Edit tour

Linux Analysis Report
loki.i686.elf

Overview

General Information

Sample name:loki.i686.elf
Analysis ID:1594514
MD5:6f919b612a801edc62474fbd619420fc
SHA1:79f495e4a44279c382531d2b126b4509b7566996
SHA256:3cfdcca4113cab1b5901ab14e777ba7655d5f6f1db6f99c04ec954d9c931227e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Suricata IDS alerts with low severity for network traffic
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594514
Start date and time:2025-01-19 04:02:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:loki.i686.elf
Detection:MAL
Classification:mal60.linELF@0/0@1/0
Command:/tmp/loki.i686.elf
PID:5433
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • loki.i686.elf (PID: 5433, Parent: 5359, MD5: 6f919b612a801edc62474fbd619420fc) Arguments: /tmp/loki.i686.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
loki.i686.elfLinux_Trojan_Mirai_268aac0bunknownunknown
  • 0x54ff:$a: 24 18 0F B7 44 24 20 8B 54 24 1C 83 F9 01 8B 7E 0C 89 04 24 8B
loki.i686.elfLinux_Trojan_Mirai_0cb1699cunknownunknown
  • 0x54b2:$a: DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 10 0F B7 02 83 E9 02 83
loki.i686.elfLinux_Trojan_Mirai_2e3f67a9unknownunknown
  • 0x682:$a: 53 83 EC 04 0F B6 74 24 14 8B 5C 24 18 8B 7C 24 20 0F B6 44
  • 0x6e2:$a: 53 83 EC 04 0F B6 74 24 14 8B 5C 24 18 8B 7C 24 20 0F B6 44
loki.i686.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x7992:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
loki.i686.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x83ff:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
SourceRuleDescriptionAuthorStrings
5433.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_268aac0bunknownunknown
  • 0x54ff:$a: 24 18 0F B7 44 24 20 8B 54 24 1C 83 F9 01 8B 7E 0C 89 04 24 8B
5433.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_0cb1699cunknownunknown
  • 0x54b2:$a: DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 10 0F B7 02 83 E9 02 83
5433.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_2e3f67a9unknownunknown
  • 0x682:$a: 53 83 EC 04 0F B6 74 24 14 8B 5C 24 18 8B 7C 24 20 0F B6 44
  • 0x6e2:$a: 53 83 EC 04 0F B6 74 24 14 8B 5C 24 18 8B 7C 24 20 0F B6 44
5433.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x7992:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
5433.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x83ff:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 5 entries
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T04:02:58.442061+010025000342Misc Attack83.222.191.9013566192.168.2.1342870TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: loki.i686.elfReversingLabs: Detection: 28%
Source: loki.i686.elfVirustotal: Detection: 18%Perma Link
Source: loki.i686.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.13:49222 -> 83.222.20.136:13566
Source: global trafficTCP traffic: 192.168.2.13:58962 -> 83.222.210.113:13566
Source: global trafficTCP traffic: 192.168.2.13:48780 -> 83.222.121.250:13566
Source: global trafficTCP traffic: 192.168.2.13:56414 -> 83.222.236.18:13566
Source: global trafficTCP traffic: 192.168.2.13:48934 -> 83.222.124.116:13566
Source: global trafficTCP traffic: 192.168.2.13:58292 -> 83.222.60.88:13566
Source: global trafficTCP traffic: 192.168.2.13:53210 -> 83.222.75.150:13566
Source: global trafficTCP traffic: 192.168.2.13:44424 -> 83.222.88.101:13566
Source: global trafficTCP traffic: 192.168.2.13:48824 -> 83.222.109.15:13566
Source: global trafficTCP traffic: 192.168.2.13:46248 -> 83.222.209.3:13566
Source: global trafficTCP traffic: 192.168.2.13:60832 -> 83.222.132.198:13566
Source: global trafficTCP traffic: 192.168.2.13:48756 -> 83.222.165.179:13566
Source: global trafficTCP traffic: 192.168.2.13:43398 -> 83.222.208.121:13566
Source: global trafficTCP traffic: 192.168.2.13:58718 -> 83.222.122.208:13566
Source: global trafficTCP traffic: 192.168.2.13:59474 -> 83.222.165.216:13566
Source: global trafficTCP traffic: 192.168.2.13:60886 -> 83.222.249.250:13566
Source: global trafficTCP traffic: 192.168.2.13:46132 -> 83.222.245.114:13566
Source: global trafficTCP traffic: 192.168.2.13:44376 -> 83.222.244.226:13566
Source: global trafficTCP traffic: 192.168.2.13:56854 -> 83.222.158.74:13566
Source: global trafficTCP traffic: 192.168.2.13:47766 -> 83.222.79.29:13566
Source: global trafficTCP traffic: 192.168.2.13:42924 -> 83.222.176.133:13566
Source: global trafficTCP traffic: 192.168.2.13:41524 -> 83.222.13.26:13566
Source: global trafficTCP traffic: 192.168.2.13:43804 -> 83.222.83.41:13566
Source: global trafficTCP traffic: 192.168.2.13:42164 -> 83.222.73.246:13566
Source: global trafficTCP traffic: 192.168.2.13:47478 -> 83.222.157.193:13566
Source: global trafficTCP traffic: 192.168.2.13:59072 -> 83.222.128.66:13566
Source: global trafficTCP traffic: 192.168.2.13:47936 -> 83.222.229.109:13566
Source: global trafficTCP traffic: 192.168.2.13:56442 -> 83.222.175.146:13566
Source: global trafficTCP traffic: 192.168.2.13:53732 -> 83.222.148.154:13566
Source: global trafficTCP traffic: 192.168.2.13:38912 -> 83.222.95.165:13566
Source: global trafficTCP traffic: 192.168.2.13:52570 -> 83.222.179.102:13566
Source: global trafficTCP traffic: 192.168.2.13:55894 -> 83.222.153.101:13566
Source: global trafficTCP traffic: 192.168.2.13:40816 -> 83.222.135.136:13566
Source: global trafficTCP traffic: 192.168.2.13:48076 -> 83.222.26.218:13566
Source: global trafficTCP traffic: 192.168.2.13:36972 -> 83.222.178.148:13566
Source: global trafficTCP traffic: 192.168.2.13:43650 -> 83.222.170.80:13566
Source: global trafficTCP traffic: 192.168.2.13:35386 -> 83.222.222.243:13566
Source: global trafficTCP traffic: 192.168.2.13:47876 -> 83.222.70.142:13566
Source: global trafficTCP traffic: 192.168.2.13:50016 -> 83.222.120.149:13566
Source: global trafficTCP traffic: 192.168.2.13:49400 -> 83.222.171.13:13566
Source: global trafficTCP traffic: 192.168.2.13:50678 -> 83.222.47.95:13566
Source: global trafficTCP traffic: 192.168.2.13:53020 -> 83.222.32.243:13566
Source: global trafficTCP traffic: 192.168.2.13:35122 -> 83.222.15.185:13566
Source: global trafficTCP traffic: 192.168.2.13:54188 -> 83.222.88.190:13566
Source: global trafficTCP traffic: 192.168.2.13:53006 -> 83.222.99.79:13566
Source: global trafficTCP traffic: 192.168.2.13:50746 -> 83.222.4.83:13566
Source: global trafficTCP traffic: 192.168.2.13:38544 -> 83.222.115.204:13566
Source: global trafficTCP traffic: 192.168.2.13:51160 -> 83.222.75.184:13566
Source: global trafficTCP traffic: 192.168.2.13:44592 -> 83.222.11.234:13566
Source: global trafficTCP traffic: 192.168.2.13:38698 -> 83.222.197.137:13566
Source: global trafficTCP traffic: 192.168.2.13:59784 -> 83.222.185.111:13566
Source: global trafficTCP traffic: 192.168.2.13:34500 -> 83.222.215.37:13566
Source: global trafficTCP traffic: 192.168.2.13:59204 -> 83.222.217.152:13566
Source: global trafficTCP traffic: 192.168.2.13:51124 -> 83.222.99.32:13566
