Edit tour

Linux Analysis Report
loki.arm4.elf

Overview

General Information

Sample name:loki.arm4.elf
Analysis ID:1594508
MD5:c6eb2a68dc74fd72026ec9937c9f7073
SHA1:b112545a508bccf9f9aef776607d59de01bb5a33
SHA256:ab1c72e6678f39f623ce1c6311c44c5818bfe584bf4e7e229a4705024b620fdf
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594508
Start date and time:2025-01-19 03:52:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 52s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:loki.arm4.elf
Detection:MAL
Classification:mal48.linELF@0/0@1/0
Command:/tmp/loki.arm4.elf
PID:5491
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • loki.arm4.elf (PID: 5491, Parent: 5416, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/loki.arm4.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T03:53:00.331841+010025000342Misc Attack83.222.191.9013566192.168.2.1456536TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: loki.arm4.elfReversingLabs: Detection: 39%
Source: global trafficTCP traffic: 192.168.2.14:54600 -> 83.222.145.168:13566
Source: global trafficTCP traffic: 192.168.2.14:50932 -> 83.222.244.196:13566
Source: global trafficTCP traffic: 192.168.2.14:49016 -> 83.222.213.124:13566
Source: global trafficTCP traffic: 192.168.2.14:60752 -> 83.222.32.173:13566
Source: global trafficTCP traffic: 192.168.2.14:40210 -> 83.222.5.105:13566
Source: global trafficTCP traffic: 192.168.2.14:60154 -> 83.222.23.120:13566
Source: global trafficTCP traffic: 192.168.2.14:38906 -> 83.222.171.168:13566
Source: global trafficTCP traffic: 192.168.2.14:54406 -> 83.222.110.36:13566
Source: global trafficTCP traffic: 192.168.2.14:43152 -> 83.222.179.198:13566
Source: global trafficTCP traffic: 192.168.2.14:57290 -> 83.222.12.215:13566
Source: global trafficTCP traffic: 192.168.2.14:48348 -> 83.222.10.153:13566
Source: global trafficTCP traffic: 192.168.2.14:54642 -> 83.222.165.79:13566
Source: global trafficTCP traffic: 192.168.2.14:49500 -> 83.222.64.244:13566
Source: global trafficTCP traffic: 192.168.2.14:47346 -> 83.222.32.121:13566
Source: global trafficTCP traffic: 192.168.2.14:43072 -> 83.222.86.81:13566
Source: global trafficTCP traffic: 192.168.2.14:52462 -> 83.222.74.232:13566
Source: global trafficTCP traffic: 192.168.2.14:41414 -> 83.222.249.63:13566
Source: global trafficTCP traffic: 192.168.2.14:53048 -> 83.222.172.206:13566
Source: global trafficTCP traffic: 192.168.2.14:40514 -> 83.222.187.204:13566
Source: global trafficTCP traffic: 192.168.2.14:34986 -> 83.222.123.192:13566
Source: global trafficTCP traffic: 192.168.2.14:55198 -> 83.222.54.146:13566
Source: global trafficTCP traffic: 192.168.2.14:49132 -> 83.222.56.225:13566
Source: global trafficTCP traffic: 192.168.2.14:59972 -> 83.222.58.166:13566
Source: global trafficTCP traffic: 192.168.2.14:45936 -> 83.222.6.237:13566
Source: global trafficTCP traffic: 192.168.2.14:53420 -> 83.222.108.18:13566
Source: global trafficTCP traffic: 192.168.2.14:56288 -> 83.222.196.119:13566
Source: global trafficTCP traffic: 192.168.2.14:43120 -> 83.222.171.105:13566
Source: global trafficTCP traffic: 192.168.2.14:49196 -> 83.222.198.236:13566
Source: global trafficTCP traffic: 192.168.2.14:59782 -> 83.222.93.230:13566
Source: global trafficTCP traffic: 192.168.2.14:48032 -> 83.222.101.180:13566
Source: global trafficTCP traffic: 192.168.2.14:41536 -> 83.222.55.175:13566
Source: global trafficTCP traffic: 192.168.2.14:35984 -> 83.222.156.48:13566
Source: global trafficTCP traffic: 192.168.2.14:40222 -> 83.222.238.72:13566
Source: global trafficTCP traffic: 192.168.2.14:54142 -> 83.222.254.170:13566
Source: global trafficTCP traffic: 192.168.2.14:45066 -> 83.222.21.121:13566
Source: global trafficTCP traffic: 192.168.2.14:33004 -> 83.222.106.75:13566
Source: global trafficTCP traffic: 192.168.2.14:40056 -> 83.222.12.163:13566
Source: global trafficTCP traffic: 192.168.2.14:60310 -> 83.222.44.70:13566
Source: global trafficTCP traffic: 192.168.2.14:40064 -> 83.222.73.50:13566
Source: global trafficTCP traffic: 192.168.2.14:37860 -> 83.222.52.182:13566
Source: global trafficTCP traffic: 192.168.2.14:32800 -> 83.222.69.248:13566
Source: global trafficTCP traffic: 192.168.2.14:58450 -> 83.222.45.240:13566
Source: global trafficTCP traffic: 192.168.2.14:42884 -> 83.222.98.243:13566
Source: global trafficTCP traffic: 192.168.2.14:33598 -> 83.222.220.191:13566
Source: global trafficTCP traffic: 192.168.2.14:53184 -> 83.222.217.65:13566
Source: global trafficTCP traffic: 192.168.2.14:47054 -> 83.222.115.17:13566
Source: global trafficTCP traffic: 192.168.2.14:53358 -> 83.222.241.15:13566
Source: global trafficTCP traffic: 192.168.2.14:38560 -> 83.222.65.223:13566
Source: global trafficTCP traffic: 192.168.2.14:48972 -> 83.222.88.64:13566
Source: global trafficTCP traffic: 192.168.2.14:36312 -> 83.222.137.109:13566
Source: global trafficTCP traffic: 192.168.2.14:45594 -> 83.222.185.244:13566
Source: global trafficTCP traffic: 192.168.2.14:34422 -> 83.222.184.197:13566
Source: global trafficTCP traffic: 192.168.2.14:43968 -> 83.222.151.228:13566
Source: global trafficTCP traffic: 192.168.2.14:54402 -> 83.222.12.224:13566
Source: global trafficTCP traffic: 192.168.2.14:42640 -> 83.222.23.64:13566
Source: global trafficTCP traffic: 192.168.2.14:40754 -> 83.222.150.92:13566
Source: global trafficTCP traffic: 192.168.2.14:55844 -> 83.222.56.195:13566
Source: global trafficTCP traffic: 192.168.2.14:51542 -> 83.222.76.154:13566
Source: global trafficTCP traffic: 192.168.2.14:47446 -> 83.222.182.41:13566
Source: global trafficTCP traffic: 192.168.2.14:54706 -> 83.222.90.144:13566
Source: global trafficTCP traffic: 192.168.2.14:50310 -> 83.222.106.205:13566
Source: global trafficTCP traffic: 192.168.2.14:55024 -> 83.222.161.91:13566
Source: global trafficTCP traffic: 192.168.2.14:49582 -> 83.222.221.226:13566
Source: global trafficTCP traffic: 192.168.2.14:39002 -> 83.222.59.53:13566
Source: global trafficTCP traffic: 192.168.2.14:60496 -> 83.222.34.196:13566
Source: global trafficTCP traffic: 192.168.2.14:36104 -> 83.222.162.220:13566
