:009ec58219f65cb25abccdcc12c9096aae5ac313605e19ba37634c9676425124
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594500
Start date and time:2025-01-19 03:37:04 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:loki.x86.elf
Detection:MAL
Classification:mal52.linELF@0/0@1/0
Command:/tmp/loki.x86.elf
PID:6249
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • loki.x86.elf (PID: 6249, Parent: 6175, MD5: d3f5b03d0c1f593d02669ad6c84ce650) Arguments: /tmp/loki.x86.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
loki.x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4840:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
loki.x86.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x69d2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
loki.x86.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x88f6:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
loki.x86.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x73b4:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
loki.x86.elfLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x69a2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
SourceRuleDescriptionAuthorStrings
6250.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x4840:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
6250.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x69d2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
6250.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x88f6:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
6250.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x73b4:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
6250.1.0000000008048000.0000000008053000.r-x.sdmpLinux_Trojan_Mirai_8aa7b5d3unknownunknown
  • 0x69a2:$a: 8B 4C 24 14 8B 74 24 0C 8B 5C 24 10 85 C9 74 0D 31 D2 8A 04 1A 88
Click to see the 5 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T03:37:54.625800+010025000342Misc Attack83.222.191.9013566192.168.2.2342750TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: loki.x86.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:52720 -> 83.222.96.67:13566
Source: global trafficTCP traffic: 192.168.2.23:53250 -> 83.222.103.245:13566
Source: global trafficTCP traffic: 192.168.2.23:34580 -> 83.222.87.142:13566
Source: global trafficTCP traffic: 192.168.2.23:59700 -> 83.222.78.237:13566
Source: global trafficTCP traffic: 192.168.2.23:44696 -> 83.222.118.91:13566
Source: global trafficTCP traffic: 192.168.2.23:42110 -> 83.222.140.194:13566
Source: global trafficTCP traffic: 192.168.2.23:54340 -> 83.222.119.76:13566
Source: global trafficTCP traffic: 192.168.2.23:59270 -> 83.222.183.136:13566
Source: global trafficTCP traffic: 192.168.2.23:35972 -> 83.222.152.17:13566
Source: global trafficTCP traffic: 192.168.2.23:54610 -> 83.222.40.112:13566
Source: global trafficTCP traffic: 192.168.2.23:33290 -> 83.222.230.25:13566
Source: global trafficTCP traffic: 192.168.2.23:44848 -> 83.222.212.238:13566
Source: global trafficTCP traffic: 192.168.2.23:34708 -> 83.222.44.150:13566
Source: global trafficTCP traffic: 192.168.2.23:33282 -> 83.222.139.151:13566
Source: global trafficTCP traffic: 192.168.2.23:42160 -> 83.222.204.106:13566
Source: global trafficTCP traffic: 192.168.2.23:51832 -> 83.222.22.21:13566
Source: global trafficTCP traffic: 192.168.2.23:47804 -> 83.222.55.148:13566
Source: global trafficTCP traffic: 192.168.2.23:55878 -> 83.222.244.115:13566
Source: global trafficTCP traffic: 192.168.2.23:36742 -> 83.222.93.129:13566
Source: global trafficTCP traffic: 192.168.2.23:45304 -> 83.222.53.211:13566
Source: global trafficTCP traffic: 192.168.2.23:37818 -> 83.222.215.227:13566
Source: global trafficTCP traffic: 192.168.2.23:43432 -> 83.222.61.4:13566
Source: global trafficTCP traffic: 192.168.2.23:44548 -> 83.222.114.84:13566
Source: global trafficTCP traffic: 192.168.2.23:44410 -> 83.222.26.88:13566
Source: global trafficTCP traffic: 192.168.2.23:60574 -> 83.222.37.112:13566
Source: global trafficTCP traffic: 192.168.2.23:52798 -> 83.222.220.2:13566
Source: global trafficTCP traffic: 192.168.2.23:34722 -> 83.222.109.145:13566
Source: global trafficTCP traffic: 192.168.2.23:39172 -> 83.222.164.36:13566
Source: global trafficTCP traffic: 192.168.2.23:40030 -> 83.222.25.120:13566
Source: global trafficTCP traffic: 192.168.2.23:51522 -> 83.222.19.70:13566
Source: global trafficTCP traffic: 192.168.2.23:43348 -> 83.222.14.74:13566
Source: global trafficTCP traffic: 192.168.2.23:34392 -> 83.222.225.177:13566
Source: global trafficTCP traffic: 192.168.2.23:48738 -> 83.222.125.7:13566
Source: global trafficTCP traffic: 192.168.2.23:35214 -> 83.222.33.113:13566
Source: global trafficTCP traffic: 192.168.2.23:43234 -> 83.222.122.126:13566
Source: global trafficTCP traffic: 192.168.2.23:41382 -> 83.222.242.176:13566
Source: global trafficTCP traffic: 192.168.2.23:56834 -> 83.222.81.206:13566
Source: global trafficTCP traffic: 192.168.2.23:51526 -> 83.222.218.154:13566
Source: global trafficTCP traffic: 192.168.2.23:43800 -> 83.222.211.36:13566
Source: global trafficTCP traffic: 192.168.2.23:58340 -> 83.222.227.237:13566
Source: global trafficTCP traffic: 192.168.2.23:46702 -> 83.222.178.143:13566
Source: global trafficTCP traffic: 192.168.2.23:43288 -> 83.222.124.80:13566
Source: global trafficTCP traffic: 192.168.2.23:51532 -> 83.222.126.32:13566
Source: global trafficTCP traffic: 192.168.2.23:52938 -> 83.222.117.151:13566
Source: global trafficTCP traffic: 192.168.2.23:59228 -> 83.222.153.136:13566
Source: global trafficTCP traffic: 192.168.2.23:35150 -> 83.222.221.167:13566
Source: global trafficTCP traffic: 192.168.2.23:46734 -> 83.222.210.183:13566
Source: global trafficTCP traffic: 192.168.2.23:45488 -> 83.222.65.179:13566
Source: global trafficTCP traffic: 192.168.2.23:51272 -> 83.222.105.190:13566
Source: global trafficTCP traffic: 192.168.2.23:53752 -> 83.222.186.138:13566
Source: global trafficTCP traffic: 192.168.2.23:60654 -> 83.222.9.34:13566
Source: global trafficTCP traffic: 192.168.2.23:60408 -> 83.222.48.53:13566
Source: global trafficTCP traffic: 192.168.2.23:55046 -> 83.222.229.90:13566
Source: global trafficTCP traffic: 192.168.2.23:55770 -> 83.222.241.151:13566
Source: global trafficTCP traffic: 192.168.2.23:35298 -> 83.222.187.204:13566
Source: global trafficTCP traffic: 192.168.2.23:43984 -> 83.222.233.196:13566
Source: global trafficTCP traffic: 192.168.2.23:52980 -> 83.222.29.47:13566
Source: global trafficTCP traffic: 192.168.2.23:57034 -> 83.222.177.55:13566
Source: global trafficTCP traffic: 192.168.2.23:42594 -> 83.222.87.146:13566
Source: global trafficTCP traffic: 192.168.2.23:46012 -> 83.222.198.240:13566
Source: global trafficTCP traffic: 192.168.2.23:56630 -> 83.222.26.164:13566
Source: global trafficTCP traffic: 192.168.2.23:45212 -> 83.222.152.236:13566
Source: global trafficTCP traffic: 192.168.2.23:36630 -> 83.222.91.217:13566
Source: global trafficTCP traffic: 192.168.2.23:36214 -> 83.222.79.200:13566
Source: global trafficTCP traffic: 192.168.2.23:59414 -> 83.222.143.88:13566
Source: global trafficTCP traffic: 192.168.2.23:57270 -> 83.222.234.116:13566
Source: global trafficTCP traffic: 192.168.2.23:45066 -> 83.222.178.219:13566
Source: global trafficTCP traffic: 192.168.2.23:46378 -> 83.222.253.133:13566
Source: global trafficTCP traffic: 192.168.2.23:57758 -> 83.222.127.84:13566
Source: global trafficTCP traffic: 192.168.2.23:49406 -> 83.222.23.70:13566
Source: global trafficTCP traffic: 192.168.2.23:48678 -> 83.222.234.221:13566
Source: global trafficTCP traffic: 192.168.2.23:58244 -> 83.222.159.196:13566
Source: global trafficTCP traffic: 192.168.2.23:42374 -> 83.222.152.90:13566
Source: global trafficTCP traffic: 192.168.2.23:46438 -> 83.222.11.156:13566
Source: global trafficTCP traffic: 192.168.2.23:43104 -> 83.222.159.198:13566
Source: global trafficTCP traffic: 192.168.2.23:54146 -> 83.222.69.49:13566
Source: global trafficTCP traffic: 192.168.2.23:48882 -> 83.222.10.78:13566
Source: global trafficTCP traffic: 192.168.2.23:48964 -> 83.222.104.80:13566
Source: global trafficTCP traffic: 192.168.2.23:49100 -> 83.222.182.189:13566
Source: global trafficTCP traffic: 192.168.2.23:51854 -> 83.222.23.89:13566
Source: global trafficTCP traffic: 192.168.2.23:59242 -> 83.222.22.166:13566
Source: global trafficTCP traffic: 192.168.2.23:43884 -> 83.222.29.69:13566
Source: global trafficTCP traffic: 192.168.2.23:43860 -> 83.222.26.99:13566
Source: global trafficTCP traffic: 192.168.2.23:60366 -> 83.222.177.1:13566
Source: global trafficTCP traffic: 192.168.2.23:51618 -> 83.222.220.37:13566
Source: global trafficTCP traffic: 192.168.2.23:47606 -> 83.222.255.124:13566
Source: global trafficTCP traffic: 192.168.2.23:51588 -> 83.222.235.104:13566