Source: global trafficTCP traffic: 192.168.2.13:55026 -> 83.222.38.219:13566
Source: global trafficTCP traffic: 192.168.2.13:45830 -> 83.222.181.210:13566
Source: global trafficTCP traffic: 192.168.2.13:46862 -> 83.222.232.229:13566
Source: global trafficTCP traffic: 192.168.2.13:48108 -> 83.222.49.91:13566
Source: global trafficTCP traffic: 192.168.2.13:45230 -> 83.222.177.81:13566
Source: global trafficTCP traffic: 192.168.2.13:35834 -> 83.222.127.85:13566
Source: global trafficTCP traffic: 192.168.2.13:47402 -> 83.222.164.106:13566
Source: global trafficTCP traffic: 192.168.2.13:57190 -> 83.222.95.226:13566
Source: global trafficTCP traffic: 192.168.2.13:50052 -> 83.222.78.192:13566
Source: global trafficTCP traffic: 192.168.2.13:37860 -> 83.222.10.167:13566
Source: global trafficTCP traffic: 192.168.2.13:59530 -> 83.222.144.146:13566
Source: global trafficTCP traffic: 192.168.2.13:60602 -> 83.222.254.8:13566
Source: global trafficTCP traffic: 192.168.2.13:43752 -> 83.222.1.222:13566
Source: global trafficTCP traffic: 192.168.2.13:45888 -> 83.222.5.73:13566
Source: global trafficTCP traffic: 192.168.2.13:41218 -> 83.222.225.100:13566
Source: global trafficTCP traffic: 192.168.2.13:33274 -> 83.222.205.123:13566
Source: global trafficTCP traffic: 192.168.2.13:40720 -> 83.222.64.180:13566
Source: global trafficTCP traffic: 192.168.2.13:35736 -> 83.222.218.40:13566
Source: global trafficTCP traffic: 192.168.2.13:49010 -> 83.222.153.11:13566
Source: global trafficTCP traffic: 192.168.2.13:47010 -> 83.222.132.74:13566
Source: global trafficTCP traffic: 192.168.2.13:49570 -> 83.222.92.210:13566
Source: global trafficTCP traffic: 192.168.2.13:45096 -> 83.222.11.102:13566
Source: global trafficTCP traffic: 192.168.2.13:42422 -> 83.222.121.138:13566
Source: global trafficTCP traffic: 192.168.2.13:45710 -> 83.222.108.95:13566
Source: global trafficTCP traffic: 192.168.2.13:39122 -> 83.222.187.216:13566
Source: global trafficTCP traffic: 192.168.2.13:41004 -> 83.222.67.57:13566
Source: global trafficTCP traffic: 192.168.2.13:58754 -> 83.222.218.211:13566
Source: global trafficTCP traffic: 192.168.2.13:55212 -> 83.222.28.205:13566
Source: global trafficTCP traffic: 192.168.2.13:34050 -> 83.222.203.223:13566
Source: global trafficTCP traffic: 192.168.2.13:48454 -> 83.222.6.113:13566
Source: global trafficTCP traffic: 192.168.2.13:60858 -> 83.222.49.188:13566
Source: global trafficTCP traffic: 192.168.2.13:42008 -> 83.222.190.254:13566
Source: global trafficTCP traffic: 192.168.2.13:37100 -> 83.222.112.224:13566
Source: global trafficTCP traffic: 192.168.2.13:33528 -> 83.222.154.9:13566
Source: global trafficTCP traffic: 192.168.2.13:53774 -> 83.222.235.30:13566
Source: global trafficTCP traffic: 192.168.2.13:55584 -> 83.222.84.71:13566
Source: global trafficTCP traffic: 192.168.2.13:58502 -> 83.222.240.95:13566
Source: global trafficTCP traffic: 192.168.2.13:45664 -> 83.222.173.106:13566
Source: global trafficTCP traffic: 192.168.2.13:59978 -> 83.222.233.104:13566
Source: global trafficTCP traffic: 192.168.2.13:35104 -> 83.222.66.85:13566
Source: global trafficTCP traffic: 192.168.2.13:58544 -> 83.222.199.133:13566
Source: global trafficTCP traffic: 192.168.2.13:59464 -> 83.222.143.161:13566
Source: global trafficTCP traffic: 192.168.2.13:47858 -> 83.222.88.90:13566
Source: global trafficTCP traffic: 192.168.2.13:58512 -> 83.222.129.117:13566
Source: global trafficTCP traffic: 192.168.2.13:42168 -> 83.222.39.63:13566
Source: global trafficTCP traffic: 192.168.2.13:36204 -> 83.222.251.121:13566
Source: global trafficTCP traffic: 192.168.2.13:39112 -> 83.222.115.89:13566
Source: global trafficTCP traffic: 192.168.2.13:52386 -> 83.222.202.108:13566
Source: global trafficTCP traffic: 192.168.2.13:59638 -> 83.222.89.100:13566
Source: global trafficTCP traffic: 192.168.2.13:34594 -> 83.222.117.68:13566
Source: global trafficTCP traffic: 192.168.2.13:42870 -> 83.222.191.90:13566
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.13:42870
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.20.136
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.121.250
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.236.18
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.124.116
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.60.88
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.75.150
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.88.101
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.109.15
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.209.3
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.132.198
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.179
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.208.121
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.122.208
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.216
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.249.250
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.245.114
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.244.226
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.158.74
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.79.29
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.176.133
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.13.26
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.83.41
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.246
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.157.193
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.128.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.229.109
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.175.146
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.148.154
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.95.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.179.102
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.101
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.135.136
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.26.218
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.178.148
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.170.80
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.222.243
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.70.142
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.120.149
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.171.13
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.47.95
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.32.243
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.15.185
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.88.190
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.99.79
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.4.83
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.115.204
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.75.184
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.11.234