Source: global trafficTCP traffic: 192.168.2.14:37494 -> 83.222.184.90:13566
Source: global trafficTCP traffic: 192.168.2.14:35418 -> 83.222.161.79:13566
Source: global trafficTCP traffic: 192.168.2.14:42570 -> 83.222.62.173:13566
Source: global trafficTCP traffic: 192.168.2.14:42490 -> 83.222.48.85:13566
Source: global trafficTCP traffic: 192.168.2.14:39704 -> 83.222.237.198:13566
Source: global trafficTCP traffic: 192.168.2.14:38592 -> 83.222.177.38:13566
Source: global trafficTCP traffic: 192.168.2.14:52266 -> 83.222.138.254:13566
Source: global trafficTCP traffic: 192.168.2.14:42950 -> 83.222.192.64:13566
Source: global trafficTCP traffic: 192.168.2.14:56578 -> 83.222.39.26:13566
Source: global trafficTCP traffic: 192.168.2.14:52124 -> 83.222.208.145:13566
Source: global trafficTCP traffic: 192.168.2.14:37820 -> 83.222.232.113:13566
Source: global trafficTCP traffic: 192.168.2.14:43338 -> 83.222.237.197:13566
Source: global trafficTCP traffic: 192.168.2.14:35446 -> 83.222.84.40:13566
Source: global trafficTCP traffic: 192.168.2.14:43402 -> 83.222.250.118:13566
Source: global trafficTCP traffic: 192.168.2.14:54570 -> 83.222.236.156:13566
Source: global trafficTCP traffic: 192.168.2.14:55614 -> 83.222.82.165:13566
Source: global trafficTCP traffic: 192.168.2.14:36504 -> 83.222.246.244:13566
Source: global trafficTCP traffic: 192.168.2.14:50112 -> 83.222.244.52:13566
Source: global trafficTCP traffic: 192.168.2.14:56362 -> 83.222.161.36:13566
Source: global trafficTCP traffic: 192.168.2.14:43450 -> 83.222.138.143:13566
Source: global trafficTCP traffic: 192.168.2.14:36194 -> 83.222.235.59:13566
Source: global trafficTCP traffic: 192.168.2.14:33274 -> 83.222.181.117:13566
Source: global trafficTCP traffic: 192.168.2.14:49646 -> 83.222.57.117:13566
Source: global trafficTCP traffic: 192.168.2.14:60610 -> 83.222.181.96:13566
Source: global trafficTCP traffic: 192.168.2.14:59554 -> 83.222.144.134:13566
Source: global trafficTCP traffic: 192.168.2.14:34350 -> 83.222.242.120:13566
Source: global trafficTCP traffic: 192.168.2.14:55270 -> 83.222.247.223:13566
Source: global trafficTCP traffic: 192.168.2.14:56536 -> 83.222.191.90:13566
Source: /tmp/loki.arm4.elf (PID: 5491)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.14:56536
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.145.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.145.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.145.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.145.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.124
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.124
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.32.173
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.5.105
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.32.173
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.5.105
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.5.105
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.23.120
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.5.105
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.23.120
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.179.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.168
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.12.215
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.179.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.12.215
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.64.244
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.32.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.64.244
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.86.81
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.32.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.74.232
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.86.81
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.74.232
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.249.63
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.206
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.249.63
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.206
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.206
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.172.206
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.204
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.204
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.204
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.123.192
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.187.204
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.54.146
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.123.192
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.56.225
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@1/0
Source: /tmp/loki.arm4.elf (PID: 5491)Queries kernel information via 'uname': Jump to behavior
Source: loki.arm4.elf, 5491.1.000055d7ca5cd000.000055d7ca742000.rw-.sdmp, loki.arm4.elf, 5493.1.000055d7ca5cd000.000055d7ca6fb000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: loki.arm4.elf, 5491.1.000055d7ca5cd000.000055d7ca742000.rw-.sdmp, loki.arm4.elf, 5493.1.000055d7ca5cd000.000055d7ca6fb000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: loki.arm4.elf, 5491.1.00007fff3309b000.00007fff330bc000.rw-.sdmp, loki.arm4.elf, 5493.1.00007fff3309b000.00007fff330bc000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/loki.arm4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/loki.arm4.elf
Source: loki.arm4.elf, 5491.1.00007fff3309b000.00007fff330bc000.rw-.sdmp, loki.arm4.elf, 5493.1.00007fff3309b000.00007fff330bc000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594508 Sample: loki.arm4.elf Startdate: 19/01/2025 Architecture: LINUX Score: 48 13 83.222.162.220, 13566, 36104 WAVENETLB Bulgaria 2->13 15 83.222.165.79, 13566, 54642 WAVENETLB Bulgaria 2->15 17 92 other IPs or domains 2->17 19 Multi AV Scanner detection for submitted file 2->19 7 loki.arm4.elf 2->7         started        signatures3 process4 process5 9 loki.arm4.elf 7->9         started        11 loki.arm4.elf 7->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