Source: global trafficTCP traffic: 192.168.2.23:36400 -> 83.222.204.232:13566
Source: global trafficTCP traffic: 192.168.2.23:42980 -> 83.222.237.76:13566
Source: global trafficTCP traffic: 192.168.2.23:36190 -> 83.222.60.5:13566
Source: global trafficTCP traffic: 192.168.2.23:53356 -> 83.222.146.129:13566
Source: global trafficTCP traffic: 192.168.2.23:42420 -> 83.222.54.124:13566
Source: global trafficTCP traffic: 192.168.2.23:36418 -> 83.222.94.84:13566
Source: global trafficTCP traffic: 192.168.2.23:56276 -> 83.222.193.21:13566
Source: global trafficTCP traffic: 192.168.2.23:52164 -> 83.222.99.40:13566
Source: global trafficTCP traffic: 192.168.2.23:59846 -> 83.222.36.122:13566
Source: global trafficTCP traffic: 192.168.2.23:51408 -> 83.222.123.232:13566
Source: global trafficTCP traffic: 192.168.2.23:43800 -> 83.222.211.248:13566
Source: global trafficTCP traffic: 192.168.2.23:44286 -> 83.222.206.213:13566
Source: global trafficTCP traffic: 192.168.2.23:49620 -> 83.222.17.203:13566
Source: global trafficTCP traffic: 192.168.2.23:42688 -> 83.222.57.87:13566
Source: global trafficTCP traffic: 192.168.2.23:44252 -> 83.222.13.56:13566
Source: global trafficTCP traffic: 192.168.2.23:36396 -> 83.222.160.160:13566
Source: global trafficTCP traffic: 192.168.2.23:42750 -> 83.222.191.90:13566
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.23:42750
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.96.67
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.103.245
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.87.142
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.78.237
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.118.91
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.140.194
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.119.76
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.183.136
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.152.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.40.112
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.230.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.212.238
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.44.150
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.139.151
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.204.106
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.22.21
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.55.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.115
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.93.129
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.53.211
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.215.227
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.61.4
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.114.84
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.26.88
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.37.112
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.220.2
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.109.145
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.164.36
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.25.120
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.19.70
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.14.74
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.225.177
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.125.7
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.113
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.122.126
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.242.176
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.81.206
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.218.154
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.211.36
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.227.237
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.178.143
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.124.80
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.126.32
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.117.151
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.136
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.221.167
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.65.179
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.105.190
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.186.138
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: loki.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6250.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6249.1.0000000008048000.0000000008053000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: classification engineClassification label: mal52.linELF@0/0@1/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594500 Sample: loki.x86.elf Startdate: 19/01/2025 Architecture: LINUX Score: 52 13 83.222.164.36, 13566, 39172 WAVENETLB Bulgaria 2->13 15 83.222.124.80, 13566, 43288 TRI-ASTrueRecordsIncES Russian Federation 2->15 17 98 other IPs or domains 2->17 19 Malicious sample detected (through community Yara rule) 2->19 21 Machine Learning detection for sample 2->21 7 loki.x86.elf 2->7         started        signatures3 process4 process5 9 loki.x86.elf 7->9         started        11 loki.x86.elf 7->11         started       
SourceDetectionScannerLabelLink
loki.x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.198.240
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.152.17
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.241.151
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.183.136
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.61.4
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.19.70
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.22.166
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.91.217
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.152.90
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.122.126
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.29.47
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.211.248
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.229.90
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.177.1
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.81.206
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.211.36
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.234.116
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    83.222.54.124
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.94.84
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.160.160
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.65.179
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.220.37
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.23.70
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.178.219
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.22.21
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.36.122
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.225.177
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.40.112
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.242.176
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.124.80
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.143.88
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.123.232
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.210.183
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.187.204
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.53.211
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.204.232
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.193.21
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.206.213
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.118.91
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.204.106
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.237.76
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.14.74
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.104.80
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.99.40
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.140.194
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.234.221
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.186.138
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.48.53
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.233.196
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.215.227
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.11.156
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.13.56
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.44.150
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.37.112
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.178.143
