Edit tour

Linux Analysis Report
Kloki.m68k.elf

Overview

General Information

Sample name:Kloki.m68k.elf
Analysis ID:1594504
MD5:bf454dc9a0f3d7b0584d124c0f12afe6
SHA1:a9a36cb8937958a661b1ea7f1adff9a9c30199f9
SHA256:fffaeb9914819e087339e1dab864af51cbd9f609df26f651ce51ef19fd8d879e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594504
Start date and time:2025-01-19 03:47:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.m68k.elf
Detection:MAL
Classification:mal52.spre.linELF@0/0@1/0
Command:/tmp/Kloki.m68k.elf
PID:5487
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5496, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • sh (PID: 5521, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 5521, Parent: 1383, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 5522, Parent: 1383, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gdm3 New Fork (PID: 5524, Parent: 1289)
  • Default (PID: 5524, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 5529, Parent: 1289)
  • Default (PID: 5529, Parent: 1289, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 5535, Parent: 1)
  • systemd-user-runtime-dir (PID: 5535, Parent: 1, MD5: d55f4b0847f88131dbcfb07435178e54) Arguments: /lib/systemd/systemd-user-runtime-dir stop 127
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T03:48:03.127135+010025000342Misc Attack83.222.191.9013566192.168.2.1456540TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.m68k.elfVirustotal: Detection: 30%Perma Link
Source: Kloki.m68k.elfString: ppid/proc/net/tcp/proc/self/exe/proc//status/fd//dev/null/dev/consolesocket05/proc/%d/exepkillkillallechowgetcurlpsbusyboxiptablesrebootshutdownhaltpoweroffsystemctltelinitcatgrepbashzshcshkshdashfish
Source: global trafficTCP traffic: 192.168.2.14:37376 -> 83.222.38.239:13566
Source: global trafficTCP traffic: 192.168.2.14:40052 -> 83.222.235.14:13566
Source: global trafficTCP traffic: 192.168.2.14:47918 -> 83.222.213.79:13566
Source: global trafficTCP traffic: 192.168.2.14:48682 -> 83.222.49.198:13566
Source: global trafficTCP traffic: 192.168.2.14:38160 -> 83.222.92.197:13566
Source: global trafficTCP traffic: 192.168.2.14:59376 -> 83.222.173.121:13566
Source: global trafficTCP traffic: 192.168.2.14:33166 -> 83.222.126.66:13566
Source: global trafficTCP traffic: 192.168.2.14:53526 -> 83.222.120.103:13566
Source: global trafficTCP traffic: 192.168.2.14:56376 -> 83.222.152.50:13566
Source: global trafficTCP traffic: 192.168.2.14:42548 -> 83.222.167.50:13566
Source: global trafficTCP traffic: 192.168.2.14:52654 -> 83.222.163.80:13566
Source: global trafficTCP traffic: 192.168.2.14:55960 -> 83.222.168.98:13566
Source: global trafficTCP traffic: 192.168.2.14:35342 -> 83.222.168.31:13566
Source: global trafficTCP traffic: 192.168.2.14:47176 -> 83.222.34.172:13566
Source: global trafficTCP traffic: 192.168.2.14:56414 -> 83.222.184.42:13566
Source: global trafficTCP traffic: 192.168.2.14:33636 -> 83.222.91.222:13566
Source: global trafficTCP traffic: 192.168.2.14:52876 -> 83.222.25.70:13566
Source: global trafficTCP traffic: 192.168.2.14:32860 -> 83.222.237.238:13566
Source: global trafficTCP traffic: 192.168.2.14:33140 -> 83.222.150.30:13566
Source: global trafficTCP traffic: 192.168.2.14:58216 -> 83.222.180.242:13566
Source: global trafficTCP traffic: 192.168.2.14:43894 -> 83.222.228.97:13566
Source: global trafficTCP traffic: 192.168.2.14:45962 -> 83.222.108.98:13566
Source: global trafficTCP traffic: 192.168.2.14:57274 -> 83.222.163.228:13566
Source: global trafficTCP traffic: 192.168.2.14:56184 -> 83.222.201.60:13566
Source: global trafficTCP traffic: 192.168.2.14:51746 -> 83.222.23.112:13566
Source: global trafficTCP traffic: 192.168.2.14:43992 -> 83.222.110.186:13566
Source: global trafficTCP traffic: 192.168.2.14:57750 -> 83.222.192.22:13566
Source: global trafficTCP traffic: 192.168.2.14:35270 -> 83.222.28.104:13566
Source: global trafficTCP traffic: 192.168.2.14:47706 -> 83.222.53.62:13566
Source: global trafficTCP traffic: 192.168.2.14:50562 -> 83.222.20.238:13566
Source: global trafficTCP traffic: 192.168.2.14:60584 -> 83.222.104.112:13566
Source: global trafficTCP traffic: 192.168.2.14:58714 -> 83.222.204.129:13566
Source: global trafficTCP traffic: 192.168.2.14:40572 -> 83.222.182.185:13566
Source: global trafficTCP traffic: 192.168.2.14:42128 -> 83.222.111.76:13566
Source: global trafficTCP traffic: 192.168.2.14:42080 -> 83.222.216.35:13566
Source: global trafficTCP traffic: 192.168.2.14:60196 -> 83.222.63.188:13566
Source: global trafficTCP traffic: 192.168.2.14:39038 -> 83.222.132.171:13566
Source: global trafficTCP traffic: 192.168.2.14:52470 -> 83.222.30.40:13566
Source: global trafficTCP traffic: 192.168.2.14:39674 -> 83.222.143.231:13566
Source: global trafficTCP traffic: 192.168.2.14:58456 -> 83.222.100.166:13566
Source: global trafficTCP traffic: 192.168.2.14:38340 -> 83.222.88.210:13566
Source: global trafficTCP traffic: 192.168.2.14:48246 -> 83.222.96.24:13566
Source: global trafficTCP traffic: 192.168.2.14:59208 -> 83.222.232.124:13566
Source: global trafficTCP traffic: 192.168.2.14:36742 -> 83.222.129.29:13566
Source: global trafficTCP traffic: 192.168.2.14:34570 -> 83.222.186.149:13566
Source: global trafficTCP traffic: 192.168.2.14:60898 -> 83.222.11.34:13566
Source: global trafficTCP traffic: 192.168.2.14:37622 -> 83.222.5.216:13566
Source: global trafficTCP traffic: 192.168.2.14:56130 -> 83.222.163.188:13566
Source: global trafficTCP traffic: 192.168.2.14:54526 -> 83.222.145.18:13566
Source: global trafficTCP traffic: 192.168.2.14:51736 -> 83.222.8.105:13566
Source: global trafficTCP traffic: 192.168.2.14:52026 -> 83.222.53.71:13566
Source: global trafficTCP traffic: 192.168.2.14:37738 -> 83.222.37.186:13566
Source: global trafficTCP traffic: 192.168.2.14:57406 -> 83.222.242.67:13566
Source: global trafficTCP traffic: 192.168.2.14:38902 -> 83.222.226.130:13566
Source: global trafficTCP traffic: 192.168.2.14:53886 -> 83.222.43.70:13566
Source: global trafficTCP traffic: 192.168.2.14:52396 -> 83.222.40.131:13566
Source: global trafficTCP traffic: 192.168.2.14:56966 -> 83.222.24.137:13566
Source: global trafficTCP traffic: 192.168.2.14:45558 -> 83.222.155.0:13566
Source: global trafficTCP traffic: 192.168.2.14:58906 -> 83.222.5.28:13566
Source: global trafficTCP traffic: 192.168.2.14:56866 -> 83.222.29.192:13566
Source: global trafficTCP traffic: 192.168.2.14:53950 -> 83.222.178.41:13566
Source: global trafficTCP traffic: 192.168.2.14:45930 -> 83.222.226.183:13566
Source: global trafficTCP traffic: 192.168.2.14:50742 -> 83.222.1.134:13566
Source: global trafficTCP traffic: 192.168.2.14:40090 -> 83.222.115.146:13566
Source: global trafficTCP traffic: 192.168.2.14:43030 -> 83.222.152.124:13566
Source: global trafficTCP traffic: 192.168.2.14:57026 -> 83.222.252.206:13566
Source: global trafficTCP traffic: 192.168.2.14:50592 -> 83.222.195.33:13566
Source: global trafficTCP traffic: 192.168.2.14:51544 -> 83.222.136.182:13566
Source: global trafficTCP traffic: 192.168.2.14:57446 -> 83.222.101.106:13566
Source: global trafficTCP traffic: 192.168.2.14:42592 -> 83.222.56.144:13566
Source: global trafficTCP traffic: 192.168.2.14:42752 -> 83.222.176.96:13566
Source: global trafficTCP traffic: 192.168.2.14:53506 -> 83.222.19.200:13566
Source: global trafficTCP traffic: 192.168.2.14:45816 -> 83.222.233.174:13566
Source: global trafficTCP traffic: 192.168.2.14:33962 -> 83.222.200.239:13566
Source: global trafficTCP traffic: 192.168.2.14:45668 -> 83.222.203.229:13566
Source: global trafficTCP traffic: 192.168.2.14:47870 -> 83.222.175.125:13566
Source: global trafficTCP traffic: 192.168.2.14:54742 -> 83.222.14.145:13566
Source: global trafficTCP traffic: 192.168.2.14:52166 -> 83.222.52.15:13566
Source: global trafficTCP traffic: 192.168.2.14:36798 -> 83.222.23.168:13566
Source: global trafficTCP traffic: 192.168.2.14:44866 -> 83.222.162.176:13566
Source: global trafficTCP traffic: 192.168.2.14:40294 -> 83.222.36.158:13566
Source: global trafficTCP traffic: 192.168.2.14:45606 -> 83.222.126.231:13566
Source: global trafficTCP traffic: 192.168.2.14:58972 -> 83.222.191.6:13566
Source: global trafficTCP traffic: 192.168.2.14:38108 -> 83.222.157.36:13566
Source: global trafficTCP traffic: 192.168.2.14:57816 -> 83.222.112.213:13566
Source: global trafficTCP traffic: 192.168.2.14:44496 -> 83.222.180.32:13566
Source: global trafficTCP traffic: 192.168.2.14:47882 -> 83.222.54.199:13566
Source: global trafficTCP traffic: 192.168.2.14:38748 -> 83.222.232.31:13566
Source: global trafficTCP traffic: 192.168.2.14:40784 -> 83.222.118.176:13566
Source: global trafficTCP traffic: 192.168.2.14:40596 -> 83.222.14.65:13566
Source: global trafficTCP traffic: 192.168.2.14:46720 -> 83.222.149.189:13566
Source: global trafficTCP traffic: 192.168.2.14:42912 -> 83.222.190.164:13566
Source: global trafficTCP traffic: 192.168.2.14:52900 -> 83.222.79.242:13566
Source: global trafficTCP traffic: 192.168.2.14:32918 -> 83.222.179.102:13566
Source: global trafficTCP traffic: 192.168.2.14:44368 -> 83.222.154.85:13566
Source: global trafficTCP traffic: 192.168.2.14:54202 -> 83.222.22.190:13566
Source: global trafficTCP traffic: 192.168.2.14:32824 -> 83.222.243.148:13566
Source: global trafficTCP traffic: 192.168.2.14:38542 -> 83.222.166.179:13566
Source: global trafficTCP traffic: 192.168.2.14:47758 -> 83.222.154.67:13566
Source: global trafficTCP traffic: 192.168.2.14:56540 -> 83.222.191.90:13566
Source: /tmp/Kloki.m68k.elf (PID: 5487)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.14:56540
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.38.239
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.38.239
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.38.239
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.38.239
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.235.14
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.235.14
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.235.14
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.235.14
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.49.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.92.197
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.92.197
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.173.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.173.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.126.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.126.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.126.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.120.103
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.120.103
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.152.50
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.152.50
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.167.50
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.126.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.167.50
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.163.80
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.163.80
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.98
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.98
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.34.172
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.34.172
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.91.222
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.25.70
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.91.222
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.25.70
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.237.238
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.237.238
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru

System Summary

barindex
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5471, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5496, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5521, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5522, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5523, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5529, result: successfulJump to behavior
Source: Initial sampleString containing 'busybox' found: busybox
Source: Initial sampleString containing 'busybox' found: ppid/proc/net/tcp/proc/self/exe/proc//status/fd//dev/null/dev/consolesocket05/proc/%d/exepkillkillallechowgetcurlpsbusyboxiptablesrebootshutdownhaltpoweroffsystemctltelinitcatgrepbashzshcshkshdashfish
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 917, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 928, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 940, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1444, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1610, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 1639, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 3094, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 3268, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 3420, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5471, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5496, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5521, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5522, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5523, result: successfulJump to behavior
Source: /tmp/Kloki.m68k.elf (PID: 5494)SIGKILL sent: pid: 5529, result: successfulJump to behavior
Source: classification engineClassification label: mal52.spre.linELF@0/0@1/0
Source: /tmp/Kloki.m68k.elf (PID: 5487)Queries kernel information via 'uname': Jump to behavior
Source: Kloki.m68k.elf, 5487.1.00007ffe7ae2e000.00007ffe7ae4f000.rw-.sdmp, Kloki.m68k.elf, 5489.1.00007ffe7ae2e000.00007ffe7ae4f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
Source: Kloki.m68k.elf, 5487.1.0000561685b85000.0000561685c0f000.rw-.sdmp, Kloki.m68k.elf, 5489.1.0000561685b85000.0000561685be9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
Source: Kloki.m68k.elf, 5487.1.00007ffe7ae2e000.00007ffe7ae4f000.rw-.sdmp, Kloki.m68k.elf, 5489.1.00007ffe7ae2e000.00007ffe7ae4f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/Kloki.m68k.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Kloki.m68k.elf
Source: Kloki.m68k.elf, 5487.1.0000561685b85000.0000561685c0f000.rw-.sdmp, Kloki.m68k.elf, 5489.1.0000561685b85000.0000561685be9000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/m68k
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594504 Sample: Kloki.m68k.elf Startdate: 19/01/2025 Architecture: LINUX Score: 52 23 83.222.162.176, 13566, 44866 WAVENETLB Bulgaria 2->23 25 83.222.163.188, 13566, 56130 WAVENETLB Bulgaria 2->25 27 98 other IPs or domains 2->27 29 Multi AV Scanner detection for submitted file 2->29 8 Kloki.m68k.elf 2->8         started        10 gnome-session-binary sh gnome-shell 2->10         started        12 gnome-session-binary sh 2->12         started        14 5 other processes 2->14 signatures3 process4 process5 16 Kloki.m68k.elf 8->16         started        18 Kloki.m68k.elf 8->18         started        process6 20 Kloki.m68k.elf 16->20         started        signatures7 31 Sample tries to kill multiple processes (SIGKILL) 20->31
SourceDetectionScannerLabelLink
Kloki.m68k.elf30%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.166.179
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.5.216
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.54.199
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.14.65
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.173.121
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.108.98
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.43.70
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.34.172
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.91.222
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.190.164
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.182.185
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.30.40
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.168.31
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.28.104
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.96.24
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.180.32
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.19.200
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.143.231
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.243.148
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.163.228
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.38.239
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.120.103
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.157.36
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.79.242
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.226.183
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.163.188
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.195.33
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.167.50
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.228.97
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.92.197
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.56.144
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.232.124
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.191.6
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.226.130
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.49.198
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.23.112
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.163.80
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.136.182
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.201.60
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.104.112
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.110.186
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.175.125
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.168.98
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.112.213
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.149.189
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.179.102
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.25.70
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.5.28
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.216.35
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.24.137
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.8.105
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.40.131
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.180.242
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.52.15
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.29.192
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.184.42
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.36.158
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.53.71
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.200.239
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.186.149
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.178.41
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.150.30
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.152.50
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.129.29
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.204.129
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.237.238
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.101.106
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.111.76
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.63.188
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.118.176
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.53.62
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.14.145
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.145.18
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.252.206
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.176.96
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.115.146
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.126.231
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.23.168
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.154.85
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.233.174
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.126.66
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.232.31
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.162.176
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.100.166
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.1.134
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.213.79
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.88.210
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.155.0
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.152.124
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.235.14
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.37.186
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.132.171
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.203.229
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.22.190
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.242.67
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.11.34
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.20.238
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.154.67
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.192.22
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.163.228Kloki.x86_64.elfGet hashmaliciousUnknownBrowse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      secure-network-rebirthltd.ruKloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.191.90
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.mpsl.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      LOL-ASluLUKloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.33.113
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.33.113
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.46.188
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.45.23
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.41.144
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.39.173
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.39.107
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.59.20
      loki.mpsl.elfGet hashmaliciousUnknownBrowse
      • 83.222.55.216
      loki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.48.106
      GCN-ASGCNAD-SofiaBulgariaBGKloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.177.55
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.177.55
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.174.216
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.175.167
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.176.33
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.177.157
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.173.11
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.166.158
      loki.mpsl.elfGet hashmaliciousUnknownBrowse
      • 83.222.169.136
      loki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.166.153
      MASTERHOST-ASMoscowRussiaRUKloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.23.89
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.23.89
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.31.69
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.9.65
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.28.56
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.9.29
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.15.96
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.17.204
      loki.mpsl.elfGet hashmaliciousUnknownBrowse
      • 83.222.5.145
      loki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.19.56
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
      Entropy (8bit):6.233868976547386
      TrID:
      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
      File name:Kloki.m68k.elf
      File size:67'480 bytes
      MD5:bf454dc9a0f3d7b0584d124c0f12afe6
      SHA1:a9a36cb8937958a661b1ea7f1adff9a9c30199f9
      SHA256:fffaeb9914819e087339e1dab864af51cbd9f609df26f651ce51ef19fd8d879e
      SHA512:f9e8513c27ee3ab84f3bd91bb6f292a4cc46a5ebdf6e53699ff98858b310fa94ec215d8830b58290dd2f76ef426a6c6b7eb1ba579ae0d5b95cc47c2a8feabe6a
      SSDEEP:1536:SO0r8VrULqRZ40CEUEA8u4Wny+56PfkAGuUjjvxFb1mJA:Sjr89VT40DUEPWF4fLG3v8JA
      TLSH:DA6329DAB811DD7DF80FE77F8463050AB571A39101830F36A79FB963BD721A44962E82
      File Content Preview:.ELF.......................D...4.........4. ...(.......................<...<...... ........@.."@.."@......4....... .dt.Q............................NV..a....da.....N^NuNV..J9..%.f>"y.."X QJ.g.X.#..."XN."y.."X QJ.f.A.....J.g.Hy...<N.X.......%.N^NuNV..N^NuN

      ELF header

      Class:ELF32
      Data:2's complement, big endian
      Version:1 (current)
      Machine:MC68000
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - System V
      ABI Version:0
      Entry Point Address:0x80000144
      Flags:0x0
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:67080
      Section Header Size:40
      Number of Section Headers:10
      Header String Table Index:9
      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
      NULL0x00x00x00x00x0000
      .initPROGBITS0x800000940x940x140x00x6AX002
      .textPROGBITS0x800000a80xa80xeece0x00x6AX004
      .finiPROGBITS0x8000ef760xef760xe0x00x6AX002
      .rodataPROGBITS0x8000ef840xef840x12b80x00x2A002
      .ctorsPROGBITS0x800122400x102400x80x00x3WA004
      .dtorsPROGBITS0x800122480x102480x80x00x3WA004
      .dataPROGBITS0x800122540x102540x3740x00x3WA004
      .bssNOBITS0x800125c80x105c80x31700x00x3WA004
      .shstrtabSTRTAB0x00x105c80x3e0x00x0001
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x800000000x800000000x1023c0x1023c6.27140x5R E0x2000.init .text .fini .rodata
      LOAD0x102400x800122400x800122400x3880x34f82.96330x6RW 0x2000.ctors .dtors .data .bss
      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

