Edit tour

Linux Analysis Report
loki.arm5.elf

Overview

General Information

Sample name:loki.arm5.elf
Analysis ID:1594515
MD5:1e5980444a7998538383f8a17165ad97
SHA1:395f7f945750f78af2b55ff6875f57a5e49deaa0
SHA256:106e968a309aac246265ec18127977d174e523ac494ebc18bec7bd6fbce4a433
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Suricata IDS alerts with low severity for network traffic
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594515
Start date and time:2025-01-19 04:02:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:loki.arm5.elf
Detection:MAL
Classification:mal48.linELF@0/0@1/0
Command:/tmp/loki.arm5.elf
PID:5496
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • loki.arm5.elf (PID: 5496, Parent: 5415, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/loki.arm5.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T04:03:00.542570+010025000342Misc Attack83.222.191.9013566192.168.2.1456538TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: loki.arm5.elfReversingLabs: Detection: 39%
Source: global trafficTCP traffic: 192.168.2.14:51588 -> 83.222.12.208:13566
Source: global trafficTCP traffic: 192.168.2.14:51058 -> 83.222.113.0:13566
Source: global trafficTCP traffic: 192.168.2.14:36864 -> 83.222.18.196:13566
Source: global trafficTCP traffic: 192.168.2.14:35628 -> 83.222.33.202:13566
Source: global trafficTCP traffic: 192.168.2.14:53378 -> 83.222.74.66:13566
Source: global trafficTCP traffic: 192.168.2.14:39554 -> 83.222.153.138:13566
Source: global trafficTCP traffic: 192.168.2.14:45460 -> 83.222.110.59:13566
Source: global trafficTCP traffic: 192.168.2.14:37178 -> 83.222.165.17:13566
Source: global trafficTCP traffic: 192.168.2.14:52604 -> 83.222.184.49:13566
Source: global trafficTCP traffic: 192.168.2.14:48552 -> 83.222.213.161:13566
Source: global trafficTCP traffic: 192.168.2.14:47830 -> 83.222.111.55:13566
Source: global trafficTCP traffic: 192.168.2.14:45880 -> 83.222.55.210:13566
Source: global trafficTCP traffic: 192.168.2.14:35948 -> 83.222.114.253:13566
Source: global trafficTCP traffic: 192.168.2.14:47098 -> 83.222.163.68:13566
Source: global trafficTCP traffic: 192.168.2.14:46746 -> 83.222.180.85:13566
Source: global trafficTCP traffic: 192.168.2.14:37534 -> 83.222.168.192:13566
Source: global trafficTCP traffic: 192.168.2.14:52308 -> 83.222.37.25:13566
Source: global trafficTCP traffic: 192.168.2.14:40398 -> 83.222.192.55:13566
Source: global trafficTCP traffic: 192.168.2.14:43538 -> 83.222.222.226:13566
Source: global trafficTCP traffic: 192.168.2.14:54414 -> 83.222.1.40:13566
Source: global trafficTCP traffic: 192.168.2.14:38814 -> 83.222.36.154:13566
Source: global trafficTCP traffic: 192.168.2.14:41428 -> 83.222.178.146:13566
Source: global trafficTCP traffic: 192.168.2.14:60060 -> 83.222.214.87:13566
Source: global trafficTCP traffic: 192.168.2.14:49472 -> 83.222.163.142:13566
Source: global trafficTCP traffic: 192.168.2.14:38380 -> 83.222.136.120:13566
Source: global trafficTCP traffic: 192.168.2.14:47122 -> 83.222.47.247:13566
Source: global trafficTCP traffic: 192.168.2.14:56942 -> 83.222.175.102:13566
Source: global trafficTCP traffic: 192.168.2.14:57348 -> 83.222.202.34:13566
Source: global trafficTCP traffic: 192.168.2.14:54690 -> 83.222.99.109:13566
Source: global trafficTCP traffic: 192.168.2.14:52016 -> 83.222.102.23:13566
Source: global trafficTCP traffic: 192.168.2.14:34708 -> 83.222.194.15:13566
Source: global trafficTCP traffic: 192.168.2.14:33800 -> 83.222.216.231:13566
Source: global trafficTCP traffic: 192.168.2.14:39636 -> 83.222.40.152:13566
Source: global trafficTCP traffic: 192.168.2.14:60192 -> 83.222.30.6:13566
Source: global trafficTCP traffic: 192.168.2.14:36280 -> 83.222.122.31:13566
Source: global trafficTCP traffic: 192.168.2.14:57492 -> 83.222.46.158:13566
Source: global trafficTCP traffic: 192.168.2.14:54980 -> 83.222.186.224:13566
Source: global trafficTCP traffic: 192.168.2.14:38102 -> 83.222.48.144:13566
Source: global trafficTCP traffic: 192.168.2.14:43204 -> 83.222.55.211:13566
Source: global trafficTCP traffic: 192.168.2.14:34330 -> 83.222.30.191:13566
Source: global trafficTCP traffic: 192.168.2.14:58958 -> 83.222.75.77:13566
Source: global trafficTCP traffic: 192.168.2.14:44672 -> 83.222.183.251:13566