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.9.34
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.109.145
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.26.99
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.96.67
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.218.154
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.126.32
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.87.142
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.127.84
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.164.36
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.87.146
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.221.167
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.139.151
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.119.76
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.230.25
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.79.200
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.220.2
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.212.238
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.153.136
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.26.164
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.60.5
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.235.104
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.55.148
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.17.203
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.159.198
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.29.69
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.25.120
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.10.78
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.182.189
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.23.89
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.159.196
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.177.55
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.69.49
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.255.124
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.78.237
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.253.133
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.117.151
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    83.222.244.115
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.57.87
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.93.129
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.146.129
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.33.113
    unknownLuxembourg
    8632LOL-ASluLUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    91.189.91.43Kloki.mips.elfGet hashmaliciousUnknownBrowse
      loki.arm7.elfGet hashmaliciousMiraiBrowse
        na.elfGet hashmaliciousPrometeiBrowse
          loki.arc.elfGet hashmaliciousUnknownBrowse
            Kloki.arm5.elfGet hashmaliciousUnknownBrowse
              Kloki.arm7.elfGet hashmaliciousMiraiBrowse
                arm7.elfGet hashmaliciousUnknownBrowse
                  ppc.elfGet hashmaliciousUnknownBrowse
                    arm.elfGet hashmaliciousUnknownBrowse
                      mips.elfGet hashmaliciousUnknownBrowse
                        91.189.91.42Kloki.mips.elfGet hashmaliciousUnknownBrowse
                          loki.arm7.elfGet hashmaliciousMiraiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              loki.arc.elfGet hashmaliciousUnknownBrowse
                                Kloki.arm5.elfGet hashmaliciousUnknownBrowse
                                  Kloki.arm7.elfGet hashmaliciousMiraiBrowse
                                    arm7.elfGet hashmaliciousUnknownBrowse
                                      ppc.elfGet hashmaliciousUnknownBrowse
                                        arm.elfGet hashmaliciousUnknownBrowse
                                          mips.elfGet hashmaliciousUnknownBrowse
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            secure-network-rebirthltd.ruKloki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            loki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            loki.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 83.222.191.90
                                            Kloki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            loki.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            loki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            loki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            loki.m68k.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.191.90
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            COGECO-PEER1CAKloki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.232.116
                                            loki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.237.134
                                            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.224.99
                                            loki.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 83.222.247.103
                                            Kloki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.224.152
                                            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.243.167
                                            loki.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.228.152
                                            loki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.254.156
                                            loki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.233.216
                                            loki.m68k.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.240.133
                                            SYNTERRA-ASRUKloki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.210.211
                                            loki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.195.162
                                            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.195.159
                                            loki.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 83.222.196.148
                                            Kloki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.194.13
                                            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.195.110
                                            loki.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.206.80
                                            loki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.211.104
                                            loki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.195.237
                                            loki.m68k.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.211.69
                                            GCN-ASGCNAD-SofiaBulgariaBGKloki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.174.216
                                            loki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.175.167
                                            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.176.33
                                            loki.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 83.222.177.157
                                            Kloki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.173.11
                                            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.166.158
                                            loki.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.169.136
                                            loki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.166.153
                                            loki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.169.206
                                            loki.m68k.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.173.171
                                            SENSELAN-ASsenseLANGmbHCHKloki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.128.248
                                            loki.mips.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.140.196
                                            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.135.55
                                            loki.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 83.222.153.195
                                            Kloki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.136.251
                                            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.152.112
                                            loki.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.154.185