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.197.137
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.185.111
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru

System Summary

barindex
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_268aac0b Author: unknown
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0cb1699c Author: unknown
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_2e3f67a9 Author: unknown
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b Author: unknown
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c Author: unknown
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 Author: unknown
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b Author: unknown
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c Author: unknown
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 Author: unknown
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_268aac0b reference_sample = 49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 9c581721bf82af7dc6482a2c41af5fb3404e01c82545c7b2b29230f707014781, id = 268aac0b-c5c7-4035-8381-4e182de91e32, last_modified = 2021-09-16
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0cb1699c reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6e44c68bba8c9fb53ac85080b9ad765579f027cabfea5055a0bb3a85b8671089, id = 0cb1699c-9a08-4885-aa7f-0f1ee2543cac, last_modified = 2021-09-16
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_2e3f67a9 reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6a06815f3d2e5f1a7a67f4264953dbb2e9d14e5f3486b178da845eab5b922d4f, id = 2e3f67a9-6fd5-4457-a626-3a9015bdb401, last_modified = 2021-09-16
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: loki.i686.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b reference_sample = 49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 9c581721bf82af7dc6482a2c41af5fb3404e01c82545c7b2b29230f707014781, id = 268aac0b-c5c7-4035-8381-4e182de91e32, last_modified = 2021-09-16
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6e44c68bba8c9fb53ac85080b9ad765579f027cabfea5055a0bb3a85b8671089, id = 0cb1699c-9a08-4885-aa7f-0f1ee2543cac, last_modified = 2021-09-16
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6a06815f3d2e5f1a7a67f4264953dbb2e9d14e5f3486b178da845eab5b922d4f, id = 2e3f67a9-6fd5-4457-a626-3a9015bdb401, last_modified = 2021-09-16
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5433.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_268aac0b reference_sample = 49c94d184d7e387c3efe34ae6f021e011c3046ae631c9733ab0a230d5fe28ead, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 9c581721bf82af7dc6482a2c41af5fb3404e01c82545c7b2b29230f707014781, id = 268aac0b-c5c7-4035-8381-4e182de91e32, last_modified = 2021-09-16
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0cb1699c reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6e44c68bba8c9fb53ac85080b9ad765579f027cabfea5055a0bb3a85b8671089, id = 0cb1699c-9a08-4885-aa7f-0f1ee2543cac, last_modified = 2021-09-16
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_2e3f67a9 reference_sample = fc8741f67f39e7409ab2c6c62d4f9acdd168d3e53cf6976dd87501833771cacb, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6a06815f3d2e5f1a7a67f4264953dbb2e9d14e5f3486b178da845eab5b922d4f, id = 2e3f67a9-6fd5-4457-a626-3a9015bdb401, last_modified = 2021-09-16
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 5434.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: classification engineClassification label: mal60.linELF@0/0@1/0
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594514 Sample: loki.i686.elf Startdate: 19/01/2025 Architecture: LINUX Score: 60 13 83.222.164.106, 13566, 47402 WAVENETLB Bulgaria 2->13 15 83.222.165.179, 13566, 48756 WAVENETLB Bulgaria 2->15 17 98 other IPs or domains 2->17 19 Malicious sample detected (through community Yara rule) 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 Machine Learning detection for sample 2->23 7 loki.i686.elf 2->7         started        signatures3 process4 process5 9 loki.i686.elf 7->9         started        11 loki.i686.elf 7->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
loki.i686.elf29%ReversingLabsLinux.Backdoor.Mirai
loki.i686.elf19%VirustotalBrowse
loki.i686.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.170.80
    unknownBulgaria
    49040KIG-UNISAT-TVBGfalse
    83.222.95.226
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.88.90
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.11.234
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.129.117
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.108.95
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.158.74
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.99.32
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.154.9
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.232.229
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.217.152
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.75.184
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.144.146
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.175.146
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.79.29
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.89.100
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.132.74
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.157.193
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.10.167
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.39.63
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.164.106
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.64.180
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.38.219
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.222.243
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.84.71
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.202.108
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.132.198
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.112.224
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.205.123
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.240.95
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.218.40
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.95.165
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.197.137
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.115.89
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.13.26
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.6.113
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.47.95
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.153.101
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.32.243
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.199.133
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.179.102
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.148.154
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.187.216
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.109.15