      Download Network PCAP: filteredfull

      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
      2025-01-19T03:48:03.127135+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1456540TCP
      • Total Packets: 245
      • 13566 undefined
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 03:48:02.203350067 CET3737613566192.168.2.1483.222.38.239
      Jan 19, 2025 03:48:02.208798885 CET135663737683.222.38.239192.168.2.14
      Jan 19, 2025 03:48:02.208870888 CET3737613566192.168.2.1483.222.38.239
      Jan 19, 2025 03:48:02.239681959 CET3737613566192.168.2.1483.222.38.239
      Jan 19, 2025 03:48:02.245748997 CET135663737683.222.38.239192.168.2.14
      Jan 19, 2025 03:48:02.245826006 CET3737613566192.168.2.1483.222.38.239
      Jan 19, 2025 03:48:02.257994890 CET4005213566192.168.2.1483.222.235.14
      Jan 19, 2025 03:48:02.264076948 CET135664005283.222.235.14192.168.2.14
      Jan 19, 2025 03:48:02.264146090 CET4005213566192.168.2.1483.222.235.14
      Jan 19, 2025 03:48:02.268589020 CET4005213566192.168.2.1483.222.235.14
      Jan 19, 2025 03:48:02.273039103 CET4791813566192.168.2.1483.222.213.79
      Jan 19, 2025 03:48:02.274580956 CET135664005283.222.235.14192.168.2.14
      Jan 19, 2025 03:48:02.274714947 CET4005213566192.168.2.1483.222.235.14
      Jan 19, 2025 03:48:02.278100014 CET135664791883.222.213.79192.168.2.14
      Jan 19, 2025 03:48:02.278170109 CET4791813566192.168.2.1483.222.213.79
      Jan 19, 2025 03:48:02.278266907 CET4791813566192.168.2.1483.222.213.79
      Jan 19, 2025 03:48:02.283237934 CET135664791883.222.213.79192.168.2.14
      Jan 19, 2025 03:48:02.283422947 CET4791813566192.168.2.1483.222.213.79
      Jan 19, 2025 03:48:02.298496962 CET4868213566192.168.2.1483.222.49.198
      Jan 19, 2025 03:48:02.303783894 CET135664868283.222.49.198192.168.2.14
      Jan 19, 2025 03:48:02.303967953 CET4868213566192.168.2.1483.222.49.198
      Jan 19, 2025 03:48:02.312752962 CET4868213566192.168.2.1483.222.49.198
      Jan 19, 2025 03:48:02.317904949 CET135664868283.222.49.198192.168.2.14
      Jan 19, 2025 03:48:02.317996979 CET4868213566192.168.2.1483.222.49.198
      Jan 19, 2025 03:48:02.344280005 CET3816013566192.168.2.1483.222.92.197
      Jan 19, 2025 03:48:02.349580050 CET135663816083.222.92.197192.168.2.14
      Jan 19, 2025 03:48:02.349669933 CET3816013566192.168.2.1483.222.92.197
      Jan 19, 2025 03:48:02.350029945 CET5937613566192.168.2.1483.222.173.121
      Jan 19, 2025 03:48:02.355953932 CET135665937683.222.173.121192.168.2.14
      Jan 19, 2025 03:48:02.356021881 CET5937613566192.168.2.1483.222.173.121
      Jan 19, 2025 03:48:02.356998920 CET3316613566192.168.2.1483.222.126.66
      Jan 19, 2025 03:48:02.363027096 CET135663316683.222.126.66192.168.2.14
      Jan 19, 2025 03:48:02.363342047 CET3316613566192.168.2.1483.222.126.66
      Jan 19, 2025 03:48:02.363454103 CET3316613566192.168.2.1483.222.126.66
      Jan 19, 2025 03:48:02.365772009 CET5352613566192.168.2.1483.222.120.103
      Jan 19, 2025 03:48:02.370436907 CET135663316683.222.126.66192.168.2.14
      Jan 19, 2025 03:48:02.370892048 CET135665352683.222.120.103192.168.2.14
      Jan 19, 2025 03:48:02.370951891 CET5352613566192.168.2.1483.222.120.103
      Jan 19, 2025 03:48:02.372222900 CET5637613566192.168.2.1483.222.152.50
      Jan 19, 2025 03:48:02.377136946 CET135665637683.222.152.50192.168.2.14
      Jan 19, 2025 03:48:02.377337933 CET5637613566192.168.2.1483.222.152.50
      Jan 19, 2025 03:48:02.377367020 CET4254813566192.168.2.1483.222.167.50
      Jan 19, 2025 03:48:02.378163099 CET135663316683.222.126.66192.168.2.14
      Jan 19, 2025 03:48:02.378259897 CET3316613566192.168.2.1483.222.126.66
      Jan 19, 2025 03:48:02.382405996 CET135664254883.222.167.50192.168.2.14
      Jan 19, 2025 03:48:02.382472038 CET4254813566192.168.2.1483.222.167.50
      Jan 19, 2025 03:48:02.383496046 CET5265413566192.168.2.1483.222.163.80
      Jan 19, 2025 03:48:02.388680935 CET135665265483.222.163.80192.168.2.14
      Jan 19, 2025 03:48:02.388755083 CET5265413566192.168.2.1483.222.163.80
      Jan 19, 2025 03:48:02.389446020 CET5596013566192.168.2.1483.222.168.98
      Jan 19, 2025 03:48:02.394730091 CET135665596083.222.168.98192.168.2.14
      Jan 19, 2025 03:48:02.394783020 CET5596013566192.168.2.1483.222.168.98
      Jan 19, 2025 03:48:02.397507906 CET3534213566192.168.2.1483.222.168.31
      Jan 19, 2025 03:48:02.402362108 CET135663534283.222.168.31192.168.2.14
      Jan 19, 2025 03:48:02.402952909 CET3534213566192.168.2.1483.222.168.31
      Jan 19, 2025 03:48:02.403273106 CET3534213566192.168.2.1483.222.168.31
      Jan 19, 2025 03:48:02.407938957 CET4717613566192.168.2.1483.222.34.172
      Jan 19, 2025 03:48:02.408267975 CET135663534283.222.168.31192.168.2.14
      Jan 19, 2025 03:48:02.408334017 CET3534213566192.168.2.1483.222.168.31
      Jan 19, 2025 03:48:02.412957907 CET135664717683.222.34.172192.168.2.14
      Jan 19, 2025 03:48:02.413079023 CET4717613566192.168.2.1483.222.34.172
      Jan 19, 2025 03:48:02.446540117 CET5641413566192.168.2.1483.222.184.42
      Jan 19, 2025 03:48:02.452563047 CET135665641483.222.184.42192.168.2.14
      Jan 19, 2025 03:48:02.452637911 CET5641413566192.168.2.1483.222.184.42
      Jan 19, 2025 03:48:02.469052076 CET5641413566192.168.2.1483.222.184.42
      Jan 19, 2025 03:48:02.474381924 CET135665641483.222.184.42192.168.2.14
      Jan 19, 2025 03:48:02.474433899 CET3363613566192.168.2.1483.222.91.222
      Jan 19, 2025 03:48:02.474482059 CET5641413566192.168.2.1483.222.184.42
      Jan 19, 2025 03:48:02.479561090 CET135663363683.222.91.222192.168.2.14
      Jan 19, 2025 03:48:02.479594946 CET5287613566192.168.2.1483.222.25.70
      Jan 19, 2025 03:48:02.479695082 CET3363613566192.168.2.1483.222.91.222
      Jan 19, 2025 03:48:02.484685898 CET135665287683.222.25.70192.168.2.14
      Jan 19, 2025 03:48:02.485033035 CET5287613566192.168.2.1483.222.25.70
      Jan 19, 2025 03:48:02.498516083 CET3286013566192.168.2.1483.222.237.238