loki.arm4.elf39%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.179.198
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.10.153
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.151.228
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.177.38
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.172.206
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.254.170
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.106.75
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.161.91
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.59.53
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.250.118
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.238.72
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.181.96
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.196.119
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.82.165
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.52.182
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.98.243
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.12.163
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.23.64
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.108.18
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.48.85
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.64.244
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.32.173
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.21.121
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.86.81
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.88.64
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.208.145
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.236.156
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.198.236
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.246.244
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.162.220
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.237.197
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.171.168
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.73.50
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.237.198
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.217.65
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.106.205
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.23.120
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.44.70
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.56.195
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.185.244
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.56.225
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.144.134
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.69.248
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.65.223
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.110.36
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.39.26
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.165.79
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.76.154
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.138.143
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.74.232
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.182.41
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.161.79
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.6.237
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.244.52
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.161.36
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.187.204
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.93.230
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.57.117
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.150.92
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.62.173
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.90.144
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.101.180
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.249.63
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.12.224
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.45.240
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.32.121
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.5.105
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.235.59
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.54.146
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.137.109
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.244.196
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.58.166
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.84.40
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.145.168
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.241.15
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.242.120
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.184.197
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.181.117
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.138.254
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.213.124
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.12.215
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.171.105
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.232.113
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.115.17
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.55.175
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.123.192
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.220.191
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.221.226
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.184.90
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.156.48
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.247.223
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.192.64
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.34.196
    unknownLuxembourg
    8632LOL-ASluLUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.98.243Kloki.arm5.elfGet hashmaliciousUnknownBrowse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      secure-network-rebirthltd.ruKloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.191.90