Source: global trafficTCP traffic: 192.168.2.14:44524 -> 83.222.179.129:13566
Source: global trafficTCP traffic: 192.168.2.14:37166 -> 83.222.29.22:13566
Source: global trafficTCP traffic: 192.168.2.14:54354 -> 83.222.238.131:13566
Source: global trafficTCP traffic: 192.168.2.14:33244 -> 83.222.46.177:13566
Source: global trafficTCP traffic: 192.168.2.14:43838 -> 83.222.146.6:13566
Source: global trafficTCP traffic: 192.168.2.14:38976 -> 83.222.152.187:13566
Source: global trafficTCP traffic: 192.168.2.14:43882 -> 83.222.158.183:13566
Source: global trafficTCP traffic: 192.168.2.14:33610 -> 83.222.193.25:13566
Source: global trafficTCP traffic: 192.168.2.14:49612 -> 83.222.214.240:13566
Source: global trafficTCP traffic: 192.168.2.14:47066 -> 83.222.183.144:13566
Source: global trafficTCP traffic: 192.168.2.14:59182 -> 83.222.208.232:13566
Source: global trafficTCP traffic: 192.168.2.14:43470 -> 83.222.32.8:13566
Source: global trafficTCP traffic: 192.168.2.14:56816 -> 83.222.187.62:13566
Source: global trafficTCP traffic: 192.168.2.14:53110 -> 83.222.199.7:13566
Source: global trafficTCP traffic: 192.168.2.14:38874 -> 83.222.139.126:13566
Source: global trafficTCP traffic: 192.168.2.14:50624 -> 83.222.2.62:13566
Source: global trafficTCP traffic: 192.168.2.14:45444 -> 83.222.255.31:13566
Source: global trafficTCP traffic: 192.168.2.14:38876 -> 83.222.85.238:13566
Source: global trafficTCP traffic: 192.168.2.14:50098 -> 83.222.162.131:13566
Source: global trafficTCP traffic: 192.168.2.14:39418 -> 83.222.159.53:13566
Source: global trafficTCP traffic: 192.168.2.14:51014 -> 83.222.137.55:13566
Source: global trafficTCP traffic: 192.168.2.14:38806 -> 83.222.240.39:13566
Source: global trafficTCP traffic: 192.168.2.14:49324 -> 83.222.238.177:13566
Source: global trafficTCP traffic: 192.168.2.14:49580 -> 83.222.64.197:13566
Source: global trafficTCP traffic: 192.168.2.14:42320 -> 83.222.161.248:13566
Source: global trafficTCP traffic: 192.168.2.14:40512 -> 83.222.85.114:13566
Source: global trafficTCP traffic: 192.168.2.14:40050 -> 83.222.224.118:13566
Source: global trafficTCP traffic: 192.168.2.14:42088 -> 83.222.122.155:13566
Source: global trafficTCP traffic: 192.168.2.14:52278 -> 83.222.180.65:13566
Source: global trafficTCP traffic: 192.168.2.14:45824 -> 83.222.162.64:13566
Source: global trafficTCP traffic: 192.168.2.14:44392 -> 83.222.192.164:13566
Source: global trafficTCP traffic: 192.168.2.14:44944 -> 83.222.126.191:13566
Source: global trafficTCP traffic: 192.168.2.14:50910 -> 83.222.195.211:13566
Source: global trafficTCP traffic: 192.168.2.14:42670 -> 83.222.173.102:13566
Source: global trafficTCP traffic: 192.168.2.14:53668 -> 83.222.86.76:13566
Source: global trafficTCP traffic: 192.168.2.14:33086 -> 83.222.155.223:13566
Source: global trafficTCP traffic: 192.168.2.14:55598 -> 83.222.132.139:13566
Source: global trafficTCP traffic: 192.168.2.14:33050 -> 83.222.7.114:13566
Source: global trafficTCP traffic: 192.168.2.14:57520 -> 83.222.60.71:13566
Source: global trafficTCP traffic: 192.168.2.14:37336 -> 83.222.55.222:13566
Source: global trafficTCP traffic: 192.168.2.14:40370 -> 83.222.63.141:13566
Source: global trafficTCP traffic: 192.168.2.14:59434 -> 83.222.80.31:13566
Source: global trafficTCP traffic: 192.168.2.14:50822 -> 83.222.3.202:13566
Source: global trafficTCP traffic: 192.168.2.14:44574 -> 83.222.187.183:13566
Source: global trafficTCP traffic: 192.168.2.14:59160 -> 83.222.11.93:13566
Source: global trafficTCP traffic: 192.168.2.14:40294 -> 83.222.247.203:13566
Source: global trafficTCP traffic: 192.168.2.14:48474 -> 83.222.2.118:13566
Source: global trafficTCP traffic: 192.168.2.14:59546 -> 83.222.139.197:13566
Source: global trafficTCP traffic: 192.168.2.14:55694 -> 83.222.73.56:13566
Source: global trafficTCP traffic: 192.168.2.14:60402 -> 83.222.43.160:13566
Source: global trafficTCP traffic: 192.168.2.14:49672 -> 83.222.133.198:13566
Source: global trafficTCP traffic: 192.168.2.14:38996 -> 83.222.127.9:13566
Source: global trafficTCP traffic: 192.168.2.14:45472 -> 83.222.81.134:13566
Source: global trafficTCP traffic: 192.168.2.14:54476 -> 83.222.123.142:13566
Source: global trafficTCP traffic: 192.168.2.14:39862 -> 83.222.206.179:13566
Source: global trafficTCP traffic: 192.168.2.14:38446 -> 83.222.108.13:13566