      Jan 19, 2025 03:48:02.503746033 CET135663286083.222.237.238192.168.2.14
      Jan 19, 2025 03:48:02.503819942 CET3286013566192.168.2.1483.222.237.238
      Jan 19, 2025 03:48:02.507162094 CET3314013566192.168.2.1483.222.150.30
      Jan 19, 2025 03:48:02.512051105 CET135663314083.222.150.30192.168.2.14
      Jan 19, 2025 03:48:02.512182951 CET3314013566192.168.2.1483.222.150.30
      Jan 19, 2025 03:48:02.521080017 CET3314013566192.168.2.1483.222.150.30
      Jan 19, 2025 03:48:02.522236109 CET5821613566192.168.2.1483.222.180.242
      Jan 19, 2025 03:48:02.526062965 CET4389413566192.168.2.1483.222.228.97
      Jan 19, 2025 03:48:02.526576042 CET135663314083.222.150.30192.168.2.14
      Jan 19, 2025 03:48:02.526621103 CET135663314083.222.150.30192.168.2.14
      Jan 19, 2025 03:48:02.528068066 CET3314013566192.168.2.1483.222.150.30
      Jan 19, 2025 03:48:02.528193951 CET135665821683.222.180.242192.168.2.14
      Jan 19, 2025 03:48:02.528248072 CET5821613566192.168.2.1483.222.180.242
      Jan 19, 2025 03:48:02.530769110 CET4596213566192.168.2.1483.222.108.98
      Jan 19, 2025 03:48:02.531196117 CET135664389483.222.228.97192.168.2.14
      Jan 19, 2025 03:48:02.531258106 CET4389413566192.168.2.1483.222.228.97
      Jan 19, 2025 03:48:02.533770084 CET5727413566192.168.2.1483.222.163.228
      Jan 19, 2025 03:48:02.536891937 CET135664596283.222.108.98192.168.2.14
      Jan 19, 2025 03:48:02.537086964 CET4596213566192.168.2.1483.222.108.98
      Jan 19, 2025 03:48:02.537487030 CET5618413566192.168.2.1483.222.201.60
      Jan 19, 2025 03:48:02.539380074 CET135665727483.222.163.228192.168.2.14
      Jan 19, 2025 03:48:02.539438009 CET5727413566192.168.2.1483.222.163.228
      Jan 19, 2025 03:48:02.541208982 CET5174613566192.168.2.1483.222.23.112
      Jan 19, 2025 03:48:02.542882919 CET135665618483.222.201.60192.168.2.14
      Jan 19, 2025 03:48:02.546273947 CET5618413566192.168.2.1483.222.201.60
      Jan 19, 2025 03:48:02.546454906 CET135665174683.222.23.112192.168.2.14
      Jan 19, 2025 03:48:02.550065994 CET5174613566192.168.2.1483.222.23.112
      Jan 19, 2025 03:48:02.554887056 CET5174613566192.168.2.1483.222.23.112
      Jan 19, 2025 03:48:02.557262897 CET4399213566192.168.2.1483.222.110.186
      Jan 19, 2025 03:48:02.560233116 CET135665174683.222.23.112192.168.2.14
      Jan 19, 2025 03:48:02.560308933 CET5174613566192.168.2.1483.222.23.112
      Jan 19, 2025 03:48:02.562357903 CET135664399283.222.110.186192.168.2.14
      Jan 19, 2025 03:48:02.562419891 CET4399213566192.168.2.1483.222.110.186
      Jan 19, 2025 03:48:02.600500107 CET4399213566192.168.2.1483.222.110.186
      Jan 19, 2025 03:48:02.605767012 CET135664399283.222.110.186192.168.2.14
      Jan 19, 2025 03:48:02.605880976 CET4399213566192.168.2.1483.222.110.186
      Jan 19, 2025 03:48:02.607280016 CET5775013566192.168.2.1483.222.192.22
      Jan 19, 2025 03:48:02.613477945 CET135665775083.222.192.22192.168.2.14
      Jan 19, 2025 03:48:02.613662958 CET5775013566192.168.2.1483.222.192.22
      Jan 19, 2025 03:48:02.614088058 CET5775013566192.168.2.1483.222.192.22
      Jan 19, 2025 03:48:02.619590044 CET3527013566192.168.2.1483.222.28.104
      Jan 19, 2025 03:48:02.619950056 CET135665775083.222.192.22192.168.2.14
      Jan 19, 2025 03:48:02.620034933 CET5775013566192.168.2.1483.222.192.22
      Jan 19, 2025 03:48:02.625144005 CET135663527083.222.28.104192.168.2.14
      Jan 19, 2025 03:48:02.625216961 CET3527013566192.168.2.1483.222.28.104
      Jan 19, 2025 03:48:02.627159119 CET4770613566192.168.2.1483.222.53.62
      Jan 19, 2025 03:48:02.632714033 CET135664770683.222.53.62192.168.2.14
      Jan 19, 2025 03:48:02.632781982 CET4770613566192.168.2.1483.222.53.62
      Jan 19, 2025 03:48:02.642895937 CET4770613566192.168.2.1483.222.53.62
      Jan 19, 2025 03:48:02.648175001 CET135664770683.222.53.62192.168.2.14
      Jan 19, 2025 03:48:02.648355961 CET4770613566192.168.2.1483.222.53.62
      Jan 19, 2025 03:48:02.649674892 CET5056213566192.168.2.1483.222.20.238
      Jan 19, 2025 03:48:02.654741049 CET135665056283.222.20.238192.168.2.14
      Jan 19, 2025 03:48:02.655030966 CET5056213566192.168.2.1483.222.20.238
      Jan 19, 2025 03:48:02.657926083 CET5056213566192.168.2.1483.222.20.238
      Jan 19, 2025 03:48:02.662194014 CET6058413566192.168.2.1483.222.104.112
      Jan 19, 2025 03:48:02.663012981 CET135665056283.222.20.238192.168.2.14
      Jan 19, 2025 03:48:02.663068056 CET5056213566192.168.2.1483.222.20.238
      Jan 19, 2025 03:48:02.665581942 CET5871413566192.168.2.1483.222.204.129
      Jan 19, 2025 03:48:02.667273998 CET135666058483.222.104.112192.168.2.14
      Jan 19, 2025 03:48:02.667411089 CET6058413566192.168.2.1483.222.104.112
      Jan 19, 2025 03:48:02.670425892 CET135665871483.222.204.129192.168.2.14
      Jan 19, 2025 03:48:02.670923948 CET5871413566192.168.2.1483.222.204.129
      Jan 19, 2025 03:48:02.670924902 CET5871413566192.168.2.1483.222.204.129
      Jan 19, 2025 03:48:02.673357964 CET4057213566192.168.2.1483.222.182.185
      Jan 19, 2025 03:48:02.676002026 CET135665871483.222.204.129192.168.2.14
      Jan 19, 2025 03:48:02.676103115 CET5871413566192.168.2.1483.222.204.129
      Jan 19, 2025 03:48:02.678312063 CET135664057283.222.182.185192.168.2.14
      Jan 19, 2025 03:48:02.678379059 CET4057213566192.168.2.1483.222.182.185
      Jan 19, 2025 03:48:02.678797007 CET4212813566192.168.2.1483.222.111.76
      Jan 19, 2025 03:48:02.683734894 CET135664212883.222.111.76192.168.2.14
      Jan 19, 2025 03:48:02.683917999 CET4212813566192.168.2.1483.222.111.76
      Jan 19, 2025 03:48:02.686213017 CET4208013566192.168.2.1483.222.216.35
      Jan 19, 2025 03:48:02.691150904 CET135664208083.222.216.35192.168.2.14
      Jan 19, 2025 03:48:02.691793919 CET4208013566192.168.2.1483.222.216.35
      Jan 19, 2025 03:48:02.693820953 CET6019613566192.168.2.1483.222.63.188
      Jan 19, 2025 03:48:02.697820902 CET3903813566192.168.2.1483.222.132.171