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      GCN-ASGCNAD-SofiaBulgariaBGKloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.176.201
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.176.96
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.177.55
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.177.55
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.174.216
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.175.167
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.176.33
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.177.157
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.173.11
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.166.158
      SENSELAN-ASsenseLANGmbHCHKloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.158.150
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.154.67
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.146.129
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.146.129
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.128.248
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.140.196
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.135.55
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.153.195
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.136.251
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.152.112
      MASTERHOST-ASMoscowRussiaRUKloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.8.97
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.20.238
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.23.89
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.23.89
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.31.69
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.9.65
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.28.56
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.9.29
      Kloki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.15.96
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.17.204
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
      Entropy (8bit):5.912438515144121
      TrID:
      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
      File name:loki.arm4.elf
      File size:50'208 bytes
      MD5:c6eb2a68dc74fd72026ec9937c9f7073
      SHA1:b112545a508bccf9f9aef776607d59de01bb5a33
      SHA256:ab1c72e6678f39f623ce1c6311c44c5818bfe584bf4e7e229a4705024b620fdf
      SHA512:6c4a9dc08fafb9d11713316f5c910f97394d95cc1a5efc1a8d1037dc75812d20272951d6b6274ec68e72e9721997a4511a0ebabd06d8f6e05140026e97c8c0c3
      SSDEEP:768:ZunRMZAVSORpY3lDdFciTj9+6hfzRAgGGIIo4nN9SYG6UmL:2R6AQpFcG5+6hflI9Kow
      TLSH:A3330990BC919A17C5E4137BFA6E418D332663B8D2EF72179D222F21778982F0D77A41
      File Content Preview:.ELF...a..........(.........4...........4. ...(.....................h...h...........................P...............Q.td..................................-...L."....-..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:ARM
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:ARM - ABI
      ABI Version:0
      Entry Point Address:0x8190
      Flags:0x202
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:49808
      Section Header Size:40
      Number of Section Headers:10
      Header String Table Index:9
      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
      NULL0x00x00x00x00x0000
      .initPROGBITS0x80940x940x180x00x6AX004
      .textPROGBITS0x80b00xb00xb6400x00x6AX0016
      .finiPROGBITS0x136f00xb6f00x140x00x6AX004
      .rodataPROGBITS0x137040xb7040x5640x00x2A004
      .ctorsPROGBITS0x1c0000xc0000x80x00x3WA004
      .dtorsPROGBITS0x1c0080xc0080x80x00x3WA004
      .dataPROGBITS0x1c0140xc0140x23c0x00x3WA004
      .bssNOBITS0x1c2500xc2500x11640x00x3WA004
      .shstrtabSTRTAB0x00xc2500x3e0x00x0001
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x80000x80000xbc680xbc685.99930x5R E0x8000.init .text .fini .rodata
      LOAD0xc0000x1c0000x1c0000x2500x13b43.17370x6RW 0x8000.ctors .dtors .data .bss
      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

      Download Network PCAP: filteredfull

      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
      2025-01-19T03:53:00.331841+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1456536TCP
      • Total Packets: 211
      • 13566 undefined
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 03:52:59.988986969 CET5460013566192.168.2.1483.222.145.168
      Jan 19, 2025 03:52:59.994383097 CET135665460083.222.145.168192.168.2.14
      Jan 19, 2025 03:52:59.994452953 CET5460013566192.168.2.1483.222.145.168
      Jan 19, 2025 03:53:00.015216112 CET5460013566192.168.2.1483.222.145.168
      Jan 19, 2025 03:53:00.020951033 CET135665460083.222.145.168192.168.2.14
      Jan 19, 2025 03:53:00.021009922 CET5460013566192.168.2.1483.222.145.168
      Jan 19, 2025 03:53:00.034722090 CET5093213566192.168.2.1483.222.244.196
      Jan 19, 2025 03:53:00.040110111 CET135665093283.222.244.196192.168.2.14
      Jan 19, 2025 03:53:00.040235043 CET5093213566192.168.2.1483.222.244.196
      Jan 19, 2025 03:53:00.055330992 CET5093213566192.168.2.1483.222.244.196
      Jan 19, 2025 03:53:00.060745955 CET135665093283.222.244.196192.168.2.14
      Jan 19, 2025 03:53:00.060803890 CET5093213566192.168.2.1483.222.244.196
      Jan 19, 2025 03:53:00.060810089 CET4901613566192.168.2.1483.222.213.124
      Jan 19, 2025 03:53:00.065939903 CET135664901683.222.213.124192.168.2.14
      Jan 19, 2025 03:53:00.066037893 CET4901613566192.168.2.1483.222.213.124
      Jan 19, 2025 03:53:00.067835093 CET6075213566192.168.2.1483.222.32.173
      Jan 19, 2025 03:53:00.069983959 CET4021013566192.168.2.1483.222.5.105
      Jan 19, 2025 03:53:00.072978020 CET135666075283.222.32.173192.168.2.14
      Jan 19, 2025 03:53:00.073036909 CET6075213566192.168.2.1483.222.32.173
      Jan 19, 2025 03:53:00.075124025 CET135664021083.222.5.105192.168.2.14
      Jan 19, 2025 03:53:00.075223923 CET4021013566192.168.2.1483.222.5.105