                                            loki.i486.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.144.139
                                            loki.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.159.6
                                            loki.m68k.elfGet hashmaliciousUnknownBrowse
                                            • 83.222.155.1
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):6.362189907836288
                                            TrID:
                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                            File name:loki.x86.elf
                                            File size:42'000 bytes
                                            MD5:d3f5b03d0c1f593d02669ad6c84ce650
                                            SHA1:b6b5361e1b28b1f26519da89a1c71ac7f2c12f6b
                                            SHA256:009ec58219f65cb25abccdcc12c9096aae5ac313605e19ba37634c9676425124
                                            SHA512:d0b8189d690ed8dc22b32cd93f545931828a0503266b116cf531ecd598e95c36a24073812b994263e89041f016ae1c96fffc48256a9acde1bdac5eb2f518579c
                                            SSDEEP:768:05mu0Vbue2KZrBnnas5AcRU+UtbjTx+tOoIiWdqAT:05mu0Vbue2KZrpas55RU3tfNkO/iwqAT
                                            TLSH:7F133AC4A813E9F5FC1906752077FB768B77F53A111CE997C3A9E937A842A01E60A34C
                                            File Content Preview:.ELF....................d...4...........4. ...(..............................................0...0......|...........Q.td............................U..S............h....#...[]...$.............U......=@2...t..5.....0......0......u........t....h. ..........

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:Intel 80386
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x8048164
                                            Flags:0x0
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:41600
                                            Section Header Size:40
                                            Number of Section Headers:10
                                            Header String Table Index:9
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x80480940x940x1c0x00x6AX001
                                            .textPROGBITS0x80480b00xb00x98460x00x6AX0016
                                            .finiPROGBITS0x80518f60x98f60x170x00x6AX001
                                            .rodataPROGBITS0x80519200x99200x7800x00x2A0032
                                            .ctorsPROGBITS0x80530a40xa0a40x80x00x3WA004
                                            .dtorsPROGBITS0x80530ac0xa0ac0x80x00x3WA004
                                            .dataPROGBITS0x80530e00xa0e00x1600x00x3WA0032
                                            .bssNOBITS0x80532400xa2400x14e00x00x3WA0032
                                            .shstrtabSTRTAB0x00xa2400x3e0x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x80480000x80480000xa0a00xa0a06.38980x5R E0x1000.init .text .fini .rodata
                                            LOAD0xa0a40x80530a40x80530a40x19c0x167c4.23360x6RW 0x1000.ctors .dtors .data .bss
                                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                            Download Network PCAP: filteredfull

                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2025-01-19T03:37:54.625800+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.2342750TCP
                                            • Total Packets: 224
                                            • 13566 undefined
                                            • 443 (HTTPS)
                                            • 80 (HTTP)
                                            • 53 (DNS)
                                            TimestampSource PortDest PortSource IPDest IP
                                            Jan 19, 2025 03:37:53.178792000 CET43928443192.168.2.2391.189.91.42
                                            Jan 19, 2025 03:37:54.606578112 CET5272013566192.168.2.2383.222.96.67
                                            Jan 19, 2025 03:37:54.606645107 CET5325013566192.168.2.2383.222.103.245
                                            Jan 19, 2025 03:37:54.606642008 CET3458013566192.168.2.2383.222.87.142
                                            Jan 19, 2025 03:37:54.606749058 CET5970013566192.168.2.2383.222.78.237
                                            Jan 19, 2025 03:37:54.606749058 CET4469613566192.168.2.2383.222.118.91
                                            Jan 19, 2025 03:37:54.606750965 CET4211013566192.168.2.2383.222.140.194
                                            Jan 19, 2025 03:37:54.606750965 CET5434013566192.168.2.2383.222.119.76
                                            Jan 19, 2025 03:37:54.606759071 CET5927013566192.168.2.2383.222.183.136
                                            Jan 19, 2025 03:37:54.606781006 CET3597213566192.168.2.2383.222.152.17
                                            Jan 19, 2025 03:37:54.606781006 CET5461013566192.168.2.2383.222.40.112
                                            Jan 19, 2025 03:37:54.606781006 CET3329013566192.168.2.2383.222.230.25
                                            Jan 19, 2025 03:37:54.606791973 CET4484813566192.168.2.2383.222.212.238
                                            Jan 19, 2025 03:37:54.606792927 CET3470813566192.168.2.2383.222.44.150
                                            Jan 19, 2025 03:37:54.606823921 CET3328213566192.168.2.2383.222.139.151
                                            Jan 19, 2025 03:37:54.606842995 CET4216013566192.168.2.2383.222.204.106
                                            Jan 19, 2025 03:37:54.606842995 CET5183213566192.168.2.2383.222.22.21
                                            Jan 19, 2025 03:37:54.606842995 CET4780413566192.168.2.2383.222.55.148
                                            Jan 19, 2025 03:37:54.606858015 CET5587813566192.168.2.2383.222.244.115
                                            Jan 19, 2025 03:37:54.606869936 CET3674213566192.168.2.2383.222.93.129
                                            Jan 19, 2025 03:37:54.606890917 CET4530413566192.168.2.2383.222.53.211
                                            Jan 19, 2025 03:37:54.606899023 CET3781813566192.168.2.2383.222.215.227
                                            Jan 19, 2025 03:37:54.606906891 CET4343213566192.168.2.2383.222.61.4
                                            Jan 19, 2025 03:37:54.606920958 CET4454813566192.168.2.2383.222.114.84
                                            Jan 19, 2025 03:37:54.606933117 CET4441013566192.168.2.2383.222.26.88
                                            Jan 19, 2025 03:37:54.606933117 CET6057413566192.168.2.2383.222.37.112
                                            Jan 19, 2025 03:37:54.606933117 CET5279813566192.168.2.2383.222.220.2
                                            Jan 19, 2025 03:37:54.606950998 CET3472213566192.168.2.2383.222.109.145
                                            Jan 19, 2025 03:37:54.606960058 CET3917213566192.168.2.2383.222.164.36
                                            Jan 19, 2025 03:37:54.606973886 CET4003013566192.168.2.2383.222.25.120
                                            Jan 19, 2025 03:37:54.606990099 CET5152213566192.168.2.2383.222.19.70
                                            Jan 19, 2025 03:37:54.607029915 CET4334813566192.168.2.2383.222.14.74
                                            Jan 19, 2025 03:37:54.607045889 CET3439213566192.168.2.2383.222.225.177
                                            Jan 19, 2025 03:37:54.607054949 CET4873813566192.168.2.2383.222.125.7
                                            Jan 19, 2025 03:37:54.607080936 CET3521413566192.168.2.2383.222.33.113
                                            Jan 19, 2025 03:37:54.607129097 CET4323413566192.168.2.2383.222.122.126
                                            Jan 19, 2025 03:37:54.607129097 CET4138213566192.168.2.2383.222.242.176
                                            Jan 19, 2025 03:37:54.607130051 CET5683413566192.168.2.2383.222.81.206
                                            Jan 19, 2025 03:37:54.607152939 CET5152613566192.168.2.2383.222.218.154
                                            Jan 19, 2025 03:37:54.607156992 CET4380013566192.168.2.2383.222.211.36
                                            Jan 19, 2025 03:37:54.607183933 CET5834013566192.168.2.2383.222.227.237