      Jan 19, 2025 03:48:02.698921919 CET135666019683.222.63.188192.168.2.14
      Jan 19, 2025 03:48:02.699007988 CET6019613566192.168.2.1483.222.63.188
      Jan 19, 2025 03:48:02.702069998 CET5247013566192.168.2.1483.222.30.40
      Jan 19, 2025 03:48:02.703406096 CET135663903883.222.132.171192.168.2.14
      Jan 19, 2025 03:48:02.703463078 CET3903813566192.168.2.1483.222.132.171
      Jan 19, 2025 03:48:02.705565929 CET3967413566192.168.2.1483.222.143.231
      Jan 19, 2025 03:48:02.706942081 CET135665247083.222.30.40192.168.2.14
      Jan 19, 2025 03:48:02.706989050 CET5247013566192.168.2.1483.222.30.40
      Jan 19, 2025 03:48:02.708790064 CET5845613566192.168.2.1483.222.100.166
      Jan 19, 2025 03:48:02.711221933 CET135663967483.222.143.231192.168.2.14
      Jan 19, 2025 03:48:02.711334944 CET3967413566192.168.2.1483.222.143.231
      Jan 19, 2025 03:48:02.711975098 CET3834013566192.168.2.1483.222.88.210
      Jan 19, 2025 03:48:02.714184999 CET135665845683.222.100.166192.168.2.14
      Jan 19, 2025 03:48:02.714235067 CET5845613566192.168.2.1483.222.100.166
      Jan 19, 2025 03:48:02.715156078 CET4824613566192.168.2.1483.222.96.24
      Jan 19, 2025 03:48:02.717104912 CET135663834083.222.88.210192.168.2.14
      Jan 19, 2025 03:48:02.717183113 CET3834013566192.168.2.1483.222.88.210
      Jan 19, 2025 03:48:02.718467951 CET5920813566192.168.2.1483.222.232.124
      Jan 19, 2025 03:48:02.721276045 CET135664824683.222.96.24192.168.2.14
      Jan 19, 2025 03:48:02.721370935 CET4824613566192.168.2.1483.222.96.24
      Jan 19, 2025 03:48:02.722143888 CET3674213566192.168.2.1483.222.129.29
      Jan 19, 2025 03:48:02.723834038 CET135665920883.222.232.124192.168.2.14
      Jan 19, 2025 03:48:02.723892927 CET5920813566192.168.2.1483.222.232.124
      Jan 19, 2025 03:48:02.727943897 CET3457013566192.168.2.1483.222.186.149
      Jan 19, 2025 03:48:02.728193998 CET135663674283.222.129.29192.168.2.14
      Jan 19, 2025 03:48:02.728290081 CET3674213566192.168.2.1483.222.129.29
      Jan 19, 2025 03:48:02.732708931 CET6089813566192.168.2.1483.222.11.34
      Jan 19, 2025 03:48:02.733390093 CET135663457083.222.186.149192.168.2.14
      Jan 19, 2025 03:48:02.733442068 CET3457013566192.168.2.1483.222.186.149
      Jan 19, 2025 03:48:02.737615108 CET3762213566192.168.2.1483.222.5.216
      Jan 19, 2025 03:48:02.737735033 CET135666089883.222.11.34192.168.2.14
      Jan 19, 2025 03:48:02.737788916 CET6089813566192.168.2.1483.222.11.34
      Jan 19, 2025 03:48:02.742516994 CET135663762283.222.5.216192.168.2.14
      Jan 19, 2025 03:48:02.742589951 CET3762213566192.168.2.1483.222.5.216
      Jan 19, 2025 03:48:02.743141890 CET5613013566192.168.2.1483.222.163.188
      Jan 19, 2025 03:48:02.748038054 CET135665613083.222.163.188192.168.2.14
      Jan 19, 2025 03:48:02.748087883 CET5613013566192.168.2.1483.222.163.188
      Jan 19, 2025 03:48:02.748467922 CET5452613566192.168.2.1483.222.145.18
      Jan 19, 2025 03:48:02.753768921 CET5173613566192.168.2.1483.222.8.105
      Jan 19, 2025 03:48:02.753890038 CET135665452683.222.145.18192.168.2.14
      Jan 19, 2025 03:48:02.753938913 CET5452613566192.168.2.1483.222.145.18
      Jan 19, 2025 03:48:02.758249044 CET5202613566192.168.2.1483.222.53.71
      Jan 19, 2025 03:48:02.758691072 CET135665173683.222.8.105192.168.2.14
      Jan 19, 2025 03:48:02.758750916 CET5173613566192.168.2.1483.222.8.105
      Jan 19, 2025 03:48:02.762011051 CET3773813566192.168.2.1483.222.37.186
      Jan 19, 2025 03:48:02.763134003 CET135665202683.222.53.71192.168.2.14
      Jan 19, 2025 03:48:02.763284922 CET5202613566192.168.2.1483.222.53.71
      Jan 19, 2025 03:48:02.766931057 CET135663773883.222.37.186192.168.2.14
      Jan 19, 2025 03:48:02.766980886 CET3773813566192.168.2.1483.222.37.186
      Jan 19, 2025 03:48:02.767257929 CET5740613566192.168.2.1483.222.242.67
      Jan 19, 2025 03:48:02.772176981 CET3890213566192.168.2.1483.222.226.130
      Jan 19, 2025 03:48:02.772320986 CET135665740683.222.242.67192.168.2.14
      Jan 19, 2025 03:48:02.772389889 CET5740613566192.168.2.1483.222.242.67
      Jan 19, 2025 03:48:02.776107073 CET5388613566192.168.2.1483.222.43.70
      Jan 19, 2025 03:48:02.777420044 CET135663890283.222.226.130192.168.2.14
      Jan 19, 2025 03:48:02.777590990 CET3890213566192.168.2.1483.222.226.130
      Jan 19, 2025 03:48:02.781080961 CET135665388683.222.43.70192.168.2.14
      Jan 19, 2025 03:48:02.781153917 CET5388613566192.168.2.1483.222.43.70
      Jan 19, 2025 03:48:02.781790972 CET5239613566192.168.2.1483.222.40.131
      Jan 19, 2025 03:48:02.786695957 CET135665239683.222.40.131192.168.2.14
      Jan 19, 2025 03:48:02.786735058 CET5239613566192.168.2.1483.222.40.131
      Jan 19, 2025 03:48:02.789103031 CET5696613566192.168.2.1483.222.24.137
      Jan 19, 2025 03:48:02.793936968 CET135665696683.222.24.137192.168.2.14
      Jan 19, 2025 03:48:02.793984890 CET5696613566192.168.2.1483.222.24.137
      Jan 19, 2025 03:48:02.794437885 CET4555813566192.168.2.1483.222.155.0
      Jan 19, 2025 03:48:02.799866915 CET135664555883.222.155.0192.168.2.14
      Jan 19, 2025 03:48:02.799938917 CET4555813566192.168.2.1483.222.155.0
      Jan 19, 2025 03:48:02.800688028 CET4555813566192.168.2.1483.222.155.0
      Jan 19, 2025 03:48:02.803749084 CET5890613566192.168.2.1483.222.5.28
      Jan 19, 2025 03:48:02.806804895 CET135664555883.222.155.0192.168.2.14
      Jan 19, 2025 03:48:02.806849003 CET4555813566192.168.2.1483.222.155.0
      Jan 19, 2025 03:48:02.808806896 CET135665890683.222.5.28192.168.2.14
      Jan 19, 2025 03:48:02.808861017 CET5890613566192.168.2.1483.222.5.28
      Jan 19, 2025 03:48:02.812172890 CET5686613566192.168.2.1483.222.29.192
      Jan 19, 2025 03:48:02.817733049 CET5395013566192.168.2.1483.222.178.41
      Jan 19, 2025 03:48:02.818020105 CET135665686683.222.29.192192.168.2.14
      Jan 19, 2025 03:48:02.818094969 CET5686613566192.168.2.1483.222.29.192