      Jan 19, 2025 03:53:00.085692883 CET4021013566192.168.2.1483.222.5.105
      Jan 19, 2025 03:53:00.088969946 CET6015413566192.168.2.1483.222.23.120
      Jan 19, 2025 03:53:00.090871096 CET135664021083.222.5.105192.168.2.14
      Jan 19, 2025 03:53:00.090928078 CET4021013566192.168.2.1483.222.5.105
      Jan 19, 2025 03:53:00.091145992 CET3890613566192.168.2.1483.222.171.168
      Jan 19, 2025 03:53:00.094202995 CET135666015483.222.23.120192.168.2.14
      Jan 19, 2025 03:53:00.094444990 CET6015413566192.168.2.1483.222.23.120
      Jan 19, 2025 03:53:00.096100092 CET135663890683.222.171.168192.168.2.14
      Jan 19, 2025 03:53:00.096220016 CET3890613566192.168.2.1483.222.171.168
      Jan 19, 2025 03:53:00.106724977 CET3890613566192.168.2.1483.222.171.168
      Jan 19, 2025 03:53:00.107868910 CET5440613566192.168.2.1483.222.110.36
      Jan 19, 2025 03:53:00.111006975 CET4315213566192.168.2.1483.222.179.198
      Jan 19, 2025 03:53:00.111942053 CET135663890683.222.171.168192.168.2.14
      Jan 19, 2025 03:53:00.112000942 CET3890613566192.168.2.1483.222.171.168
      Jan 19, 2025 03:53:00.112977028 CET135665440683.222.110.36192.168.2.14
      Jan 19, 2025 03:53:00.113030910 CET5440613566192.168.2.1483.222.110.36
      Jan 19, 2025 03:53:00.114100933 CET5729013566192.168.2.1483.222.12.215
      Jan 19, 2025 03:53:00.116064072 CET135664315283.222.179.198192.168.2.14
      Jan 19, 2025 03:53:00.116117001 CET4315213566192.168.2.1483.222.179.198
      Jan 19, 2025 03:53:00.117702961 CET4834813566192.168.2.1483.222.10.153
      Jan 19, 2025 03:53:00.118988037 CET135665729083.222.12.215192.168.2.14
      Jan 19, 2025 03:53:00.119031906 CET5729013566192.168.2.1483.222.12.215
      Jan 19, 2025 03:53:00.121330976 CET5464213566192.168.2.1483.222.165.79
      Jan 19, 2025 03:53:00.122821093 CET135664834883.222.10.153192.168.2.14
      Jan 19, 2025 03:53:00.123002052 CET4834813566192.168.2.1483.222.10.153
      Jan 19, 2025 03:53:00.124763012 CET4950013566192.168.2.1483.222.64.244
      Jan 19, 2025 03:53:00.126234055 CET135665464283.222.165.79192.168.2.14
      Jan 19, 2025 03:53:00.126271963 CET5464213566192.168.2.1483.222.165.79
      Jan 19, 2025 03:53:00.128189087 CET4734613566192.168.2.1483.222.32.121
      Jan 19, 2025 03:53:00.129630089 CET135664950083.222.64.244192.168.2.14
      Jan 19, 2025 03:53:00.129678011 CET4950013566192.168.2.1483.222.64.244
      Jan 19, 2025 03:53:00.132345915 CET4307213566192.168.2.1483.222.86.81
      Jan 19, 2025 03:53:00.133260965 CET135664734683.222.32.121192.168.2.14
      Jan 19, 2025 03:53:00.133325100 CET4734613566192.168.2.1483.222.32.121
      Jan 19, 2025 03:53:00.136796951 CET5246213566192.168.2.1483.222.74.232
      Jan 19, 2025 03:53:00.137450933 CET135664307283.222.86.81192.168.2.14
      Jan 19, 2025 03:53:00.137552023 CET4307213566192.168.2.1483.222.86.81
      Jan 19, 2025 03:53:00.141753912 CET135665246283.222.74.232192.168.2.14
      Jan 19, 2025 03:53:00.141819954 CET5246213566192.168.2.1483.222.74.232
      Jan 19, 2025 03:53:00.144576073 CET4141413566192.168.2.1483.222.249.63
      Jan 19, 2025 03:53:00.146240950 CET5304813566192.168.2.1483.222.172.206
      Jan 19, 2025 03:53:00.149759054 CET135664141483.222.249.63192.168.2.14
      Jan 19, 2025 03:53:00.149940968 CET4141413566192.168.2.1483.222.249.63
      Jan 19, 2025 03:53:00.151141882 CET135665304883.222.172.206192.168.2.14
      Jan 19, 2025 03:53:00.151204109 CET5304813566192.168.2.1483.222.172.206
      Jan 19, 2025 03:53:00.167809010 CET5304813566192.168.2.1483.222.172.206
      Jan 19, 2025 03:53:00.173115969 CET135665304883.222.172.206192.168.2.14
      Jan 19, 2025 03:53:00.173177004 CET5304813566192.168.2.1483.222.172.206
      Jan 19, 2025 03:53:00.198250055 CET4051413566192.168.2.1483.222.187.204
      Jan 19, 2025 03:53:00.203458071 CET135664051483.222.187.204192.168.2.14
      Jan 19, 2025 03:53:00.203528881 CET4051413566192.168.2.1483.222.187.204
      Jan 19, 2025 03:53:00.205667973 CET4051413566192.168.2.1483.222.187.204
      Jan 19, 2025 03:53:00.206835032 CET3498613566192.168.2.1483.222.123.192
      Jan 19, 2025 03:53:00.210814953 CET135664051483.222.187.204192.168.2.14
      Jan 19, 2025 03:53:00.210874081 CET4051413566192.168.2.1483.222.187.204
      Jan 19, 2025 03:53:00.211266994 CET5519813566192.168.2.1483.222.54.146
      Jan 19, 2025 03:53:00.211721897 CET135663498683.222.123.192192.168.2.14
      Jan 19, 2025 03:53:00.211782932 CET3498613566192.168.2.1483.222.123.192
      Jan 19, 2025 03:53:00.213160992 CET4913213566192.168.2.1483.222.56.225
      Jan 19, 2025 03:53:00.216320038 CET135665519883.222.54.146192.168.2.14
      Jan 19, 2025 03:53:00.216388941 CET5519813566192.168.2.1483.222.54.146
      Jan 19, 2025 03:53:00.217973948 CET135664913283.222.56.225192.168.2.14
      Jan 19, 2025 03:53:00.218019962 CET4913213566192.168.2.1483.222.56.225
      Jan 19, 2025 03:53:00.228980064 CET4913213566192.168.2.1483.222.56.225
      Jan 19, 2025 03:53:00.230067968 CET5997213566192.168.2.1483.222.58.166
      Jan 19, 2025 03:53:00.234004021 CET135664913283.222.56.225192.168.2.14
      Jan 19, 2025 03:53:00.234049082 CET4913213566192.168.2.1483.222.56.225
      Jan 19, 2025 03:53:00.234627962 CET4593613566192.168.2.1483.222.6.237
      Jan 19, 2025 03:53:00.234858036 CET135665997283.222.58.166192.168.2.14
      Jan 19, 2025 03:53:00.234905005 CET5997213566192.168.2.1483.222.58.166
      Jan 19, 2025 03:53:00.239569902 CET135664593683.222.6.237192.168.2.14
      Jan 19, 2025 03:53:00.239619017 CET4593613566192.168.2.1483.222.6.237
      Jan 19, 2025 03:53:00.247958899 CET4593613566192.168.2.1483.222.6.237
      Jan 19, 2025 03:53:00.248404980 CET5342013566192.168.2.1483.222.108.18
      Jan 19, 2025 03:53:00.249250889 CET5628813566192.168.2.1483.222.196.119
      Jan 19, 2025 03:53:00.250792027 CET4312013566192.168.2.1483.222.171.105
      Jan 19, 2025 03:53:00.251718044 CET4919613566192.168.2.1483.222.198.236
      Jan 19, 2025 03:53:00.252759933 CET5978213566192.168.2.1483.222.93.230