                                            Jan 19, 2025 03:37:54.607183933 CET4670213566192.168.2.2383.222.178.143
                                            Jan 19, 2025 03:37:54.607208967 CET4328813566192.168.2.2383.222.124.80
                                            Jan 19, 2025 03:37:54.607211113 CET5153213566192.168.2.2383.222.126.32
                                            Jan 19, 2025 03:37:54.607219934 CET5293813566192.168.2.2383.222.117.151
                                            Jan 19, 2025 03:37:54.607234001 CET5922813566192.168.2.2383.222.153.136
                                            Jan 19, 2025 03:37:54.607251883 CET3515013566192.168.2.2383.222.221.167
                                            Jan 19, 2025 03:37:54.607269049 CET4673413566192.168.2.2383.222.210.183
                                            Jan 19, 2025 03:37:54.607306004 CET4548813566192.168.2.2383.222.65.179
                                            Jan 19, 2025 03:37:54.607306004 CET5127213566192.168.2.2383.222.105.190
                                            Jan 19, 2025 03:37:54.607343912 CET5375213566192.168.2.2383.222.186.138
                                            Jan 19, 2025 03:37:54.607347965 CET6065413566192.168.2.2383.222.9.34
                                            Jan 19, 2025 03:37:54.607353926 CET6040813566192.168.2.2383.222.48.53
                                            Jan 19, 2025 03:37:54.607383966 CET5504613566192.168.2.2383.222.229.90
                                            Jan 19, 2025 03:37:54.607383966 CET5577013566192.168.2.2383.222.241.151
                                            Jan 19, 2025 03:37:54.607393980 CET3529813566192.168.2.2383.222.187.204
                                            Jan 19, 2025 03:37:54.607398987 CET4398413566192.168.2.2383.222.233.196
                                            Jan 19, 2025 03:37:54.607423067 CET5298013566192.168.2.2383.222.29.47
                                            Jan 19, 2025 03:37:54.607423067 CET5703413566192.168.2.2383.222.177.55
                                            Jan 19, 2025 03:37:54.607434034 CET4259413566192.168.2.2383.222.87.146
                                            Jan 19, 2025 03:37:54.607445955 CET4601213566192.168.2.2383.222.198.240
                                            Jan 19, 2025 03:37:54.607460022 CET5663013566192.168.2.2383.222.26.164
                                            Jan 19, 2025 03:37:54.607475042 CET4521213566192.168.2.2383.222.152.236
                                            Jan 19, 2025 03:37:54.607482910 CET3663013566192.168.2.2383.222.91.217
                                            Jan 19, 2025 03:37:54.607522011 CET3621413566192.168.2.2383.222.79.200
                                            Jan 19, 2025 03:37:54.607537031 CET5941413566192.168.2.2383.222.143.88
                                            Jan 19, 2025 03:37:54.607553959 CET5727013566192.168.2.2383.222.234.116
                                            Jan 19, 2025 03:37:54.607570887 CET4506613566192.168.2.2383.222.178.219
                                            Jan 19, 2025 03:37:54.607628107 CET4637813566192.168.2.2383.222.253.133
                                            Jan 19, 2025 03:37:54.607637882 CET5775813566192.168.2.2383.222.127.84
                                            Jan 19, 2025 03:37:54.607649088 CET4940613566192.168.2.2383.222.23.70
                                            Jan 19, 2025 03:37:54.607665062 CET4867813566192.168.2.2383.222.234.221
                                            Jan 19, 2025 03:37:54.607669115 CET5824413566192.168.2.2383.222.159.196
                                            Jan 19, 2025 03:37:54.607669115 CET4237413566192.168.2.2383.222.152.90
                                            Jan 19, 2025 03:37:54.607669115 CET4643813566192.168.2.2383.222.11.156
                                            Jan 19, 2025 03:37:54.607669115 CET4310413566192.168.2.2383.222.159.198
                                            Jan 19, 2025 03:37:54.607669115 CET5414613566192.168.2.2383.222.69.49
                                            Jan 19, 2025 03:37:54.607738972 CET4888213566192.168.2.2383.222.10.78
                                            Jan 19, 2025 03:37:54.607742071 CET4896413566192.168.2.2383.222.104.80
                                            Jan 19, 2025 03:37:54.607742071 CET4910013566192.168.2.2383.222.182.189
                                            Jan 19, 2025 03:37:54.607757092 CET5185413566192.168.2.2383.222.23.89
                                            Jan 19, 2025 03:37:54.607788086 CET5924213566192.168.2.2383.222.22.166
                                            Jan 19, 2025 03:37:54.607788086 CET4388413566192.168.2.2383.222.29.69
                                            Jan 19, 2025 03:37:54.607829094 CET4386013566192.168.2.2383.222.26.99
                                            Jan 19, 2025 03:37:54.607832909 CET6036613566192.168.2.2383.222.177.1
                                            Jan 19, 2025 03:37:54.607846975 CET5161813566192.168.2.2383.222.220.37
                                            Jan 19, 2025 03:37:54.607860088 CET4760613566192.168.2.2383.222.255.124
                                            Jan 19, 2025 03:37:54.607867002 CET5158813566192.168.2.2383.222.235.104
                                            Jan 19, 2025 03:37:54.607881069 CET3640013566192.168.2.2383.222.204.232
                                            Jan 19, 2025 03:37:54.607897997 CET4298013566192.168.2.2383.222.237.76
                                            Jan 19, 2025 03:37:54.607911110 CET3619013566192.168.2.2383.222.60.5
                                            Jan 19, 2025 03:37:54.607949018 CET5335613566192.168.2.2383.222.146.129
                                            Jan 19, 2025 03:37:54.607949018 CET4242013566192.168.2.2383.222.54.124
                                            Jan 19, 2025 03:37:54.607974052 CET3641813566192.168.2.2383.222.94.84
                                            Jan 19, 2025 03:37:54.607994080 CET5627613566192.168.2.2383.222.193.21
                                            Jan 19, 2025 03:37:54.608017921 CET5216413566192.168.2.2383.222.99.40
                                            Jan 19, 2025 03:37:54.608028889 CET5984613566192.168.2.2383.222.36.122
                                            Jan 19, 2025 03:37:54.608068943 CET5140813566192.168.2.2383.222.123.232
                                            Jan 19, 2025 03:37:54.608110905 CET4380013566192.168.2.2383.222.211.248
                                            Jan 19, 2025 03:37:54.608117104 CET4428613566192.168.2.2383.222.206.213
                                            Jan 19, 2025 03:37:54.608117104 CET4962013566192.168.2.2383.222.17.203
                                            Jan 19, 2025 03:37:54.608117104 CET4268813566192.168.2.2383.222.57.87
                                            Jan 19, 2025 03:37:54.608118057 CET4425213566192.168.2.2383.222.13.56
                                            Jan 19, 2025 03:37:54.608207941 CET3639613566192.168.2.2383.222.160.160
                                            Jan 19, 2025 03:37:54.611670971 CET135665272083.222.96.67192.168.2.23
                                            Jan 19, 2025 03:37:54.611713886 CET135663458083.222.87.142192.168.2.23
                                            Jan 19, 2025 03:37:54.611728907 CET5272013566192.168.2.2383.222.96.67
                                            Jan 19, 2025 03:37:54.611743927 CET135665325083.222.103.245192.168.2.23
                                            Jan 19, 2025 03:37:54.611766100 CET3458013566192.168.2.2383.222.87.142
                                            Jan 19, 2025 03:37:54.611773014 CET135665970083.222.78.237192.168.2.23
                                            Jan 19, 2025 03:37:54.611804008 CET5325013566192.168.2.2383.222.103.245
                                            Jan 19, 2025 03:37:54.611824036 CET5970013566192.168.2.2383.222.78.237
                                            Jan 19, 2025 03:37:54.611993074 CET135664211083.222.140.194192.168.2.23
                                            Jan 19, 2025 03:37:54.612021923 CET135664469683.222.118.91192.168.2.23
                                            Jan 19, 2025 03:37:54.612044096 CET4211013566192.168.2.2383.222.140.194
                                            Jan 19, 2025 03:37:54.612049103 CET135665434083.222.119.76192.168.2.23
                                            Jan 19, 2025 03:37:54.612066031 CET4469613566192.168.2.2383.222.118.91