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.177.81
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.245.114
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.49.188
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.236.18
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.73.246
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.171.13
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.92.210
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.88.190
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.128.66
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.190.254
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.122.208
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.49.91
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.181.210
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.215.37
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.178.148
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.5.73
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.176.133
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.185.111
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.15.185
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.225.100
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.121.138
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.210.113
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.127.85
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.235.30
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.121.250
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.143.161
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.251.121
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.20.136
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.165.216
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.135.136
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.1.222
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.120.149
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.83.41
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.88.101
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.165.179
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.67.57
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.66.85
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.75.150
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.244.226
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.209.3
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.173.106
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.117.68
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.124.116
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.4.83
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.70.142
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.208.121
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.233.104
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.249.250
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.254.8
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.26.218
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.99.79
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.11.102
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.218.211
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.203.223
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.28.205
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.129.117Kloki.arm7.elfGet hashmaliciousMiraiBrowse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      secure-network-rebirthltd.ruloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.191.90
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.191.90
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.84.40
      loki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.82.192
      Kloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.80.179
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.88.210
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.129
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.129
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.200
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.66.189
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.74.245
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.71.84
      KIG-UNISAT-TVBGloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.172.206
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.167.50
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.160.160
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.160.160
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.170.174
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.172.220
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.170.87
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.160.209
      Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.160.195
      loki.i486.elfGet hashmaliciousUnknownBrowse
      • 83.222.160.19
      ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.84.40
      loki.ppc.elfGet hashmaliciousUnknownBrowse
      • 83.222.82.192
      Kloki.arm4.elfGet hashmaliciousUnknownBrowse
      • 83.222.80.179
      Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      • 83.222.88.210
      Kloki.i686.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.129
      loki.x86.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.129
      Kloki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.93.200
      loki.mips.elfGet hashmaliciousUnknownBrowse
      • 83.222.66.189
      Kloki.sh4.elfGet hashmaliciousUnknownBrowse
      • 83.222.74.245
      loki.arm7.elfGet hashmaliciousMiraiBrowse
      • 83.222.71.84
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
      Entropy (8bit):6.141328249071198
      TrID:
      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
      File name:loki.i686.elf
      File size:46'256 bytes
      MD5:6f919b612a801edc62474fbd619420fc
      SHA1:79f495e4a44279c382531d2b126b4509b7566996
      SHA256:3cfdcca4113cab1b5901ab14e777ba7655d5f6f1db6f99c04ec954d9c931227e
      SHA512:2a1ddc571327d81c59dd689860db9f7ac1b40757309e337215189ad85c25f60382b45a8a0458ceb77651e1702324eba654f3b8e89be93cd28f5cca35a535d202
      SSDEEP:768:rHmKUTsCkP3Ij5esowPFW4XFw3rAG3WF3/qf2wbqLBKkj4nC:CKCAPIj5etwPIIKk3/62qiBKc4n
      TLSH:5E23F784F54F94F5E5074A309067F63FCB72D62A4261CA6EDF89AF36DB27601C11228D
      File Content Preview:.ELF....................h...4... .......4. ...(.....................@...@...............D...DA..DA......|...........Q.td............................U..S............h........[]...$.............U......=.B...t..1.....A......A......u........t...$@1..........B

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:Intel 80386
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - System V
      ABI Version:0
      Entry Point Address:0x8048168
      Flags:0x0
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:45856