      Jan 19, 2025 03:53:00.253089905 CET135664593683.222.6.237192.168.2.14
      Jan 19, 2025 03:53:00.253211975 CET4593613566192.168.2.1483.222.6.237
      Jan 19, 2025 03:53:00.253401041 CET135665342083.222.108.18192.168.2.14
      Jan 19, 2025 03:53:00.253540039 CET5342013566192.168.2.1483.222.108.18
      Jan 19, 2025 03:53:00.253774881 CET4803213566192.168.2.1483.222.101.180
      Jan 19, 2025 03:53:00.254020929 CET135665628883.222.196.119192.168.2.14
      Jan 19, 2025 03:53:00.254062891 CET5628813566192.168.2.1483.222.196.119
      Jan 19, 2025 03:53:00.254791975 CET4153613566192.168.2.1483.222.55.175
      Jan 19, 2025 03:53:00.255676031 CET135664312083.222.171.105192.168.2.14
      Jan 19, 2025 03:53:00.255829096 CET4312013566192.168.2.1483.222.171.105
      Jan 19, 2025 03:53:00.256421089 CET3598413566192.168.2.1483.222.156.48
      Jan 19, 2025 03:53:00.256589890 CET135664919683.222.198.236192.168.2.14
      Jan 19, 2025 03:53:00.256633997 CET4919613566192.168.2.1483.222.198.236
      Jan 19, 2025 03:53:00.257246017 CET4022213566192.168.2.1483.222.238.72
      Jan 19, 2025 03:53:00.257589102 CET135665978283.222.93.230192.168.2.14
      Jan 19, 2025 03:53:00.257631063 CET5978213566192.168.2.1483.222.93.230
      Jan 19, 2025 03:53:00.258236885 CET5414213566192.168.2.1483.222.254.170
      Jan 19, 2025 03:53:00.258606911 CET135664803283.222.101.180192.168.2.14
      Jan 19, 2025 03:53:00.258646965 CET4803213566192.168.2.1483.222.101.180
      Jan 19, 2025 03:53:00.259645939 CET135664153683.222.55.175192.168.2.14
      Jan 19, 2025 03:53:00.259816885 CET4153613566192.168.2.1483.222.55.175
      Jan 19, 2025 03:53:00.260026932 CET4506613566192.168.2.1483.222.21.121
      Jan 19, 2025 03:53:00.261267900 CET135663598483.222.156.48192.168.2.14
      Jan 19, 2025 03:53:00.261342049 CET3300413566192.168.2.1483.222.106.75
      Jan 19, 2025 03:53:00.261418104 CET3598413566192.168.2.1483.222.156.48
      Jan 19, 2025 03:53:00.262037992 CET135664022283.222.238.72192.168.2.14
      Jan 19, 2025 03:53:00.262089014 CET4022213566192.168.2.1483.222.238.72
      Jan 19, 2025 03:53:00.262377024 CET4005613566192.168.2.1483.222.12.163
      Jan 19, 2025 03:53:00.263025045 CET135665414283.222.254.170192.168.2.14
      Jan 19, 2025 03:53:00.263072968 CET5414213566192.168.2.1483.222.254.170
      Jan 19, 2025 03:53:00.263866901 CET6031013566192.168.2.1483.222.44.70
      Jan 19, 2025 03:53:00.264779091 CET135664506683.222.21.121192.168.2.14
      Jan 19, 2025 03:53:00.264816046 CET4506613566192.168.2.1483.222.21.121
      Jan 19, 2025 03:53:00.265321970 CET4006413566192.168.2.1483.222.73.50
      Jan 19, 2025 03:53:00.266103983 CET135663300483.222.106.75192.168.2.14
      Jan 19, 2025 03:53:00.266143084 CET3300413566192.168.2.1483.222.106.75
      Jan 19, 2025 03:53:00.266325951 CET3786013566192.168.2.1483.222.52.182
      Jan 19, 2025 03:53:00.267200947 CET135664005683.222.12.163192.168.2.14
      Jan 19, 2025 03:53:00.267245054 CET4005613566192.168.2.1483.222.12.163
      Jan 19, 2025 03:53:00.267739058 CET3280013566192.168.2.1483.222.69.248
      Jan 19, 2025 03:53:00.268692017 CET135666031083.222.44.70192.168.2.14
      Jan 19, 2025 03:53:00.268738031 CET6031013566192.168.2.1483.222.44.70
      Jan 19, 2025 03:53:00.269148111 CET5845013566192.168.2.1483.222.45.240
      Jan 19, 2025 03:53:00.270087957 CET135664006483.222.73.50192.168.2.14
      Jan 19, 2025 03:53:00.270147085 CET4006413566192.168.2.1483.222.73.50
      Jan 19, 2025 03:53:00.270271063 CET4288413566192.168.2.1483.222.98.243
      Jan 19, 2025 03:53:00.271143913 CET135663786083.222.52.182192.168.2.14
      Jan 19, 2025 03:53:00.271182060 CET3786013566192.168.2.1483.222.52.182
      Jan 19, 2025 03:53:00.271585941 CET3359813566192.168.2.1483.222.220.191
      Jan 19, 2025 03:53:00.272485018 CET135663280083.222.69.248192.168.2.14
      Jan 19, 2025 03:53:00.272525072 CET3280013566192.168.2.1483.222.69.248
      Jan 19, 2025 03:53:00.273118973 CET5318413566192.168.2.1483.222.217.65
      Jan 19, 2025 03:53:00.273909092 CET135665845083.222.45.240192.168.2.14
      Jan 19, 2025 03:53:00.273952007 CET5845013566192.168.2.1483.222.45.240
      Jan 19, 2025 03:53:00.274996996 CET4705413566192.168.2.1483.222.115.17
      Jan 19, 2025 03:53:00.275032043 CET135664288483.222.98.243192.168.2.14
      Jan 19, 2025 03:53:00.275070906 CET4288413566192.168.2.1483.222.98.243
      Jan 19, 2025 03:53:00.276367903 CET135663359883.222.220.191192.168.2.14
      Jan 19, 2025 03:53:00.276407003 CET3359813566192.168.2.1483.222.220.191
      Jan 19, 2025 03:53:00.277865887 CET5335813566192.168.2.1483.222.241.15
      Jan 19, 2025 03:53:00.277971983 CET135665318483.222.217.65192.168.2.14
      Jan 19, 2025 03:53:00.278198004 CET5318413566192.168.2.1483.222.217.65
      Jan 19, 2025 03:53:00.279860020 CET135664705483.222.115.17192.168.2.14
      Jan 19, 2025 03:53:00.279905081 CET4705413566192.168.2.1483.222.115.17
      Jan 19, 2025 03:53:00.280042887 CET3856013566192.168.2.1483.222.65.223
      Jan 19, 2025 03:53:00.281935930 CET4897213566192.168.2.1483.222.88.64
      Jan 19, 2025 03:53:00.282816887 CET135665335883.222.241.15192.168.2.14
      Jan 19, 2025 03:53:00.282876968 CET5335813566192.168.2.1483.222.241.15
      Jan 19, 2025 03:53:00.283427954 CET3631213566192.168.2.1483.222.137.109
      Jan 19, 2025 03:53:00.284147978 CET4559413566192.168.2.1483.222.185.244
      Jan 19, 2025 03:53:00.284843922 CET135663856083.222.65.223192.168.2.14
      Jan 19, 2025 03:53:00.284881115 CET3856013566192.168.2.1483.222.65.223
      Jan 19, 2025 03:53:00.285011053 CET3442213566192.168.2.1483.222.184.197
      Jan 19, 2025 03:53:00.285619020 CET4396813566192.168.2.1483.222.151.228
      Jan 19, 2025 03:53:00.286418915 CET5440213566192.168.2.1483.222.12.224
      Jan 19, 2025 03:53:00.286797047 CET135664897283.222.88.64192.168.2.14
      Jan 19, 2025 03:53:00.286850929 CET4897213566192.168.2.1483.222.88.64
      Jan 19, 2025 03:53:00.287071943 CET4264013566192.168.2.1483.222.23.64
      Jan 19, 2025 03:53:00.287750006 CET4075413566192.168.2.1483.222.150.92