                                            Jan 19, 2025 03:37:54.612077951 CET135665927083.222.183.136192.168.2.23
                                            Jan 19, 2025 03:37:54.612097979 CET5434013566192.168.2.2383.222.119.76
                                            Jan 19, 2025 03:37:54.612107038 CET135663470883.222.44.150192.168.2.23
                                            Jan 19, 2025 03:37:54.612118959 CET5927013566192.168.2.2383.222.183.136
                                            Jan 19, 2025 03:37:54.612135887 CET135664484883.222.212.238192.168.2.23
                                            Jan 19, 2025 03:37:54.612152100 CET3470813566192.168.2.2383.222.44.150
                                            Jan 19, 2025 03:37:54.612164974 CET135663328283.222.139.151192.168.2.23
                                            Jan 19, 2025 03:37:54.612184048 CET4484813566192.168.2.2383.222.212.238
                                            Jan 19, 2025 03:37:54.612193108 CET135663597283.222.152.17192.168.2.23
                                            Jan 19, 2025 03:37:54.612206936 CET3328213566192.168.2.2383.222.139.151
                                            Jan 19, 2025 03:37:54.612221003 CET135665587883.222.244.115192.168.2.23
                                            Jan 19, 2025 03:37:54.612247944 CET135665461083.222.40.112192.168.2.23
                                            Jan 19, 2025 03:37:54.612246990 CET3597213566192.168.2.2383.222.152.17
                                            Jan 19, 2025 03:37:54.612260103 CET5587813566192.168.2.2383.222.244.115
                                            Jan 19, 2025 03:37:54.612277031 CET135663674283.222.93.129192.168.2.23
                                            Jan 19, 2025 03:37:54.612304926 CET135664216083.222.204.106192.168.2.23
                                            Jan 19, 2025 03:37:54.612308979 CET5461013566192.168.2.2383.222.40.112
                                            Jan 19, 2025 03:37:54.612318993 CET3674213566192.168.2.2383.222.93.129
                                            Jan 19, 2025 03:37:54.612333059 CET135663329083.222.230.25192.168.2.23
                                            Jan 19, 2025 03:37:54.612350941 CET4216013566192.168.2.2383.222.204.106
                                            Jan 19, 2025 03:37:54.612361908 CET135665183283.222.22.21192.168.2.23
                                            Jan 19, 2025 03:37:54.612382889 CET3329013566192.168.2.2383.222.230.25
                                            Jan 19, 2025 03:37:54.612399101 CET5183213566192.168.2.2383.222.22.21
                                            Jan 19, 2025 03:37:54.612416029 CET135664780483.222.55.148192.168.2.23
                                            Jan 19, 2025 03:37:54.612443924 CET135664530483.222.53.211192.168.2.23
                                            Jan 19, 2025 03:37:54.612471104 CET135663781883.222.215.227192.168.2.23
                                            Jan 19, 2025 03:37:54.612494946 CET4530413566192.168.2.2383.222.53.211
                                            Jan 19, 2025 03:37:54.612498999 CET135664343283.222.61.4192.168.2.23
                                            Jan 19, 2025 03:37:54.612513065 CET3781813566192.168.2.2383.222.215.227
                                            Jan 19, 2025 03:37:54.612526894 CET135664454883.222.114.84192.168.2.23
                                            Jan 19, 2025 03:37:54.612555027 CET135664441083.222.26.88192.168.2.23
                                            Jan 19, 2025 03:37:54.612565041 CET4454813566192.168.2.2383.222.114.84
                                            Jan 19, 2025 03:37:54.612582922 CET135663472283.222.109.145192.168.2.23
                                            Jan 19, 2025 03:37:54.612590075 CET4780413566192.168.2.2383.222.55.148
                                            Jan 19, 2025 03:37:54.612590075 CET4343213566192.168.2.2383.222.61.4
                                            Jan 19, 2025 03:37:54.612595081 CET4441013566192.168.2.2383.222.26.88
                                            Jan 19, 2025 03:37:54.612611055 CET135663917283.222.164.36192.168.2.23
                                            Jan 19, 2025 03:37:54.612627983 CET3472213566192.168.2.2383.222.109.145
                                            Jan 19, 2025 03:37:54.612700939 CET135664003083.222.25.120192.168.2.23
                                            Jan 19, 2025 03:37:54.612713099 CET3917213566192.168.2.2383.222.164.36
                                            Jan 19, 2025 03:37:54.612730026 CET135666057483.222.37.112192.168.2.23
                                            Jan 19, 2025 03:37:54.612741947 CET4003013566192.168.2.2383.222.25.120
                                            Jan 19, 2025 03:37:54.612761021 CET135665152283.222.19.70192.168.2.23
                                            Jan 19, 2025 03:37:54.612790108 CET135665279883.222.220.2192.168.2.23
                                            Jan 19, 2025 03:37:54.612795115 CET6057413566192.168.2.2383.222.37.112
                                            Jan 19, 2025 03:37:54.612813950 CET5152213566192.168.2.2383.222.19.70
                                            Jan 19, 2025 03:37:54.612817049 CET135663439283.222.225.177192.168.2.23
                                            Jan 19, 2025 03:37:54.612845898 CET135664334883.222.14.74192.168.2.23
                                            Jan 19, 2025 03:37:54.612854958 CET3439213566192.168.2.2383.222.225.177
                                            Jan 19, 2025 03:37:54.612860918 CET5279813566192.168.2.2383.222.220.2
                                            Jan 19, 2025 03:37:54.612873077 CET135664873883.222.125.7192.168.2.23
                                            Jan 19, 2025 03:37:54.612900019 CET4334813566192.168.2.2383.222.14.74
                                            Jan 19, 2025 03:37:54.612900972 CET135663521483.222.33.113192.168.2.23
                                            Jan 19, 2025 03:37:54.612916946 CET4873813566192.168.2.2383.222.125.7
                                            Jan 19, 2025 03:37:54.612930059 CET135664323483.222.122.126192.168.2.23
                                            Jan 19, 2025 03:37:54.612942934 CET3521413566192.168.2.2383.222.33.113
                                            Jan 19, 2025 03:37:54.612958908 CET135664138283.222.242.176192.168.2.23
                                            Jan 19, 2025 03:37:54.613008022 CET135665683483.222.81.206192.168.2.23
                                            Jan 19, 2025 03:37:54.613043070 CET135664380083.222.211.36192.168.2.23
                                            Jan 19, 2025 03:37:54.613070965 CET135665152683.222.218.154192.168.2.23
                                            Jan 19, 2025 03:37:54.613085985 CET4380013566192.168.2.2383.222.211.36
                                            Jan 19, 2025 03:37:54.613090038 CET4323413566192.168.2.2383.222.122.126
                                            Jan 19, 2025 03:37:54.613090038 CET4138213566192.168.2.2383.222.242.176
                                            Jan 19, 2025 03:37:54.613090038 CET5683413566192.168.2.2383.222.81.206
                                            Jan 19, 2025 03:37:54.613099098 CET135665834083.222.227.237192.168.2.23
                                            Jan 19, 2025 03:37:54.613126993 CET135664670283.222.178.143192.168.2.23
                                            Jan 19, 2025 03:37:54.613140106 CET5834013566192.168.2.2383.222.227.237
                                            Jan 19, 2025 03:37:54.613154888 CET135665153283.222.126.32192.168.2.23
                                            Jan 19, 2025 03:37:54.613176107 CET4670213566192.168.2.2383.222.178.143
                                            Jan 19, 2025 03:37:54.613183975 CET135664328883.222.124.80192.168.2.23
                                            Jan 19, 2025 03:37:54.613194942 CET5153213566192.168.2.2383.222.126.32
                                            Jan 19, 2025 03:37:54.613204002 CET5152613566192.168.2.2383.222.218.154
                                            Jan 19, 2025 03:37:54.613213062 CET135665293883.222.117.151192.168.2.23
                                            Jan 19, 2025 03:37:54.613231897 CET4328813566192.168.2.2383.222.124.80
                                            Jan 19, 2025 03:37:54.613240957 CET135665922883.222.153.136192.168.2.23
                                            Jan 19, 2025 03:37:54.613255978 CET5293813566192.168.2.2383.222.117.151