      Section Header Size:40
      Number of Section Headers:10
      Header String Table Index:9
      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
      NULL0x00x00x00x00x0000
      .initPROGBITS0x80480940x940x1c0x00x6AX001
      .textPROGBITS0x80480b00xb00xa8e10x00x6AX0016
      .finiPROGBITS0x80529910xa9910x170x00x6AX001
      .rodataPROGBITS0x80529c00xa9c00x7800x00x2A0032
      .ctorsPROGBITS0x80541440xb1440x80x00x3WA004
      .dtorsPROGBITS0x805414c0xb14c0x80x00x3WA004
      .dataPROGBITS0x80541800xb1800x1600x00x3WA0032
      .bssNOBITS0x80542e00xb2e00x14e00x00x3WA0032
      .shstrtabSTRTAB0x00xb2e00x3e0x00x0001
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x80480000x80480000xb1400xb1406.16280x5R E0x1000.init .text .fini .rodata
      LOAD0xb1440x80541440x80541440x19c0x167c4.23270x6RW 0x1000.ctors .dtors .data .bss
      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

      Download Network PCAP: filteredfull

      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
      2025-01-19T04:02:58.442061+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1342870TCP
      • Total Packets: 219
      • 13566 undefined
      • 53 (DNS)
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 04:02:58.416126013 CET4922213566192.168.2.1383.222.20.136
      Jan 19, 2025 04:02:58.416265011 CET5896213566192.168.2.1383.222.210.113
      Jan 19, 2025 04:02:58.416281939 CET4878013566192.168.2.1383.222.121.250
      Jan 19, 2025 04:02:58.416281939 CET5641413566192.168.2.1383.222.236.18
      Jan 19, 2025 04:02:58.416296959 CET4893413566192.168.2.1383.222.124.116
      Jan 19, 2025 04:02:58.416321039 CET5829213566192.168.2.1383.222.60.88
      Jan 19, 2025 04:02:58.416344881 CET5321013566192.168.2.1383.222.75.150
      Jan 19, 2025 04:02:58.416351080 CET4442413566192.168.2.1383.222.88.101
      Jan 19, 2025 04:02:58.416351080 CET4882413566192.168.2.1383.222.109.15
      Jan 19, 2025 04:02:58.416357040 CET4624813566192.168.2.1383.222.209.3
      Jan 19, 2025 04:02:58.416424990 CET6083213566192.168.2.1383.222.132.198
      Jan 19, 2025 04:02:58.416438103 CET4875613566192.168.2.1383.222.165.179
      Jan 19, 2025 04:02:58.416438103 CET4339813566192.168.2.1383.222.208.121
      Jan 19, 2025 04:02:58.416450024 CET5871813566192.168.2.1383.222.122.208
      Jan 19, 2025 04:02:58.416438103 CET5947413566192.168.2.1383.222.165.216
      Jan 19, 2025 04:02:58.416438103 CET6088613566192.168.2.1383.222.249.250
      Jan 19, 2025 04:02:58.416438103 CET4613213566192.168.2.1383.222.245.114
      Jan 19, 2025 04:02:58.416439056 CET4437613566192.168.2.1383.222.244.226
      Jan 19, 2025 04:02:58.416461945 CET5685413566192.168.2.1383.222.158.74
      Jan 19, 2025 04:02:58.416488886 CET4776613566192.168.2.1383.222.79.29
      Jan 19, 2025 04:02:58.416502953 CET4292413566192.168.2.1383.222.176.133
      Jan 19, 2025 04:02:58.416501045 CET4152413566192.168.2.1383.222.13.26
      Jan 19, 2025 04:02:58.416501045 CET4380413566192.168.2.1383.222.83.41
      Jan 19, 2025 04:02:58.416501999 CET4216413566192.168.2.1383.222.73.246
      Jan 19, 2025 04:02:58.416523933 CET4747813566192.168.2.1383.222.157.193
      Jan 19, 2025 04:02:58.416523933 CET5907213566192.168.2.1383.222.128.66
      Jan 19, 2025 04:02:58.416542053 CET4793613566192.168.2.1383.222.229.109
      Jan 19, 2025 04:02:58.416548014 CET5644213566192.168.2.1383.222.175.146
      Jan 19, 2025 04:02:58.416542053 CET5373213566192.168.2.1383.222.148.154
      Jan 19, 2025 04:02:58.416563988 CET3891213566192.168.2.1383.222.95.165
      Jan 19, 2025 04:02:58.416575909 CET5257013566192.168.2.1383.222.179.102
      Jan 19, 2025 04:02:58.416575909 CET5589413566192.168.2.1383.222.153.101
      Jan 19, 2025 04:02:58.416996956 CET4081613566192.168.2.1383.222.135.136
      Jan 19, 2025 04:02:58.417005062 CET4807613566192.168.2.1383.222.26.218
      Jan 19, 2025 04:02:58.417020082 CET3697213566192.168.2.1383.222.178.148
      Jan 19, 2025 04:02:58.417023897 CET4365013566192.168.2.1383.222.170.80
      Jan 19, 2025 04:02:58.417038918 CET3538613566192.168.2.1383.222.222.243
      Jan 19, 2025 04:02:58.417051077 CET4787613566192.168.2.1383.222.70.142
      Jan 19, 2025 04:02:58.417064905 CET5001613566192.168.2.1383.222.120.149
      Jan 19, 2025 04:02:58.417069912 CET4940013566192.168.2.1383.222.171.13
      Jan 19, 2025 04:02:58.417078018 CET5067813566192.168.2.1383.222.47.95
      Jan 19, 2025 04:02:58.417103052 CET5302013566192.168.2.1383.222.32.243
      Jan 19, 2025 04:02:58.417103052 CET3512213566192.168.2.1383.222.15.185
      Jan 19, 2025 04:02:58.417110920 CET5418813566192.168.2.1383.222.88.190
      Jan 19, 2025 04:02:58.417125940 CET5300613566192.168.2.1383.222.99.79
      Jan 19, 2025 04:02:58.417126894 CET5074613566192.168.2.1383.222.4.83
      Jan 19, 2025 04:02:58.417128086 CET3854413566192.168.2.1383.222.115.204
      Jan 19, 2025 04:02:58.417128086 CET5116013566192.168.2.1383.222.75.184
      Jan 19, 2025 04:02:58.417128086 CET4459213566192.168.2.1383.222.11.234
      Jan 19, 2025 04:02:58.417159081 CET3869813566192.168.2.1383.222.197.137
      Jan 19, 2025 04:02:58.417181969 CET5978413566192.168.2.1383.222.185.111
      Jan 19, 2025 04:02:58.417292118 CET3450013566192.168.2.1383.222.215.37
      Jan 19, 2025 04:02:58.417414904 CET5920413566192.168.2.1383.222.217.152
      Jan 19, 2025 04:02:58.417428017 CET5112413566192.168.2.1383.222.99.32
      Jan 19, 2025 04:02:58.417438030 CET5502613566192.168.2.1383.222.38.219
      Jan 19, 2025 04:02:58.417457104 CET4583013566192.168.2.1383.222.181.210
      Jan 19, 2025 04:02:58.417459011 CET4686213566192.168.2.1383.222.232.229
      Jan 19, 2025 04:02:58.417481899 CET4810813566192.168.2.1383.222.49.91
      Jan 19, 2025 04:02:58.417651892 CET4523013566192.168.2.1383.222.177.81
      Jan 19, 2025 04:02:58.417678118 CET3583413566192.168.2.1383.222.127.85
      Jan 19, 2025 04:02:58.417691946 CET4740213566192.168.2.1383.222.164.106
      Jan 19, 2025 04:02:58.417692900 CET5719013566192.168.2.1383.222.95.226
      Jan 19, 2025 04:02:58.417695045 CET5005213566192.168.2.1383.222.78.192
      Jan 19, 2025 04:02:58.417695045 CET3786013566192.168.2.1383.222.10.167
      Jan 19, 2025 04:02:58.417824984 CET5953013566192.168.2.1383.222.144.146
      Jan 19, 2025 04:02:58.417859077 CET6060213566192.168.2.1383.222.254.8
      Jan 19, 2025 04:02:58.417864084 CET4375213566192.168.2.1383.222.1.222
      Jan 19, 2025 04:02:58.417870045 CET4588813566192.168.2.1383.222.5.73
      Jan 19, 2025 04:02:58.417870045 CET4121813566192.168.2.1383.222.225.100
      Jan 19, 2025 04:02:58.417922020 CET3327413566192.168.2.1383.222.205.123
      Jan 19, 2025 04:02:58.418248892 CET4072013566192.168.2.1383.222.64.180
      Jan 19, 2025 04:02:58.418266058 CET3573613566192.168.2.1383.222.218.40
      Jan 19, 2025 04:02:58.418268919 CET4901013566192.168.2.1383.222.153.11
      Jan 19, 2025 04:02:58.418293953 CET4701013566192.168.2.1383.222.132.74