      Jan 19, 2025 03:53:00.288197041 CET135663631283.222.137.109192.168.2.14
      Jan 19, 2025 03:53:00.288233042 CET3631213566192.168.2.1483.222.137.109
      Jan 19, 2025 03:53:00.288471937 CET5584413566192.168.2.1483.222.56.195
      Jan 19, 2025 03:53:00.288976908 CET135664559483.222.185.244192.168.2.14
      Jan 19, 2025 03:53:00.289014101 CET4559413566192.168.2.1483.222.185.244
      Jan 19, 2025 03:53:00.289172888 CET5154213566192.168.2.1483.222.76.154
      Jan 19, 2025 03:53:00.289871931 CET135663442283.222.184.197192.168.2.14
      Jan 19, 2025 03:53:00.289916039 CET4744613566192.168.2.1483.222.182.41
      Jan 19, 2025 03:53:00.290013075 CET3442213566192.168.2.1483.222.184.197
      Jan 19, 2025 03:53:00.290468931 CET135664396883.222.151.228192.168.2.14
      Jan 19, 2025 03:53:00.290505886 CET4396813566192.168.2.1483.222.151.228
      Jan 19, 2025 03:53:00.290632963 CET5470613566192.168.2.1483.222.90.144
      Jan 19, 2025 03:53:00.291224003 CET135665440283.222.12.224192.168.2.14
      Jan 19, 2025 03:53:00.291269064 CET5440213566192.168.2.1483.222.12.224
      Jan 19, 2025 03:53:00.291330099 CET5031013566192.168.2.1483.222.106.205
      Jan 19, 2025 03:53:00.291939020 CET135664264083.222.23.64192.168.2.14
      Jan 19, 2025 03:53:00.292082071 CET5502413566192.168.2.1483.222.161.91
      Jan 19, 2025 03:53:00.292084932 CET4264013566192.168.2.1483.222.23.64
      Jan 19, 2025 03:53:00.292552948 CET135664075483.222.150.92192.168.2.14
      Jan 19, 2025 03:53:00.292593002 CET4075413566192.168.2.1483.222.150.92
      Jan 19, 2025 03:53:00.292946100 CET4958213566192.168.2.1483.222.221.226
      Jan 19, 2025 03:53:00.293220043 CET135665584483.222.56.195192.168.2.14
      Jan 19, 2025 03:53:00.293258905 CET5584413566192.168.2.1483.222.56.195
      Jan 19, 2025 03:53:00.293549061 CET3900213566192.168.2.1483.222.59.53
      Jan 19, 2025 03:53:00.293912888 CET135665154283.222.76.154192.168.2.14
      Jan 19, 2025 03:53:00.293951988 CET5154213566192.168.2.1483.222.76.154
      Jan 19, 2025 03:53:00.294277906 CET6049613566192.168.2.1483.222.34.196
      Jan 19, 2025 03:53:00.294811964 CET135664744683.222.182.41192.168.2.14
      Jan 19, 2025 03:53:00.294960976 CET4744613566192.168.2.1483.222.182.41
      Jan 19, 2025 03:53:00.295085907 CET3610413566192.168.2.1483.222.162.220
      Jan 19, 2025 03:53:00.295475960 CET135665470683.222.90.144192.168.2.14
      Jan 19, 2025 03:53:00.295512915 CET5470613566192.168.2.1483.222.90.144
      Jan 19, 2025 03:53:00.295758009 CET3749413566192.168.2.1483.222.184.90
      Jan 19, 2025 03:53:00.296094894 CET135665031083.222.106.205192.168.2.14
      Jan 19, 2025 03:53:00.296133995 CET5031013566192.168.2.1483.222.106.205
      Jan 19, 2025 03:53:00.296485901 CET3541813566192.168.2.1483.222.161.79
      Jan 19, 2025 03:53:00.296917915 CET135665502483.222.161.91192.168.2.14
      Jan 19, 2025 03:53:00.296958923 CET5502413566192.168.2.1483.222.161.91
      Jan 19, 2025 03:53:00.297214985 CET4257013566192.168.2.1483.222.62.173
      Jan 19, 2025 03:53:00.297830105 CET135664958283.222.221.226192.168.2.14
      Jan 19, 2025 03:53:00.297934055 CET4249013566192.168.2.1483.222.48.85
      Jan 19, 2025 03:53:00.297995090 CET4958213566192.168.2.1483.222.221.226
      Jan 19, 2025 03:53:00.298310041 CET135663900283.222.59.53192.168.2.14
      Jan 19, 2025 03:53:00.298345089 CET3900213566192.168.2.1483.222.59.53
      Jan 19, 2025 03:53:00.298754930 CET3970413566192.168.2.1483.222.237.198
      Jan 19, 2025 03:53:00.299056053 CET135666049683.222.34.196192.168.2.14
      Jan 19, 2025 03:53:00.299091101 CET6049613566192.168.2.1483.222.34.196
      Jan 19, 2025 03:53:00.299401045 CET3859213566192.168.2.1483.222.177.38
      Jan 19, 2025 03:53:00.299959898 CET135663610483.222.162.220192.168.2.14
      Jan 19, 2025 03:53:00.300108910 CET3610413566192.168.2.1483.222.162.220
      Jan 19, 2025 03:53:00.300131083 CET5226613566192.168.2.1483.222.138.254
      Jan 19, 2025 03:53:00.300576925 CET135663749483.222.184.90192.168.2.14
      Jan 19, 2025 03:53:00.300704956 CET3749413566192.168.2.1483.222.184.90
      Jan 19, 2025 03:53:00.300854921 CET4295013566192.168.2.1483.222.192.64
      Jan 19, 2025 03:53:00.301265955 CET135663541883.222.161.79192.168.2.14
      Jan 19, 2025 03:53:00.301321030 CET3541813566192.168.2.1483.222.161.79
      Jan 19, 2025 03:53:00.301567078 CET5657813566192.168.2.1483.222.39.26
      Jan 19, 2025 03:53:00.301954985 CET135664257083.222.62.173192.168.2.14
      Jan 19, 2025 03:53:00.301990032 CET4257013566192.168.2.1483.222.62.173
      Jan 19, 2025 03:53:00.302314043 CET5212413566192.168.2.1483.222.208.145
      Jan 19, 2025 03:53:00.302680969 CET135664249083.222.48.85192.168.2.14
      Jan 19, 2025 03:53:00.302720070 CET4249013566192.168.2.1483.222.48.85
      Jan 19, 2025 03:53:00.303059101 CET3782013566192.168.2.1483.222.232.113
      Jan 19, 2025 03:53:00.303527117 CET135663970483.222.237.198192.168.2.14
      Jan 19, 2025 03:53:00.303584099 CET3970413566192.168.2.1483.222.237.198
      Jan 19, 2025 03:53:00.303814888 CET4333813566192.168.2.1483.222.237.197
      Jan 19, 2025 03:53:00.304174900 CET135663859283.222.177.38192.168.2.14
      Jan 19, 2025 03:53:00.304213047 CET3859213566192.168.2.1483.222.177.38
      Jan 19, 2025 03:53:00.304554939 CET3544613566192.168.2.1483.222.84.40
      Jan 19, 2025 03:53:00.304929972 CET135665226683.222.138.254192.168.2.14
      Jan 19, 2025 03:53:00.304964066 CET5226613566192.168.2.1483.222.138.254
      Jan 19, 2025 03:53:00.305293083 CET4340213566192.168.2.1483.222.250.118
      Jan 19, 2025 03:53:00.305665970 CET135664295083.222.192.64192.168.2.14
      Jan 19, 2025 03:53:00.305702925 CET4295013566192.168.2.1483.222.192.64
      Jan 19, 2025 03:53:00.306031942 CET5457013566192.168.2.1483.222.236.156
      Jan 19, 2025 03:53:00.306325912 CET135665657883.222.39.26192.168.2.14
      Jan 19, 2025 03:53:00.306359053 CET5657813566192.168.2.1483.222.39.26
      Jan 19, 2025 03:53:00.306796074 CET5561413566192.168.2.1483.222.82.165