Source: global trafficTCP traffic: 192.168.2.14:56538 -> 83.222.191.90:13566
Source: /tmp/loki.arm5.elf (PID: 5496)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.14:56538
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.12.208
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.12.208
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.12.208
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.12.208
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.113.0
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.113.0
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.202
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.18.196
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.202
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.202
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.74.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.138
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.33.202
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.74.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.138
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.138
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.153.138
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.49
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.161
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.165.17
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.184.49
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.111.55
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.213.161
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.55.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.111.55
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.114.253
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.55.210
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.163.68
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.114.253
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.85
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.163.68
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.192
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.180.85
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.168.192
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.37.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.37.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.37.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.192.55
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.37.25
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.192.55
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.222.226
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.222.226
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.222.226
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.222.226
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@1/0
Source: /tmp/loki.arm5.elf (PID: 5496)Queries kernel information via 'uname': Jump to behavior
Source: loki.arm5.elf, 5496.1.0000562e5ac57000.0000562e5adcc000.rw-.sdmp, loki.arm5.elf, 5498.1.0000562e5ac57000.0000562e5ad85000.rw-.sdmpBinary or memory string: Z.V!/etc/qemu-binfmt/arm
Source: loki.arm5.elf, 5496.1.0000562e5ac57000.0000562e5adcc000.rw-.sdmp, loki.arm5.elf, 5498.1.0000562e5ac57000.0000562e5ad85000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: loki.arm5.elf, 5496.1.00007ffec119f000.00007ffec11c0000.rw-.sdmp, loki.arm5.elf, 5498.1.00007ffec119f000.00007ffec11c0000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: loki.arm5.elf, 5496.1.00007ffec119f000.00007ffec11c0000.rw-.sdmp, loki.arm5.elf, 5498.1.00007ffec119f000.00007ffec11c0000.rw-.sdmpBinary or memory string: lx86_64/usr/bin/qemu-arm/tmp/loki.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/loki.arm5.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594515 Sample: loki.arm5.elf Startdate: 19/01/2025 Architecture: LINUX Score: 48 13 83.222.162.131, 13566, 50098 WAVENETLB Bulgaria 2->13 15 83.222.162.64, 13566, 45824 WAVENETLB Bulgaria 2->15 17 97 other IPs or domains 2->17 19 Multi AV Scanner detection for submitted file 2->19 7 loki.arm5.elf 2->7         started        signatures3 process4 process5 9 loki.arm5.elf 7->9         started        11 loki.arm5.elf 7->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