      Jan 19, 2025 03:48:02.823406935 CET4593013566192.168.2.1483.222.226.183
      Jan 19, 2025 03:48:02.824300051 CET135665395083.222.178.41192.168.2.14
      Jan 19, 2025 03:48:02.824350119 CET5395013566192.168.2.1483.222.178.41
      Jan 19, 2025 03:48:02.828314066 CET5074213566192.168.2.1483.222.1.134
      Jan 19, 2025 03:48:02.828318119 CET135664593083.222.226.183192.168.2.14
      Jan 19, 2025 03:48:02.828371048 CET4593013566192.168.2.1483.222.226.183
      Jan 19, 2025 03:48:02.833231926 CET135665074283.222.1.134192.168.2.14
      Jan 19, 2025 03:48:02.833314896 CET5074213566192.168.2.1483.222.1.134
      Jan 19, 2025 03:48:02.834142923 CET4009013566192.168.2.1483.222.115.146
      Jan 19, 2025 03:48:02.838783026 CET4303013566192.168.2.1483.222.152.124
      Jan 19, 2025 03:48:02.838951111 CET135664009083.222.115.146192.168.2.14
      Jan 19, 2025 03:48:02.839008093 CET4009013566192.168.2.1483.222.115.146
      Jan 19, 2025 03:48:02.843724012 CET135664303083.222.152.124192.168.2.14
      Jan 19, 2025 03:48:02.843787909 CET4303013566192.168.2.1483.222.152.124
      Jan 19, 2025 03:48:02.844630957 CET5702613566192.168.2.1483.222.252.206
      Jan 19, 2025 03:48:02.849266052 CET5059213566192.168.2.1483.222.195.33
      Jan 19, 2025 03:48:02.849585056 CET135665702683.222.252.206192.168.2.14
      Jan 19, 2025 03:48:02.849643946 CET5702613566192.168.2.1483.222.252.206
      Jan 19, 2025 03:48:02.854199886 CET135665059283.222.195.33192.168.2.14
      Jan 19, 2025 03:48:02.854264975 CET5059213566192.168.2.1483.222.195.33
      Jan 19, 2025 03:48:02.855186939 CET5154413566192.168.2.1483.222.136.182
      Jan 19, 2025 03:48:02.860055923 CET135665154483.222.136.182192.168.2.14
      Jan 19, 2025 03:48:02.860223055 CET5154413566192.168.2.1483.222.136.182
      Jan 19, 2025 03:48:02.860835075 CET5744613566192.168.2.1483.222.101.106
      Jan 19, 2025 03:48:02.865699053 CET135665744683.222.101.106192.168.2.14
      Jan 19, 2025 03:48:02.865771055 CET5744613566192.168.2.1483.222.101.106
      Jan 19, 2025 03:48:02.866522074 CET4259213566192.168.2.1483.222.56.144
      Jan 19, 2025 03:48:02.870625973 CET4275213566192.168.2.1483.222.176.96
      Jan 19, 2025 03:48:02.871373892 CET135664259283.222.56.144192.168.2.14
      Jan 19, 2025 03:48:02.871582985 CET4259213566192.168.2.1483.222.56.144
      Jan 19, 2025 03:48:02.874345064 CET5350613566192.168.2.1483.222.19.200
      Jan 19, 2025 03:48:02.875483036 CET135664275283.222.176.96192.168.2.14
      Jan 19, 2025 03:48:02.875528097 CET4275213566192.168.2.1483.222.176.96
      Jan 19, 2025 03:48:02.877947092 CET4581613566192.168.2.1483.222.233.174
      Jan 19, 2025 03:48:02.879241943 CET135665350683.222.19.200192.168.2.14
      Jan 19, 2025 03:48:02.879297018 CET5350613566192.168.2.1483.222.19.200
      Jan 19, 2025 03:48:02.882786989 CET135664581683.222.233.174192.168.2.14
      Jan 19, 2025 03:48:02.882857084 CET4581613566192.168.2.1483.222.233.174
      Jan 19, 2025 03:48:02.898417950 CET3396213566192.168.2.1483.222.200.239
      Jan 19, 2025 03:48:02.903968096 CET135663396283.222.200.239192.168.2.14
      Jan 19, 2025 03:48:02.904038906 CET3396213566192.168.2.1483.222.200.239
      Jan 19, 2025 03:48:02.908576012 CET3396213566192.168.2.1483.222.200.239
      Jan 19, 2025 03:48:02.914414883 CET135663396283.222.200.239192.168.2.14
      Jan 19, 2025 03:48:02.914474010 CET3396213566192.168.2.1483.222.200.239
      Jan 19, 2025 03:48:02.915879965 CET4566813566192.168.2.1483.222.203.229
      Jan 19, 2025 03:48:02.917032957 CET4787013566192.168.2.1483.222.175.125
      Jan 19, 2025 03:48:02.919724941 CET5474213566192.168.2.1483.222.14.145
      Jan 19, 2025 03:48:02.920806885 CET135664566883.222.203.229192.168.2.14
      Jan 19, 2025 03:48:02.920994997 CET4566813566192.168.2.1483.222.203.229
      Jan 19, 2025 03:48:02.921063900 CET5216613566192.168.2.1483.222.52.15
      Jan 19, 2025 03:48:02.921958923 CET135664787083.222.175.125192.168.2.14
      Jan 19, 2025 03:48:02.922007084 CET4787013566192.168.2.1483.222.175.125
      Jan 19, 2025 03:48:02.922259092 CET3679813566192.168.2.1483.222.23.168
      Jan 19, 2025 03:48:02.924547911 CET135665474283.222.14.145192.168.2.14
      Jan 19, 2025 03:48:02.924604893 CET5474213566192.168.2.1483.222.14.145
      Jan 19, 2025 03:48:02.924853086 CET4486613566192.168.2.1483.222.162.176
      Jan 19, 2025 03:48:02.925826073 CET135665216683.222.52.15192.168.2.14
      Jan 19, 2025 03:48:02.925877094 CET5216613566192.168.2.1483.222.52.15
      Jan 19, 2025 03:48:02.926026106 CET4029413566192.168.2.1483.222.36.158
      Jan 19, 2025 03:48:02.927158117 CET135663679883.222.23.168192.168.2.14
      Jan 19, 2025 03:48:02.927198887 CET4560613566192.168.2.1483.222.126.231
      Jan 19, 2025 03:48:02.927202940 CET3679813566192.168.2.1483.222.23.168
      Jan 19, 2025 03:48:02.928529978 CET5897213566192.168.2.1483.222.191.6
      Jan 19, 2025 03:48:02.929723024 CET135664486683.222.162.176192.168.2.14
      Jan 19, 2025 03:48:02.929775953 CET3810813566192.168.2.1483.222.157.36
      Jan 19, 2025 03:48:02.929775953 CET4486613566192.168.2.1483.222.162.176
      Jan 19, 2025 03:48:02.930896997 CET135664029483.222.36.158192.168.2.14
      Jan 19, 2025 03:48:02.930994987 CET4029413566192.168.2.1483.222.36.158
      Jan 19, 2025 03:48:02.931149960 CET5781613566192.168.2.1483.222.112.213
      Jan 19, 2025 03:48:02.932029963 CET135664560683.222.126.231192.168.2.14
      Jan 19, 2025 03:48:02.932082891 CET4560613566192.168.2.1483.222.126.231
      Jan 19, 2025 03:48:02.932308912 CET4449613566192.168.2.1483.222.180.32
      Jan 19, 2025 03:48:02.933362961 CET135665897283.222.191.6192.168.2.14
      Jan 19, 2025 03:48:02.933413029 CET5897213566192.168.2.1483.222.191.6
      Jan 19, 2025 03:48:02.933474064 CET4788213566192.168.2.1483.222.54.199
      Jan 19, 2025 03:48:02.934637070 CET135663810883.222.157.36192.168.2.14
      Jan 19, 2025 03:48:02.935605049 CET3810813566192.168.2.1483.222.157.36