      Jan 19, 2025 03:53:00.307138920 CET135665212483.222.208.145192.168.2.14
      Jan 19, 2025 03:53:00.307177067 CET5212413566192.168.2.1483.222.208.145
      Jan 19, 2025 03:53:00.307600975 CET3650413566192.168.2.1483.222.246.244
      Jan 19, 2025 03:53:00.307899952 CET135663782083.222.232.113192.168.2.14
      Jan 19, 2025 03:53:00.307945967 CET3782013566192.168.2.1483.222.232.113
      Jan 19, 2025 03:53:00.308306932 CET5011213566192.168.2.1483.222.244.52
      Jan 19, 2025 03:53:00.308532000 CET135664333883.222.237.197192.168.2.14
      Jan 19, 2025 03:53:00.308572054 CET4333813566192.168.2.1483.222.237.197
      Jan 19, 2025 03:53:00.309058905 CET5636213566192.168.2.1483.222.161.36
      Jan 19, 2025 03:53:00.309370041 CET135663544683.222.84.40192.168.2.14
      Jan 19, 2025 03:53:00.309408903 CET3544613566192.168.2.1483.222.84.40
      Jan 19, 2025 03:53:00.309875011 CET4345013566192.168.2.1483.222.138.143
      Jan 19, 2025 03:53:00.310106993 CET135664340283.222.250.118192.168.2.14
      Jan 19, 2025 03:53:00.310142994 CET4340213566192.168.2.1483.222.250.118
      Jan 19, 2025 03:53:00.310507059 CET3619413566192.168.2.1483.222.235.59
      Jan 19, 2025 03:53:00.310858965 CET135665457083.222.236.156192.168.2.14
      Jan 19, 2025 03:53:00.310902119 CET5457013566192.168.2.1483.222.236.156
      Jan 19, 2025 03:53:00.311253071 CET3327413566192.168.2.1483.222.181.117
      Jan 19, 2025 03:53:00.311644077 CET135665561483.222.82.165192.168.2.14
      Jan 19, 2025 03:53:00.311822891 CET5561413566192.168.2.1483.222.82.165
      Jan 19, 2025 03:53:00.312139034 CET4964613566192.168.2.1483.222.57.117
      Jan 19, 2025 03:53:00.312381029 CET135663650483.222.246.244192.168.2.14
      Jan 19, 2025 03:53:00.312416077 CET3650413566192.168.2.1483.222.246.244
      Jan 19, 2025 03:53:00.312865973 CET6061013566192.168.2.1483.222.181.96
      Jan 19, 2025 03:53:00.313129902 CET135665011283.222.244.52192.168.2.14
      Jan 19, 2025 03:53:00.313168049 CET5011213566192.168.2.1483.222.244.52
      Jan 19, 2025 03:53:00.313519001 CET5955413566192.168.2.1483.222.144.134
      Jan 19, 2025 03:53:00.313884974 CET135665636283.222.161.36192.168.2.14
      Jan 19, 2025 03:53:00.313936949 CET5636213566192.168.2.1483.222.161.36
      Jan 19, 2025 03:53:00.314321995 CET3435013566192.168.2.1483.222.242.120
      Jan 19, 2025 03:53:00.314738035 CET135664345083.222.138.143192.168.2.14
      Jan 19, 2025 03:53:00.314783096 CET4345013566192.168.2.1483.222.138.143
      Jan 19, 2025 03:53:00.315076113 CET5527013566192.168.2.1483.222.247.223
      Jan 19, 2025 03:53:00.315280914 CET135663619483.222.235.59192.168.2.14
      Jan 19, 2025 03:53:00.315323114 CET3619413566192.168.2.1483.222.235.59
      Jan 19, 2025 03:53:00.316073895 CET135663327483.222.181.117192.168.2.14
      Jan 19, 2025 03:53:00.316113949 CET3327413566192.168.2.1483.222.181.117
      Jan 19, 2025 03:53:00.316988945 CET135664964683.222.57.117192.168.2.14
      Jan 19, 2025 03:53:00.317163944 CET4964613566192.168.2.1483.222.57.117
      Jan 19, 2025 03:53:00.317723036 CET135666061083.222.181.96192.168.2.14
      Jan 19, 2025 03:53:00.317893982 CET6061013566192.168.2.1483.222.181.96
      Jan 19, 2025 03:53:00.318285942 CET135665955483.222.144.134192.168.2.14
      Jan 19, 2025 03:53:00.318329096 CET5955413566192.168.2.1483.222.144.134
      Jan 19, 2025 03:53:00.319076061 CET135663435083.222.242.120192.168.2.14
      Jan 19, 2025 03:53:00.319117069 CET3435013566192.168.2.1483.222.242.120
      Jan 19, 2025 03:53:00.319818020 CET135665527083.222.247.223192.168.2.14
      Jan 19, 2025 03:53:00.319859982 CET5527013566192.168.2.1483.222.247.223
      Jan 19, 2025 03:53:00.326950073 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:53:00.331840992 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:53:00.331890106 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:53:00.332737923 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:53:00.337749004 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:53:00.337826967 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:53:00.342892885 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:53:10.342681885 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:53:10.347840071 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:53:10.566024065 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:53:10.566243887 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:53:10.923643112 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:53:10.923851967 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:54:10.979558945 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:54:10.985168934 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:54:11.186666965 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:54:11.186877966 CET5653613566192.168.2.1483.222.191.90
      Jan 19, 2025 03:54:11.926434994 CET135665653683.222.191.90192.168.2.14
      Jan 19, 2025 03:54:11.926760912 CET5653613566192.168.2.1483.222.191.90
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 03:53:00.317087889 CET5738053192.168.2.148.8.8.8
      Jan 19, 2025 03:53:00.326082945 CET53573808.8.8.8192.168.2.14
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 19, 2025 03:53:00.317087889 CET192.168.2.148.8.8.80x1c0Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 19, 2025 03:53:00.326082945 CET8.8.8.8192.168.2.140x1c0No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

      System Behavior

      Start time (UTC):02:52:59
      Start date (UTC):19/01/2025
      Path:/tmp/loki.arm4.elf
      Arguments:/tmp/loki.arm4.elf
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      Start time (UTC):02:52:59
      Start date (UTC):19/01/2025
      Path:/tmp/loki.arm4.elf
      Arguments:-
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

      Start time (UTC):02:52:59
      Start date (UTC):19/01/2025
      Path:/tmp/loki.arm4.elf
      Arguments:-
      File size:4956856 bytes
      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1