                                            Jan 19, 2025 03:37:54.613269091 CET135663515083.222.221.167192.168.2.23
                                            Jan 19, 2025 03:37:54.613286018 CET5922813566192.168.2.2383.222.153.136
                                            Jan 19, 2025 03:37:54.613296032 CET135664673483.222.210.183192.168.2.23
                                            Jan 19, 2025 03:37:54.613320112 CET3515013566192.168.2.2383.222.221.167
                                            Jan 19, 2025 03:37:54.613325119 CET135664548883.222.65.179192.168.2.23
                                            Jan 19, 2025 03:37:54.613353968 CET135665127283.222.105.190192.168.2.23
                                            Jan 19, 2025 03:37:54.613382101 CET135666065483.222.9.34192.168.2.23
                                            Jan 19, 2025 03:37:54.613409996 CET135665375283.222.186.138192.168.2.23
                                            Jan 19, 2025 03:37:54.613420010 CET6065413566192.168.2.2383.222.9.34
                                            Jan 19, 2025 03:37:54.613437891 CET135666040883.222.48.53192.168.2.23
                                            Jan 19, 2025 03:37:54.613457918 CET5375213566192.168.2.2383.222.186.138
                                            Jan 19, 2025 03:37:54.613466024 CET135663529883.222.187.204192.168.2.23
                                            Jan 19, 2025 03:37:54.613460064 CET4673413566192.168.2.2383.222.210.183
                                            Jan 19, 2025 03:37:54.613460064 CET4548813566192.168.2.2383.222.65.179
                                            Jan 19, 2025 03:37:54.613461018 CET5127213566192.168.2.2383.222.105.190
                                            Jan 19, 2025 03:37:54.613488913 CET6040813566192.168.2.2383.222.48.53
                                            Jan 19, 2025 03:37:54.613495111 CET135665504683.222.229.90192.168.2.23
                                            Jan 19, 2025 03:37:54.613506079 CET3529813566192.168.2.2383.222.187.204
                                            Jan 19, 2025 03:37:54.613526106 CET135665577083.222.241.151192.168.2.23
                                            Jan 19, 2025 03:37:54.613537073 CET5504613566192.168.2.2383.222.229.90
                                            Jan 19, 2025 03:37:54.613558054 CET135664398483.222.233.196192.168.2.23
                                            Jan 19, 2025 03:37:54.613564014 CET5577013566192.168.2.2383.222.241.151
                                            Jan 19, 2025 03:37:54.613594055 CET135665298083.222.29.47192.168.2.23
                                            Jan 19, 2025 03:37:54.613606930 CET4398413566192.168.2.2383.222.233.196
                                            Jan 19, 2025 03:37:54.613621950 CET135665703483.222.177.55192.168.2.23
                                            Jan 19, 2025 03:37:54.613641024 CET5298013566192.168.2.2383.222.29.47
                                            Jan 19, 2025 03:37:54.613651037 CET135664259483.222.87.146192.168.2.23
                                            Jan 19, 2025 03:37:54.613662004 CET5703413566192.168.2.2383.222.177.55
                                            Jan 19, 2025 03:37:54.613678932 CET135664601283.222.198.240192.168.2.23
                                            Jan 19, 2025 03:37:54.613692045 CET4259413566192.168.2.2383.222.87.146
                                            Jan 19, 2025 03:37:54.613706112 CET135665663083.222.26.164192.168.2.23
                                            Jan 19, 2025 03:37:54.613719940 CET4601213566192.168.2.2383.222.198.240
                                            Jan 19, 2025 03:37:54.613734961 CET135664521283.222.152.236192.168.2.23
                                            Jan 19, 2025 03:37:54.613745928 CET5663013566192.168.2.2383.222.26.164
                                            Jan 19, 2025 03:37:54.613764048 CET135663663083.222.91.217192.168.2.23
                                            Jan 19, 2025 03:37:54.613784075 CET4521213566192.168.2.2383.222.152.236
                                            Jan 19, 2025 03:37:54.613791943 CET135663621483.222.79.200192.168.2.23
                                            Jan 19, 2025 03:37:54.613810062 CET3663013566192.168.2.2383.222.91.217
                                            Jan 19, 2025 03:37:54.613820076 CET135665941483.222.143.88192.168.2.23
                                            Jan 19, 2025 03:37:54.613837004 CET3621413566192.168.2.2383.222.79.200
                                            Jan 19, 2025 03:37:54.613847971 CET135665727083.222.234.116192.168.2.23
                                            Jan 19, 2025 03:37:54.613861084 CET5941413566192.168.2.2383.222.143.88
                                            Jan 19, 2025 03:37:54.613876104 CET135664506683.222.178.219192.168.2.23
                                            Jan 19, 2025 03:37:54.613889933 CET5727013566192.168.2.2383.222.234.116
                                            Jan 19, 2025 03:37:54.613903046 CET135664637883.222.253.133192.168.2.23
                                            Jan 19, 2025 03:37:54.613922119 CET4506613566192.168.2.2383.222.178.219
                                            Jan 19, 2025 03:37:54.613930941 CET135665775883.222.127.84192.168.2.23
                                            Jan 19, 2025 03:37:54.613948107 CET4637813566192.168.2.2383.222.253.133
                                            Jan 19, 2025 03:37:54.613959074 CET135664940683.222.23.70192.168.2.23
                                            Jan 19, 2025 03:37:54.613976002 CET5775813566192.168.2.2383.222.127.84
                                            Jan 19, 2025 03:37:54.613986015 CET135664867883.222.234.221192.168.2.23
                                            Jan 19, 2025 03:37:54.613997936 CET4940613566192.168.2.2383.222.23.70
                                            Jan 19, 2025 03:37:54.614013910 CET135664888283.222.10.78192.168.2.23
                                            Jan 19, 2025 03:37:54.614032030 CET4867813566192.168.2.2383.222.234.221
                                            Jan 19, 2025 03:37:54.614042997 CET135665824483.222.159.196192.168.2.23
                                            Jan 19, 2025 03:37:54.614056110 CET4888213566192.168.2.2383.222.10.78
                                            Jan 19, 2025 03:37:54.614070892 CET135664237483.222.152.90192.168.2.23
                                            Jan 19, 2025 03:37:54.614097118 CET5824413566192.168.2.2383.222.159.196
                                            Jan 19, 2025 03:37:54.614101887 CET135665185483.222.23.89192.168.2.23
                                            Jan 19, 2025 03:37:54.614129066 CET4237413566192.168.2.2383.222.152.90
                                            Jan 19, 2025 03:37:54.614147902 CET135664643883.222.11.156192.168.2.23
                                            Jan 19, 2025 03:37:54.614161968 CET5185413566192.168.2.2383.222.23.89
                                            Jan 19, 2025 03:37:54.614208937 CET4643813566192.168.2.2383.222.11.156
                                            Jan 19, 2025 03:37:54.617860079 CET135664310483.222.159.198192.168.2.23
                                            Jan 19, 2025 03:37:54.617888927 CET135665414683.222.69.49192.168.2.23
                                            Jan 19, 2025 03:37:54.617916107 CET135664388483.222.29.69192.168.2.23
                                            Jan 19, 2025 03:37:54.617943048 CET135665924283.222.22.166192.168.2.23
                                            Jan 19, 2025 03:37:54.617969990 CET135664896483.222.104.80192.168.2.23
                                            Jan 19, 2025 03:37:54.617989063 CET5924213566192.168.2.2383.222.22.166
                                            Jan 19, 2025 03:37:54.617996931 CET135664910083.222.182.189192.168.2.23
                                            Jan 19, 2025 03:37:54.618025064 CET135664386083.222.26.99192.168.2.23
                                            Jan 19, 2025 03:37:54.618031979 CET4896413566192.168.2.2383.222.104.80
                                            Jan 19, 2025 03:37:54.618031979 CET4910013566192.168.2.2383.222.182.189
                                            Jan 19, 2025 03:37:54.618052959 CET135666036683.222.177.1192.168.2.23
                                            Jan 19, 2025 03:37:54.618046999 CET4310413566192.168.2.2383.222.159.198