      Jan 19, 2025 03:48:02.935976028 CET135665781683.222.112.213192.168.2.14
      Jan 19, 2025 03:48:02.936050892 CET5781613566192.168.2.1483.222.112.213
      Jan 19, 2025 03:48:02.936217070 CET3874813566192.168.2.1483.222.232.31
      Jan 19, 2025 03:48:02.937247992 CET135664449683.222.180.32192.168.2.14
      Jan 19, 2025 03:48:02.937305927 CET4449613566192.168.2.1483.222.180.32
      Jan 19, 2025 03:48:02.937515974 CET4078413566192.168.2.1483.222.118.176
      Jan 19, 2025 03:48:02.938263893 CET135664788283.222.54.199192.168.2.14
      Jan 19, 2025 03:48:02.938314915 CET4788213566192.168.2.1483.222.54.199
      Jan 19, 2025 03:48:02.938777924 CET4059613566192.168.2.1483.222.14.65
      Jan 19, 2025 03:48:02.940064907 CET4672013566192.168.2.1483.222.149.189
      Jan 19, 2025 03:48:02.941071987 CET135663874883.222.232.31192.168.2.14
      Jan 19, 2025 03:48:02.941123962 CET3874813566192.168.2.1483.222.232.31
      Jan 19, 2025 03:48:02.941278934 CET4291213566192.168.2.1483.222.190.164
      Jan 19, 2025 03:48:02.942341089 CET135664078483.222.118.176192.168.2.14
      Jan 19, 2025 03:48:02.942390919 CET4078413566192.168.2.1483.222.118.176
      Jan 19, 2025 03:48:02.942620993 CET5290013566192.168.2.1483.222.79.242
      Jan 19, 2025 03:48:02.943658113 CET135664059683.222.14.65192.168.2.14
      Jan 19, 2025 03:48:02.943708897 CET4059613566192.168.2.1483.222.14.65
      Jan 19, 2025 03:48:02.943866968 CET3291813566192.168.2.1483.222.179.102
      Jan 19, 2025 03:48:02.944931030 CET135664672083.222.149.189192.168.2.14
      Jan 19, 2025 03:48:02.945027113 CET4672013566192.168.2.1483.222.149.189
      Jan 19, 2025 03:48:02.945200920 CET4436813566192.168.2.1483.222.154.85
      Jan 19, 2025 03:48:02.946105957 CET135664291283.222.190.164192.168.2.14
      Jan 19, 2025 03:48:02.946258068 CET4291213566192.168.2.1483.222.190.164
      Jan 19, 2025 03:48:02.947484016 CET135665290083.222.79.242192.168.2.14
      Jan 19, 2025 03:48:02.947886944 CET5290013566192.168.2.1483.222.79.242
      Jan 19, 2025 03:48:02.947938919 CET5420213566192.168.2.1483.222.22.190
      Jan 19, 2025 03:48:02.948693037 CET135663291883.222.179.102192.168.2.14
      Jan 19, 2025 03:48:02.948924065 CET3291813566192.168.2.1483.222.179.102
      Jan 19, 2025 03:48:02.950155020 CET135664436883.222.154.85192.168.2.14
      Jan 19, 2025 03:48:02.950295925 CET4436813566192.168.2.1483.222.154.85
      Jan 19, 2025 03:48:02.952873945 CET135665420283.222.22.190192.168.2.14
      Jan 19, 2025 03:48:02.954281092 CET5420213566192.168.2.1483.222.22.190
      Jan 19, 2025 03:48:02.958509922 CET5420213566192.168.2.1483.222.22.190
      Jan 19, 2025 03:48:02.963443995 CET135665420283.222.22.190192.168.2.14
      Jan 19, 2025 03:48:02.963659048 CET5420213566192.168.2.1483.222.22.190
      Jan 19, 2025 03:48:02.963722944 CET3282413566192.168.2.1483.222.243.148
      Jan 19, 2025 03:48:02.968616009 CET135663282483.222.243.148192.168.2.14
      Jan 19, 2025 03:48:02.968677044 CET3282413566192.168.2.1483.222.243.148
      Jan 19, 2025 03:48:02.974401951 CET3282413566192.168.2.1483.222.243.148
      Jan 19, 2025 03:48:02.980685949 CET135663282483.222.243.148192.168.2.14
      Jan 19, 2025 03:48:02.980768919 CET3282413566192.168.2.1483.222.243.148
      Jan 19, 2025 03:48:02.982429028 CET3854213566192.168.2.1483.222.166.179
      Jan 19, 2025 03:48:02.987921000 CET135663854283.222.166.179192.168.2.14
      Jan 19, 2025 03:48:02.988065004 CET3854213566192.168.2.1483.222.166.179
      Jan 19, 2025 03:48:02.998406887 CET3854213566192.168.2.1483.222.166.179
      Jan 19, 2025 03:48:03.004673004 CET135663854283.222.166.179192.168.2.14
      Jan 19, 2025 03:48:03.004829884 CET3854213566192.168.2.1483.222.166.179
      Jan 19, 2025 03:48:03.014534950 CET4775813566192.168.2.1483.222.154.67
      Jan 19, 2025 03:48:03.019908905 CET135664775883.222.154.67192.168.2.14
      Jan 19, 2025 03:48:03.020072937 CET4775813566192.168.2.1483.222.154.67
      Jan 19, 2025 03:48:03.062884092 CET4775813566192.168.2.1483.222.154.67
      Jan 19, 2025 03:48:03.067919970 CET135664775883.222.154.67192.168.2.14
      Jan 19, 2025 03:48:03.068123102 CET4775813566192.168.2.1483.222.154.67
      Jan 19, 2025 03:48:03.120899916 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:48:03.127135038 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:48:03.127310038 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:48:03.132611036 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:48:03.138648987 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:48:03.138751030 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:48:03.145589113 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:48:13.141882896 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:48:13.147242069 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:48:13.350084066 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:48:13.350161076 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:48:13.725045919 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:48:13.725209951 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:49:13.772367954 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:49:13.777757883 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:49:14.035149097 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:49:14.035480976 CET5654013566192.168.2.1483.222.191.90
      Jan 19, 2025 03:49:14.727818966 CET135665654083.222.191.90192.168.2.14
      Jan 19, 2025 03:49:14.728261948 CET5654013566192.168.2.1483.222.191.90
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 03:48:03.107661009 CET4999753192.168.2.148.8.8.8
      Jan 19, 2025 03:48:03.118324995 CET53499978.8.8.8192.168.2.14
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 19, 2025 03:48:03.107661009 CET192.168.2.148.8.8.80xa6b3Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 19, 2025 03:48:03.118324995 CET8.8.8.8192.168.2.140xa6b3No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