      Jan 19, 2025 04:02:58.418293953 CET4957013566192.168.2.1383.222.92.210
      Jan 19, 2025 04:02:58.418303013 CET4509613566192.168.2.1383.222.11.102
      Jan 19, 2025 04:02:58.418304920 CET4242213566192.168.2.1383.222.121.138
      Jan 19, 2025 04:02:58.418317080 CET4571013566192.168.2.1383.222.108.95
      Jan 19, 2025 04:02:58.418329954 CET3912213566192.168.2.1383.222.187.216
      Jan 19, 2025 04:02:58.418335915 CET4100413566192.168.2.1383.222.67.57
      Jan 19, 2025 04:02:58.418382883 CET5875413566192.168.2.1383.222.218.211
      Jan 19, 2025 04:02:58.418396950 CET5521213566192.168.2.1383.222.28.205
      Jan 19, 2025 04:02:58.418397903 CET3405013566192.168.2.1383.222.203.223
      Jan 19, 2025 04:02:58.418430090 CET4845413566192.168.2.1383.222.6.113
      Jan 19, 2025 04:02:58.418430090 CET6085813566192.168.2.1383.222.49.188
      Jan 19, 2025 04:02:58.418438911 CET4200813566192.168.2.1383.222.190.254
      Jan 19, 2025 04:02:58.418447018 CET3710013566192.168.2.1383.222.112.224
      Jan 19, 2025 04:02:58.418472052 CET3352813566192.168.2.1383.222.154.9
      Jan 19, 2025 04:02:58.418472052 CET5377413566192.168.2.1383.222.235.30
      Jan 19, 2025 04:02:58.418493032 CET5558413566192.168.2.1383.222.84.71
      Jan 19, 2025 04:02:58.418493032 CET5850213566192.168.2.1383.222.240.95
      Jan 19, 2025 04:02:58.418510914 CET4566413566192.168.2.1383.222.173.106
      Jan 19, 2025 04:02:58.418539047 CET5997813566192.168.2.1383.222.233.104
      Jan 19, 2025 04:02:58.418557882 CET3510413566192.168.2.1383.222.66.85
      Jan 19, 2025 04:02:58.418565989 CET5854413566192.168.2.1383.222.199.133
      Jan 19, 2025 04:02:58.418595076 CET5946413566192.168.2.1383.222.143.161
      Jan 19, 2025 04:02:58.418607950 CET4785813566192.168.2.1383.222.88.90
      Jan 19, 2025 04:02:58.418607950 CET5851213566192.168.2.1383.222.129.117
      Jan 19, 2025 04:02:58.418633938 CET4216813566192.168.2.1383.222.39.63
      Jan 19, 2025 04:02:58.418647051 CET3620413566192.168.2.1383.222.251.121
      Jan 19, 2025 04:02:58.418648005 CET3911213566192.168.2.1383.222.115.89
      Jan 19, 2025 04:02:58.418648005 CET5238613566192.168.2.1383.222.202.108
      Jan 19, 2025 04:02:58.419081926 CET5963813566192.168.2.1383.222.89.100
      Jan 19, 2025 04:02:58.419101000 CET3459413566192.168.2.1383.222.117.68
      Jan 19, 2025 04:02:58.421288013 CET135664922283.222.20.136192.168.2.13
      Jan 19, 2025 04:02:58.421308994 CET135665896283.222.210.113192.168.2.13
      Jan 19, 2025 04:02:58.421324968 CET135664878083.222.121.250192.168.2.13
      Jan 19, 2025 04:02:58.421339989 CET135664893483.222.124.116192.168.2.13
      Jan 19, 2025 04:02:58.421341896 CET4922213566192.168.2.1383.222.20.136
      Jan 19, 2025 04:02:58.421349049 CET5896213566192.168.2.1383.222.210.113
      Jan 19, 2025 04:02:58.421370029 CET4893413566192.168.2.1383.222.124.116
      Jan 19, 2025 04:02:58.421371937 CET4878013566192.168.2.1383.222.121.250
      Jan 19, 2025 04:02:58.426012993 CET135665829283.222.60.88192.168.2.13
      Jan 19, 2025 04:02:58.426038980 CET135665641483.222.236.18192.168.2.13
      Jan 19, 2025 04:02:58.426054001 CET135665321083.222.75.150192.168.2.13
      Jan 19, 2025 04:02:58.426069021 CET135664442483.222.88.101192.168.2.13
      Jan 19, 2025 04:02:58.426083088 CET135664624883.222.209.3192.168.2.13
      Jan 19, 2025 04:02:58.426083088 CET5829213566192.168.2.1383.222.60.88
      Jan 19, 2025 04:02:58.426098108 CET135664882483.222.109.15192.168.2.13
      Jan 19, 2025 04:02:58.426104069 CET5641413566192.168.2.1383.222.236.18
      Jan 19, 2025 04:02:58.426104069 CET4442413566192.168.2.1383.222.88.101
      Jan 19, 2025 04:02:58.426120043 CET5321013566192.168.2.1383.222.75.150
      Jan 19, 2025 04:02:58.426122904 CET4624813566192.168.2.1383.222.209.3
      Jan 19, 2025 04:02:58.426136017 CET4882413566192.168.2.1383.222.109.15
      Jan 19, 2025 04:02:58.426258087 CET135666083283.222.132.198192.168.2.13
      Jan 19, 2025 04:02:58.426273108 CET135665871883.222.122.208192.168.2.13
      Jan 19, 2025 04:02:58.426285982 CET135665685483.222.158.74192.168.2.13
      Jan 19, 2025 04:02:58.426300049 CET135664776683.222.79.29192.168.2.13
      Jan 19, 2025 04:02:58.426301956 CET5871813566192.168.2.1383.222.122.208
      Jan 19, 2025 04:02:58.426304102 CET6083213566192.168.2.1383.222.132.198
      Jan 19, 2025 04:02:58.426316977 CET135664292483.222.176.133192.168.2.13
      Jan 19, 2025 04:02:58.426323891 CET5685413566192.168.2.1383.222.158.74
      Jan 19, 2025 04:02:58.426337957 CET4776613566192.168.2.1383.222.79.29
      Jan 19, 2025 04:02:58.426350117 CET4292413566192.168.2.1383.222.176.133
      Jan 19, 2025 04:02:58.431078911 CET135664747883.222.157.193192.168.2.13
      Jan 19, 2025 04:02:58.431107998 CET135664875683.222.165.179192.168.2.13
      Jan 19, 2025 04:02:58.431123018 CET135665907283.222.128.66192.168.2.13
      Jan 19, 2025 04:02:58.431123972 CET4747813566192.168.2.1383.222.157.193
      Jan 19, 2025 04:02:58.431140900 CET135664339883.222.208.121192.168.2.13
      Jan 19, 2025 04:02:58.431155920 CET135665947483.222.165.216192.168.2.13
      Jan 19, 2025 04:02:58.431165934 CET5907213566192.168.2.1383.222.128.66
      Jan 19, 2025 04:02:58.431180954 CET135666088683.222.249.250192.168.2.13
      Jan 19, 2025 04:02:58.431197882 CET135664613283.222.245.114192.168.2.13
      Jan 19, 2025 04:02:58.431210995 CET135664437683.222.244.226192.168.2.13
      Jan 19, 2025 04:02:58.431225061 CET135665644283.222.175.146192.168.2.13
      Jan 19, 2025 04:02:58.431241035 CET135663891283.222.95.165192.168.2.13
      Jan 19, 2025 04:02:58.431253910 CET135664152483.222.13.26192.168.2.13
      Jan 19, 2025 04:02:58.431261063 CET5644213566192.168.2.1383.222.175.146
      Jan 19, 2025 04:02:58.431267023 CET135664380483.222.83.41192.168.2.13
      Jan 19, 2025 04:02:58.431272030 CET3891213566192.168.2.1383.222.95.165
      Jan 19, 2025 04:02:58.431281090 CET135664216483.222.73.246192.168.2.13
      Jan 19, 2025 04:02:58.431288004 CET135665257083.222.179.102192.168.2.13
      Jan 19, 2025 04:02:58.431282043 CET4875613566192.168.2.1383.222.165.179
      Jan 19, 2025 04:02:58.431282997 CET4339813566192.168.2.1383.222.208.121
      Jan 19, 2025 04:02:58.431282997 CET5947413566192.168.2.1383.222.165.216
      Jan 19, 2025 04:02:58.431282997 CET6088613566192.168.2.1383.222.249.250
      Jan 19, 2025 04:02:58.431282997 CET4613213566192.168.2.1383.222.245.114
      Jan 19, 2025 04:02:58.431282997 CET4437613566192.168.2.1383.222.244.226
      Jan 19, 2025 04:02:58.431301117 CET135665589483.222.153.101192.168.2.13
      Jan 19, 2025 04:02:58.431329966 CET135664793683.222.229.109192.168.2.13
      Jan 19, 2025 04:02:58.431304932 CET4152413566192.168.2.1383.222.13.26
      Jan 19, 2025 04:02:58.431370974 CET135665373283.222.148.154192.168.2.13
      Jan 19, 2025 04:02:58.431391001 CET135664081683.222.135.136192.168.2.13
      Jan 19, 2025 04:02:58.431401014 CET4380413566192.168.2.1383.222.83.41