                                            Jan 19, 2025 03:37:54.618046999 CET5414613566192.168.2.2383.222.69.49
                                            Jan 19, 2025 03:37:54.618047953 CET4388413566192.168.2.2383.222.29.69
                                            Jan 19, 2025 03:37:54.618067980 CET4386013566192.168.2.2383.222.26.99
                                            Jan 19, 2025 03:37:54.618081093 CET135665161883.222.220.37192.168.2.23
                                            Jan 19, 2025 03:37:54.618113041 CET135665158883.222.235.104192.168.2.23
                                            Jan 19, 2025 03:37:54.618113041 CET6036613566192.168.2.2383.222.177.1
                                            Jan 19, 2025 03:37:54.618133068 CET5161813566192.168.2.2383.222.220.37
                                            Jan 19, 2025 03:37:54.618143082 CET135664760683.222.255.124192.168.2.23
                                            Jan 19, 2025 03:37:54.618170023 CET135663640083.222.204.232192.168.2.23
                                            Jan 19, 2025 03:37:54.618191004 CET4760613566192.168.2.2383.222.255.124
                                            Jan 19, 2025 03:37:54.618196964 CET135664298083.222.237.76192.168.2.23
                                            Jan 19, 2025 03:37:54.618210077 CET3640013566192.168.2.2383.222.204.232
                                            Jan 19, 2025 03:37:54.618225098 CET135663619083.222.60.5192.168.2.23
                                            Jan 19, 2025 03:37:54.618252993 CET135665335683.222.146.129192.168.2.23
                                            Jan 19, 2025 03:37:54.618279934 CET135663641883.222.94.84192.168.2.23
                                            Jan 19, 2025 03:37:54.618305922 CET135664242083.222.54.124192.168.2.23
                                            Jan 19, 2025 03:37:54.618313074 CET5335613566192.168.2.2383.222.146.129
                                            Jan 19, 2025 03:37:54.618324995 CET5158813566192.168.2.2383.222.235.104
                                            Jan 19, 2025 03:37:54.618324995 CET4298013566192.168.2.2383.222.237.76
                                            Jan 19, 2025 03:37:54.618324995 CET3619013566192.168.2.2383.222.60.5
                                            Jan 19, 2025 03:37:54.618334055 CET135665627683.222.193.21192.168.2.23
                                            Jan 19, 2025 03:37:54.618346930 CET3641813566192.168.2.2383.222.94.84
                                            Jan 19, 2025 03:37:54.618351936 CET4242013566192.168.2.2383.222.54.124
                                            Jan 19, 2025 03:37:54.618366003 CET135665216483.222.99.40192.168.2.23
                                            Jan 19, 2025 03:37:54.618382931 CET5627613566192.168.2.2383.222.193.21
                                            Jan 19, 2025 03:37:54.618397951 CET135665984683.222.36.122192.168.2.23
                                            Jan 19, 2025 03:37:54.618410110 CET5216413566192.168.2.2383.222.99.40
                                            Jan 19, 2025 03:37:54.618427992 CET135665140883.222.123.232192.168.2.23
                                            Jan 19, 2025 03:37:54.618454933 CET135664380083.222.211.248192.168.2.23
                                            Jan 19, 2025 03:37:54.618483067 CET135664428683.222.206.213192.168.2.23
                                            Jan 19, 2025 03:37:54.618501902 CET4380013566192.168.2.2383.222.211.248
                                            Jan 19, 2025 03:37:54.618509054 CET135664268883.222.57.87192.168.2.23
                                            Jan 19, 2025 03:37:54.618537903 CET135664962083.222.17.203192.168.2.23
                                            Jan 19, 2025 03:37:54.618566036 CET135663639683.222.160.160192.168.2.23
                                            Jan 19, 2025 03:37:54.618570089 CET5984613566192.168.2.2383.222.36.122
                                            Jan 19, 2025 03:37:54.618571997 CET4428613566192.168.2.2383.222.206.213
                                            Jan 19, 2025 03:37:54.618570089 CET5140813566192.168.2.2383.222.123.232
                                            Jan 19, 2025 03:37:54.618571997 CET4268813566192.168.2.2383.222.57.87
                                            Jan 19, 2025 03:37:54.618587017 CET4962013566192.168.2.2383.222.17.203
                                            Jan 19, 2025 03:37:54.618592978 CET135664425283.222.13.56192.168.2.23
                                            Jan 19, 2025 03:37:54.618614912 CET3639613566192.168.2.2383.222.160.160
                                            Jan 19, 2025 03:37:54.618635893 CET4425213566192.168.2.2383.222.13.56
                                            Jan 19, 2025 03:37:54.620974064 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:37:54.625799894 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:37:54.625983000 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:37:54.625983000 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:37:54.630947113 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:37:54.631135941 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:37:54.636183023 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:37:58.810249090 CET42836443192.168.2.2391.189.91.43
                                            Jan 19, 2025 03:37:59.578181028 CET4251680192.168.2.23109.202.202.202
                                            Jan 19, 2025 03:38:04.633486032 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:38:04.638787985 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:38:04.837249041 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:38:04.837678909 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:38:05.207526922 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:38:05.207762957 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:38:14.680115938 CET43928443192.168.2.2391.189.91.42
                                            Jan 19, 2025 03:38:24.918772936 CET42836443192.168.2.2391.189.91.43
                                            Jan 19, 2025 03:38:29.013962030 CET4251680192.168.2.23109.202.202.202
                                            Jan 19, 2025 03:38:55.634637117 CET43928443192.168.2.2391.189.91.42
                                            Jan 19, 2025 03:39:05.257297993 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:39:05.262435913 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:39:05.460933924 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:39:05.461345911 CET4275013566192.168.2.2383.222.191.90
                                            Jan 19, 2025 03:39:06.207020998 CET135664275083.222.191.90192.168.2.23
                                            Jan 19, 2025 03:39:06.207257032 CET4275013566192.168.2.2383.222.191.90
                                            TimestampSource PortDest PortSource IPDest IP
                                            Jan 19, 2025 03:37:54.608160019 CET3725653192.168.2.238.8.8.8
                                            Jan 19, 2025 03:37:54.620860100 CET53372568.8.8.8192.168.2.23
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Jan 19, 2025 03:37:54.608160019 CET192.168.2.238.8.8.80x3ed2Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Jan 19, 2025 03:37:54.620860100 CET8.8.8.8192.168.2.230x3ed2No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):02:37:53
                                            Start date (UTC):19/01/2025
                                            Path:/tmp/loki.x86.elf
                                            Arguments:/tmp/loki.x86.elf
                                            File size:42000 bytes
                                            MD5 hash:d3f5b03d0c1f593d02669ad6c84ce650

                                            Start time (UTC):02:37:53
                                            Start date (UTC):19/01/2025
                                            Path:/tmp/loki.x86.elf
                                            Arguments:-
                                            File size:42000 bytes
                                            MD5 hash:d3f5b03d0c1f593d02669ad6c84ce650

                                            Start time (UTC):02:37:54
                                            Start date (UTC):19/01/2025
                                            Path:/tmp/loki.x86.elf
                                            Arguments:-
                                            File size:42000 bytes
                                            MD5 hash:d3f5b03d0c1f593d02669ad6c84ce650