loki.arm5.elf39%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.238.131
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.114.253
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.208.232
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.132.139
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.110.59
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.222.226
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.162.64
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.216.231
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.240.39
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.12.208
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.186.224
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.108.13
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.3.202
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.139.126
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.122.31
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.168.192
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.60.71
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.7.114
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.30.6
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.158.183
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.85.238
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.159.53
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.224.118
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.63.141
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.85.114
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.183.251
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.86.76
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.139.197
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.247.203
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.255.31
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.155.223
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.46.177
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.48.144
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.75.77
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.11.93
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.73.56
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.29.22
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.199.7
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.33.202
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.55.222
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.214.87
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.193.25
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.192.55
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.187.183
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.206.179
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.64.197
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.127.9
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.202.34
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.2.118
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.162.131
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.55.210
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.146.6
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.55.211
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.111.55
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.80.31
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.122.155
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.238.177
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.46.158
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.184.49
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.37.25
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.180.85
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.165.17
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.137.55
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.47.247
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.194.15
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.152.187
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.36.154
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.178.146
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.81.134
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.136.120
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.32.8
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.175.102
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.179.129
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.1.40
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.30.191
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.126.191
    unknownRussian Federation
    47328TRI-ASTrueRecordsIncESfalse
    83.222.163.68
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.195.211
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.163.142
    unknownBulgaria
    31037WAVENETLBfalse
    83.222.40.152
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.187.62
    unknownBulgaria
    43561NET1-ASBGfalse
    83.222.99.109
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.74.66
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.214.240
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.180.65
    unknownBulgaria
    205872EXTRANET-ASBGfalse
    83.222.153.138
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.113.0
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.192.164
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.173.102
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.133.198
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.43.160
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.2.62
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.183.144
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.161.248
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.102.23
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.18.196
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.123.142
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.213.161
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.168.192Kloki.ppc.elfGet hashmaliciousUnknownBrowse
      83.222.216.231Kloki.arm7.elfGet hashmaliciousMiraiBrowse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        secure-network-rebirthltd.ruloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        loki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.m68k.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        loki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        Kloki.sh4.elfGet hashmaliciousUnknownBrowse
        • 83.222.191.90
        loki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.191.90
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        SYNTERRA-ASRUloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.192.64
        loki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.195.117
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.207.75
        Kloki.m68k.elfGet hashmaliciousUnknownBrowse
        • 83.222.192.22
        Kloki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.204.106
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.204.106
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.210.211
        loki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.195.162
        Kloki.sh4.elfGet hashmaliciousUnknownBrowse
        • 83.222.195.159
        loki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.196.148
        COGECO-PEER1CAloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.247.223
        loki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.239.13
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.251.105
        Kloki.m68k.elfGet hashmaliciousUnknownBrowse
        • 83.222.242.67
        Kloki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.227.237
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.244.115
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.232.116
        loki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.237.134
        Kloki.sh4.elfGet hashmaliciousUnknownBrowse
        • 83.222.224.99
        loki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.247.103
        MNOGOBYTE-ASMoscowRussiaRUloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.123.192
        loki.ppc.elfGet hashmaliciousUnknownBrowse
        • 83.222.106.184
        Kloki.arm4.elfGet hashmaliciousUnknownBrowse
        • 83.222.114.40
        Kloki.m68k.elfGet hashmaliciousUnknownBrowse
        • 83.222.100.166