      Jan 19, 2025 04:02:58.431401014 CET4216413566192.168.2.1383.222.73.246
      Jan 19, 2025 04:02:58.431406021 CET135664807683.222.26.218192.168.2.13
      Jan 19, 2025 04:02:58.431396008 CET4793613566192.168.2.1383.222.229.109
      Jan 19, 2025 04:02:58.431418896 CET135663697283.222.178.148192.168.2.13
      Jan 19, 2025 04:02:58.431421995 CET5257013566192.168.2.1383.222.179.102
      Jan 19, 2025 04:02:58.431422949 CET5589413566192.168.2.1383.222.153.101
      Jan 19, 2025 04:02:58.431430101 CET4081613566192.168.2.1383.222.135.136
      Jan 19, 2025 04:02:58.431432962 CET135664365083.222.170.80192.168.2.13
      Jan 19, 2025 04:02:58.431446075 CET135663538683.222.222.243192.168.2.13
      Jan 19, 2025 04:02:58.431453943 CET3697213566192.168.2.1383.222.178.148
      Jan 19, 2025 04:02:58.431459904 CET135664787683.222.70.142192.168.2.13
      Jan 19, 2025 04:02:58.431463957 CET5373213566192.168.2.1383.222.148.154
      Jan 19, 2025 04:02:58.431464911 CET4807613566192.168.2.1383.222.26.218
      Jan 19, 2025 04:02:58.431468964 CET4365013566192.168.2.1383.222.170.80
      Jan 19, 2025 04:02:58.431474924 CET135664940083.222.171.13192.168.2.13
      Jan 19, 2025 04:02:58.431483030 CET3538613566192.168.2.1383.222.222.243
      Jan 19, 2025 04:02:58.431488991 CET135665001683.222.120.149192.168.2.13
      Jan 19, 2025 04:02:58.431495905 CET4787613566192.168.2.1383.222.70.142
      Jan 19, 2025 04:02:58.431505919 CET135665067883.222.47.95192.168.2.13
      Jan 19, 2025 04:02:58.431510925 CET4940013566192.168.2.1383.222.171.13
      Jan 19, 2025 04:02:58.431521893 CET135665418883.222.88.190192.168.2.13
      Jan 19, 2025 04:02:58.431529999 CET5001613566192.168.2.1383.222.120.149
      Jan 19, 2025 04:02:58.431535959 CET135665302083.222.32.243192.168.2.13
      Jan 19, 2025 04:02:58.431538105 CET5067813566192.168.2.1383.222.47.95
      Jan 19, 2025 04:02:58.431550026 CET135663512283.222.15.185192.168.2.13
      Jan 19, 2025 04:02:58.431559086 CET5418813566192.168.2.1383.222.88.190
      Jan 19, 2025 04:02:58.431564093 CET135665300683.222.99.79192.168.2.13
      Jan 19, 2025 04:02:58.431571960 CET135663869883.222.197.137192.168.2.13
      Jan 19, 2025 04:02:58.431582928 CET135665978483.222.185.111192.168.2.13
      Jan 19, 2025 04:02:58.431596041 CET135665074683.222.4.83192.168.2.13
      Jan 19, 2025 04:02:58.431605101 CET5300613566192.168.2.1383.222.99.79
      Jan 19, 2025 04:02:58.431606054 CET3869813566192.168.2.1383.222.197.137
      Jan 19, 2025 04:02:58.431608915 CET135663854483.222.115.204192.168.2.13
      Jan 19, 2025 04:02:58.431615114 CET5302013566192.168.2.1383.222.32.243
      Jan 19, 2025 04:02:58.431615114 CET3512213566192.168.2.1383.222.15.185
      Jan 19, 2025 04:02:58.431615114 CET5978413566192.168.2.1383.222.185.111
      Jan 19, 2025 04:02:58.431623936 CET135665116083.222.75.184192.168.2.13
      Jan 19, 2025 04:02:58.431638956 CET135664459283.222.11.234192.168.2.13
      Jan 19, 2025 04:02:58.431653976 CET135663450083.222.215.37192.168.2.13
      Jan 19, 2025 04:02:58.431667089 CET135665920483.222.217.152192.168.2.13
      Jan 19, 2025 04:02:58.431680918 CET135665112483.222.99.32192.168.2.13
      Jan 19, 2025 04:02:58.431684971 CET3450013566192.168.2.1383.222.215.37
      Jan 19, 2025 04:02:58.431694984 CET135665502683.222.38.219192.168.2.13
      Jan 19, 2025 04:02:58.431709051 CET135664583083.222.181.210192.168.2.13
      Jan 19, 2025 04:02:58.431714058 CET5920413566192.168.2.1383.222.217.152
      Jan 19, 2025 04:02:58.431715012 CET5112413566192.168.2.1383.222.99.32
      Jan 19, 2025 04:02:58.431723118 CET135664686283.222.232.229192.168.2.13
      Jan 19, 2025 04:02:58.431726933 CET5502613566192.168.2.1383.222.38.219
      Jan 19, 2025 04:02:58.431735992 CET4583013566192.168.2.1383.222.181.210
      Jan 19, 2025 04:02:58.431736946 CET135664810883.222.49.91192.168.2.13
      Jan 19, 2025 04:02:58.431750059 CET135664523083.222.177.81192.168.2.13
      Jan 19, 2025 04:02:58.431762934 CET4686213566192.168.2.1383.222.232.229
      Jan 19, 2025 04:02:58.431763887 CET135663583483.222.127.85192.168.2.13
      Jan 19, 2025 04:02:58.431762934 CET5074613566192.168.2.1383.222.4.83
      Jan 19, 2025 04:02:58.431770086 CET4810813566192.168.2.1383.222.49.91
      Jan 19, 2025 04:02:58.431762934 CET3854413566192.168.2.1383.222.115.204
      Jan 19, 2025 04:02:58.431762934 CET5116013566192.168.2.1383.222.75.184
      Jan 19, 2025 04:02:58.431762934 CET4459213566192.168.2.1383.222.11.234
      Jan 19, 2025 04:02:58.431778908 CET135664740283.222.164.106192.168.2.13
      Jan 19, 2025 04:02:58.431792974 CET135665719083.222.95.226192.168.2.13
      Jan 19, 2025 04:02:58.431793928 CET3583413566192.168.2.1383.222.127.85
      Jan 19, 2025 04:02:58.431797028 CET4523013566192.168.2.1383.222.177.81
      Jan 19, 2025 04:02:58.431806087 CET135665005283.222.78.192192.168.2.13
      Jan 19, 2025 04:02:58.431814909 CET4740213566192.168.2.1383.222.164.106
      Jan 19, 2025 04:02:58.431818962 CET135663786083.222.10.167192.168.2.13
      Jan 19, 2025 04:02:58.431833029 CET135665953083.222.144.146192.168.2.13
      Jan 19, 2025 04:02:58.431842089 CET5719013566192.168.2.1383.222.95.226
      Jan 19, 2025 04:02:58.431845903 CET5005213566192.168.2.1383.222.78.192
      Jan 19, 2025 04:02:58.431847095 CET135666060283.222.254.8192.168.2.13
      Jan 19, 2025 04:02:58.431859970 CET135664375283.222.1.222192.168.2.13
      Jan 19, 2025 04:02:58.431869030 CET3786013566192.168.2.1383.222.10.167
      Jan 19, 2025 04:02:58.431869030 CET5953013566192.168.2.1383.222.144.146
      Jan 19, 2025 04:02:58.431881905 CET6060213566192.168.2.1383.222.254.8
      Jan 19, 2025 04:02:58.431884050 CET135664588883.222.5.73192.168.2.13
      Jan 19, 2025 04:02:58.431899071 CET135664121883.222.225.100192.168.2.13
      Jan 19, 2025 04:02:58.431900978 CET4375213566192.168.2.1383.222.1.222
      Jan 19, 2025 04:02:58.431915998 CET135663327483.222.205.123192.168.2.13
      Jan 19, 2025 04:02:58.431926966 CET4588813566192.168.2.1383.222.5.73
      Jan 19, 2025 04:02:58.431932926 CET135664072083.222.64.180192.168.2.13
      Jan 19, 2025 04:02:58.431947947 CET135664901083.222.153.11192.168.2.13
      Jan 19, 2025 04:02:58.431950092 CET4121813566192.168.2.1383.222.225.100
      Jan 19, 2025 04:02:58.431961060 CET135663573683.222.218.40192.168.2.13
      Jan 19, 2025 04:02:58.431966066 CET4072013566192.168.2.1383.222.64.180
      Jan 19, 2025 04:02:58.431967020 CET3327413566192.168.2.1383.222.205.123
      Jan 19, 2025 04:02:58.431976080 CET4901013566192.168.2.1383.222.153.11
      Jan 19, 2025 04:02:58.431976080 CET135664509683.222.11.102192.168.2.13
      Jan 19, 2025 04:02:58.431992054 CET135664242283.222.121.138192.168.2.13
      Jan 19, 2025 04:02:58.432003975 CET3573613566192.168.2.1383.222.218.40
      Jan 19, 2025 04:02:58.432004929 CET135664701083.222.132.74192.168.2.13
      Jan 19, 2025 04:02:58.432018042 CET135664957083.222.92.210192.168.2.13