      System Behavior

      Start time (UTC):02:48:00
      Start date (UTC):19/01/2025
      Path:/tmp/Kloki.m68k.elf
      Arguments:/tmp/Kloki.m68k.elf
      File size:4463432 bytes
      MD5 hash:cd177594338c77b895ae27c33f8f86cc

      Start time (UTC):02:48:00
      Start date (UTC):19/01/2025
      Path:/tmp/Kloki.m68k.elf
      Arguments:-
      File size:4463432 bytes
      MD5 hash:cd177594338c77b895ae27c33f8f86cc

      Start time (UTC):02:48:00
      Start date (UTC):19/01/2025
      Path:/tmp/Kloki.m68k.elf
      Arguments:-
      File size:4463432 bytes
      MD5 hash:cd177594338c77b895ae27c33f8f86cc

      Start time (UTC):02:48:00
      Start date (UTC):19/01/2025
      Path:/tmp/Kloki.m68k.elf
      Arguments:-
      File size:4463432 bytes
      MD5 hash:cd177594338c77b895ae27c33f8f86cc

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/bin/sh
      Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/bin/sh
      Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/usr/bin/gnome-shell
      Arguments:/usr/bin/gnome-shell
      File size:23168 bytes
      MD5 hash:da7a257239677622fe4b3a65972c9e87

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/bin/sh
      Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/usr/libexec/gnome-session-binary
      Arguments:-
      File size:334664 bytes
      MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/usr/sbin/gdm3
      Arguments:-
      File size:453296 bytes
      MD5 hash:2492e2d8d34f9377e3e530a61a15674f

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/etc/gdm3/PrimeOff/Default
      Arguments:/etc/gdm3/PrimeOff/Default
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/usr/sbin/gdm3
      Arguments:-
      File size:453296 bytes
      MD5 hash:2492e2d8d34f9377e3e530a61a15674f

      Start time (UTC):02:48:01
      Start date (UTC):19/01/2025
      Path:/etc/gdm3/PrimeOff/Default
      Arguments:/etc/gdm3/PrimeOff/Default
      File size:129816 bytes
      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

      Start time (UTC):02:48:11
      Start date (UTC):19/01/2025
      Path:/usr/lib/systemd/systemd
      Arguments:-
      File size:1620224 bytes
      MD5 hash:9b2bec7092a40488108543f9334aab75

      Start time (UTC):02:48:11
      Start date (UTC):19/01/2025
      Path:/lib/systemd/systemd-user-runtime-dir
      Arguments:/lib/systemd/systemd-user-runtime-dir stop 127
      File size:22672 bytes
      MD5 hash:d55f4b0847f88131dbcfb07435178e54