        Kloki.i686.elfGet hashmaliciousUnknownBrowse
        • 83.222.114.84
        loki.x86.elfGet hashmaliciousUnknownBrowse
        • 83.222.117.151
        Kloki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.105.103
        loki.mips.elfGet hashmaliciousUnknownBrowse
        • 83.222.113.134
        Kloki.sh4.elfGet hashmaliciousUnknownBrowse
        • 83.222.118.158
        loki.arm7.elfGet hashmaliciousMiraiBrowse
        • 83.222.117.74
        No context
        No context
        No created / dropped files found
        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
        Entropy (8bit):5.9138266952272405
        TrID:
        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
        File name:loki.arm5.elf
        File size:50'208 bytes
        MD5:1e5980444a7998538383f8a17165ad97
        SHA1:395f7f945750f78af2b55ff6875f57a5e49deaa0
        SHA256:106e968a309aac246265ec18127977d174e523ac494ebc18bec7bd6fbce4a433
        SHA512:6cf1228d73d2d52327734fad8174690c8522c0f45308786cdca64f90f7a198d17e513bb4fe065efea71ce3634721e8fc62d52ea1f0e506ca92770c38a7bd1412
        SSDEEP:768:T8LFhHe8cGmF6W2oQ2p+oRLRxCG7W+UEoRFN9+KUKemww:gh+812pBlRxCGvUpQPw
        TLSH:B4331990BC919A13C6E4137BFA6E418D372663B8E2EF72139D225F11778982F0D77642
        File Content Preview:.ELF...a..........(.........4...........4. ...(.....................................................P...............Q.td..................................-...L."....-..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:ARM
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:ARM - ABI
        ABI Version:0
        Entry Point Address:0x8190
        Flags:0x2
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:3
        Section Header Offset:49808
        Section Header Size:40
        Number of Section Headers:10
        Header String Table Index:9
        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .initPROGBITS0x80940x940x180x00x6AX004
        .textPROGBITS0x80b00xb00xb6800x00x6AX0016
        .finiPROGBITS0x137300xb7300x140x00x6AX004
        .rodataPROGBITS0x137440xb7440x5640x00x2A004
        .ctorsPROGBITS0x1c0000xc0000x80x00x3WA004
        .dtorsPROGBITS0x1c0080xc0080x80x00x3WA004
        .dataPROGBITS0x1c0140xc0140x23c0x00x3WA004
        .bssNOBITS0x1c2500xc2500x11640x00x3WA004
        .shstrtabSTRTAB0x00xc2500x3e0x00x0001
        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x80000x80000xbca80xbca85.99610x5R E0x8000.init .text .fini .rodata
        LOAD0xc0000x1c0000x1c0000x2500x13b43.17830x6RW 0x8000.ctors .dtors .data .bss
        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

        Download Network PCAP: filteredfull

        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
        2025-01-19T04:03:00.542570+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.1456538TCP
        • Total Packets: 221
        • 13566 undefined
        • 53 (DNS)
        TimestampSource PortDest PortSource IPDest IP
        Jan 19, 2025 04:03:00.182689905 CET5158813566192.168.2.1483.222.12.208
        Jan 19, 2025 04:03:00.187875032 CET135665158883.222.12.208192.168.2.14
        Jan 19, 2025 04:03:00.187937975 CET5158813566192.168.2.1483.222.12.208
        Jan 19, 2025 04:03:00.200212002 CET5158813566192.168.2.1483.222.12.208
        Jan 19, 2025 04:03:00.205321074 CET135665158883.222.12.208192.168.2.14
        Jan 19, 2025 04:03:00.205364943 CET5158813566192.168.2.1483.222.12.208
        Jan 19, 2025 04:03:00.206196070 CET5105813566192.168.2.1483.222.113.0
        Jan 19, 2025 04:03:00.211046934 CET135665105883.222.113.0192.168.2.14
        Jan 19, 2025 04:03:00.211150885 CET5105813566192.168.2.1483.222.113.0
        Jan 19, 2025 04:03:00.226227999 CET3686413566192.168.2.1483.222.18.196
        Jan 19, 2025 04:03:00.231374979 CET135663686483.222.18.196192.168.2.14
        Jan 19, 2025 04:03:00.231545925 CET3686413566192.168.2.1483.222.18.196
        Jan 19, 2025 04:03:00.243864059 CET3686413566192.168.2.1483.222.18.196
        Jan 19, 2025 04:03:00.248109102 CET3562813566192.168.2.1483.222.33.202
        Jan 19, 2025 04:03:00.248919964 CET135663686483.222.18.196192.168.2.14
        Jan 19, 2025 04:03:00.249105930 CET3686413566192.168.2.1483.222.18.196
        Jan 19, 2025 04:03:00.253165960 CET135663562883.222.33.202192.168.2.14