      Jan 19, 2025 04:02:58.432024002 CET4242213566192.168.2.1383.222.121.138
      Jan 19, 2025 04:02:58.432024002 CET4509613566192.168.2.1383.222.11.102
      Jan 19, 2025 04:02:58.432032108 CET135664571083.222.108.95192.168.2.13
      Jan 19, 2025 04:02:58.432043076 CET4701013566192.168.2.1383.222.132.74
      Jan 19, 2025 04:02:58.432046890 CET135664100483.222.67.57192.168.2.13
      Jan 19, 2025 04:02:58.432061911 CET135663912283.222.187.216192.168.2.13
      Jan 19, 2025 04:02:58.432063103 CET4571013566192.168.2.1383.222.108.95
      Jan 19, 2025 04:02:58.432068110 CET4957013566192.168.2.1383.222.92.210
      Jan 19, 2025 04:02:58.432075977 CET135665875483.222.218.211192.168.2.13
      Jan 19, 2025 04:02:58.432079077 CET4100413566192.168.2.1383.222.67.57
      Jan 19, 2025 04:02:58.432106018 CET3912213566192.168.2.1383.222.187.216
      Jan 19, 2025 04:02:58.432116032 CET5875413566192.168.2.1383.222.218.211
      Jan 19, 2025 04:02:58.436366081 CET135665521283.222.28.205192.168.2.13
      Jan 19, 2025 04:02:58.436392069 CET135663405083.222.203.223192.168.2.13
      Jan 19, 2025 04:02:58.436405897 CET5521213566192.168.2.1383.222.28.205
      Jan 19, 2025 04:02:58.436408043 CET135666085883.222.49.188192.168.2.13
      Jan 19, 2025 04:02:58.436422110 CET135664845483.222.6.113192.168.2.13
      Jan 19, 2025 04:02:58.436435938 CET135664200883.222.190.254192.168.2.13
      Jan 19, 2025 04:02:58.436436892 CET6085813566192.168.2.1383.222.49.188
      Jan 19, 2025 04:02:58.436450005 CET135663710083.222.112.224192.168.2.13
      Jan 19, 2025 04:02:58.436464071 CET135663352883.222.154.9192.168.2.13
      Jan 19, 2025 04:02:58.436477900 CET135665558483.222.84.71192.168.2.13
      Jan 19, 2025 04:02:58.436491013 CET135665850283.222.240.95192.168.2.13
      Jan 19, 2025 04:02:58.436505079 CET135665377483.222.235.30192.168.2.13
      Jan 19, 2025 04:02:58.436517000 CET5558413566192.168.2.1383.222.84.71
      Jan 19, 2025 04:02:58.436518908 CET135664566483.222.173.106192.168.2.13
      Jan 19, 2025 04:02:58.436528921 CET5850213566192.168.2.1383.222.240.95
      Jan 19, 2025 04:02:58.436532974 CET135665997883.222.233.104192.168.2.13
      Jan 19, 2025 04:02:58.436547995 CET135663510483.222.66.85192.168.2.13
      Jan 19, 2025 04:02:58.436543941 CET3405013566192.168.2.1383.222.203.223
      Jan 19, 2025 04:02:58.436543941 CET4845413566192.168.2.1383.222.6.113
      Jan 19, 2025 04:02:58.436559916 CET135665854483.222.199.133192.168.2.13
      Jan 19, 2025 04:02:58.436573982 CET135665946483.222.143.161192.168.2.13
      Jan 19, 2025 04:02:58.436578989 CET5997813566192.168.2.1383.222.233.104
      Jan 19, 2025 04:02:58.436578989 CET3510413566192.168.2.1383.222.66.85
      Jan 19, 2025 04:02:58.436588049 CET135664785883.222.88.90192.168.2.13
      Jan 19, 2025 04:02:58.436593056 CET4200813566192.168.2.1383.222.190.254
      Jan 19, 2025 04:02:58.436602116 CET135665851283.222.129.117192.168.2.13
      Jan 19, 2025 04:02:58.436593056 CET4566413566192.168.2.1383.222.173.106
      Jan 19, 2025 04:02:58.436614990 CET135664216883.222.39.63192.168.2.13
      Jan 19, 2025 04:02:58.436621904 CET4785813566192.168.2.1383.222.88.90
      Jan 19, 2025 04:02:58.436625004 CET5854413566192.168.2.1383.222.199.133
      Jan 19, 2025 04:02:58.436629057 CET135663620483.222.251.121192.168.2.13
      Jan 19, 2025 04:02:58.436633110 CET3710013566192.168.2.1383.222.112.224
      Jan 19, 2025 04:02:58.436640978 CET5851213566192.168.2.1383.222.129.117
      Jan 19, 2025 04:02:58.436644077 CET135663911283.222.115.89192.168.2.13
      Jan 19, 2025 04:02:58.436634064 CET3352813566192.168.2.1383.222.154.9
      Jan 19, 2025 04:02:58.436634064 CET5377413566192.168.2.1383.222.235.30
      Jan 19, 2025 04:02:58.436660051 CET135665238683.222.202.108192.168.2.13
      Jan 19, 2025 04:02:58.436671019 CET3620413566192.168.2.1383.222.251.121
      Jan 19, 2025 04:02:58.436674118 CET135665963883.222.89.100192.168.2.13
      Jan 19, 2025 04:02:58.436686039 CET135663459483.222.117.68192.168.2.13
      Jan 19, 2025 04:02:58.436711073 CET5963813566192.168.2.1383.222.89.100
      Jan 19, 2025 04:02:58.436718941 CET3459413566192.168.2.1383.222.117.68
      Jan 19, 2025 04:02:58.436721087 CET5946413566192.168.2.1383.222.143.161
      Jan 19, 2025 04:02:58.436722040 CET3911213566192.168.2.1383.222.115.89
      Jan 19, 2025 04:02:58.436721087 CET4216813566192.168.2.1383.222.39.63
      Jan 19, 2025 04:02:58.436722040 CET5238613566192.168.2.1383.222.202.108
      Jan 19, 2025 04:02:58.436773062 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:02:58.442060947 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:02:58.442219973 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:02:58.442240000 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:02:58.447388887 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:02:58.447438955 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:02:58.452497959 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:03:08.452513933 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:03:08.457442999 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:03:08.653237104 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:03:08.653400898 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:03:09.073724985 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:03:09.073900938 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:04:09.127752066 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:04:09.132961035 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:04:09.338737011 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:04:09.339001894 CET4287013566192.168.2.1383.222.191.90
      Jan 19, 2025 04:04:10.078180075 CET135664287083.222.191.90192.168.2.13
      Jan 19, 2025 04:04:10.078701019 CET4287013566192.168.2.1383.222.191.90
      TimestampSource PortDest PortSource IPDest IP
      Jan 19, 2025 04:02:58.419130087 CET4808353192.168.2.138.8.8.8
      Jan 19, 2025 04:02:58.436703920 CET53480838.8.8.8192.168.2.13
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 19, 2025 04:02:58.419130087 CET192.168.2.138.8.8.80xa7baStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 19, 2025 04:02:58.436703920 CET8.8.8.8192.168.2.130xa7baNo error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

      System Behavior

      Start time (UTC):03:02:57
      Start date (UTC):19/01/2025
      Path:/tmp/loki.i686.elf
      Arguments:/tmp/loki.i686.elf
      File size:46256 bytes
      MD5 hash:6f919b612a801edc62474fbd619420fc

      Start time (UTC):03:02:57
      Start date (UTC):19/01/2025
      Path:/tmp/loki.i686.elf
      Arguments:-
      File size:46256 bytes
      MD5 hash:6f919b612a801edc62474fbd619420fc

      Start time (UTC):03:02:57
      Start date (UTC):19/01/2025
      Path:/tmp/loki.i686.elf
      Arguments:-
      File size:46256 bytes
      MD5 hash:6f919b612a801edc62474fbd619420fc