        Jan 19, 2025 04:03:00.253287077 CET3562813566192.168.2.1483.222.33.202
        Jan 19, 2025 04:03:00.253936052 CET3562813566192.168.2.1483.222.33.202
        Jan 19, 2025 04:03:00.255688906 CET5337813566192.168.2.1483.222.74.66
        Jan 19, 2025 04:03:00.258547068 CET3955413566192.168.2.1483.222.153.138
        Jan 19, 2025 04:03:00.258903027 CET135663562883.222.33.202192.168.2.14
        Jan 19, 2025 04:03:00.258959055 CET3562813566192.168.2.1483.222.33.202
        Jan 19, 2025 04:03:00.260587931 CET135665337883.222.74.66192.168.2.14
        Jan 19, 2025 04:03:00.260639906 CET5337813566192.168.2.1483.222.74.66
        Jan 19, 2025 04:03:00.263444901 CET135663955483.222.153.138192.168.2.14
        Jan 19, 2025 04:03:00.263631105 CET3955413566192.168.2.1483.222.153.138
        Jan 19, 2025 04:03:00.274353981 CET3955413566192.168.2.1483.222.153.138
        Jan 19, 2025 04:03:00.277057886 CET4546013566192.168.2.1483.222.110.59
        Jan 19, 2025 04:03:00.280410051 CET3717813566192.168.2.1483.222.165.17
        Jan 19, 2025 04:03:00.281377077 CET135663955483.222.153.138192.168.2.14
        Jan 19, 2025 04:03:00.281436920 CET3955413566192.168.2.1483.222.153.138
        Jan 19, 2025 04:03:00.282097101 CET135664546083.222.110.59192.168.2.14
        Jan 19, 2025 04:03:00.282169104 CET4546013566192.168.2.1483.222.110.59
        Jan 19, 2025 04:03:00.285392046 CET135663717883.222.165.17192.168.2.14
        Jan 19, 2025 04:03:00.285563946 CET3717813566192.168.2.1483.222.165.17
        Jan 19, 2025 04:03:00.294707060 CET3717813566192.168.2.1483.222.165.17
        Jan 19, 2025 04:03:00.296252966 CET5260413566192.168.2.1483.222.184.49
        Jan 19, 2025 04:03:00.299410105 CET4855213566192.168.2.1483.222.213.161
        Jan 19, 2025 04:03:00.299974918 CET135663717883.222.165.17192.168.2.14
        Jan 19, 2025 04:03:00.300174952 CET3717813566192.168.2.1483.222.165.17
        Jan 19, 2025 04:03:00.301139116 CET135665260483.222.184.49192.168.2.14
        Jan 19, 2025 04:03:00.301187992 CET5260413566192.168.2.1483.222.184.49
        Jan 19, 2025 04:03:00.302894115 CET4783013566192.168.2.1483.222.111.55
        Jan 19, 2025 04:03:00.304366112 CET135664855283.222.213.161192.168.2.14
        Jan 19, 2025 04:03:00.304408073 CET4855213566192.168.2.1483.222.213.161
        Jan 19, 2025 04:03:00.306694031 CET4588013566192.168.2.1483.222.55.210
        Jan 19, 2025 04:03:00.307744026 CET135664783083.222.111.55192.168.2.14
        Jan 19, 2025 04:03:00.307806015 CET4783013566192.168.2.1483.222.111.55
        Jan 19, 2025 04:03:00.310436010 CET3594813566192.168.2.1483.222.114.253
        Jan 19, 2025 04:03:00.311614037 CET135664588083.222.55.210192.168.2.14
        Jan 19, 2025 04:03:00.311662912 CET4588013566192.168.2.1483.222.55.210
        Jan 19, 2025 04:03:00.313985109 CET4709813566192.168.2.1483.222.163.68
        Jan 19, 2025 04:03:00.315650940 CET135663594883.222.114.253192.168.2.14
        Jan 19, 2025 04:03:00.315726995 CET3594813566192.168.2.1483.222.114.253
        Jan 19, 2025 04:03:00.317572117 CET4674613566192.168.2.1483.222.180.85
        Jan 19, 2025 04:03:00.318794966 CET135664709883.222.163.68192.168.2.14
        Jan 19, 2025 04:03:00.318835020 CET4709813566192.168.2.1483.222.163.68
        Jan 19, 2025 04:03:00.322324038 CET3753413566192.168.2.1483.222.168.192
        Jan 19, 2025 04:03:00.322494984 CET135664674683.222.180.85192.168.2.14
        Jan 19, 2025 04:03:00.322549105 CET4674613566192.168.2.1483.222.180.85
        Jan 19, 2025 04:03:00.327675104 CET135663753483.222.168.192192.168.2.14
        Jan 19, 2025 04:03:00.327744961 CET3753413566192.168.2.1483.222.168.192
        Jan 19, 2025 04:03:00.329726934 CET5230813566192.168.2.1483.222.37.25
        Jan 19, 2025 04:03:00.334630013 CET135665230883.222.37.25192.168.2.14
        Jan 19, 2025 04:03:00.334681988 CET5230813566192.168.2.1483.222.37.25
        Jan 19, 2025 04:03:00.335226059 CET5230813566192.168.2.1483.222.37.25
        Jan 19, 2025 04:03:00.336088896 CET4039813566192.168.2.1483.222.192.55
        Jan 19, 2025 04:03:00.340389967 CET135665230883.222.37.25192.168.2.14
        Jan 19, 2025 04:03:00.340476990 CET5230813566192.168.2.1483.222.37.25
        Jan 19, 2025 04:03:00.340970039 CET135664039883.222.192.55192.168.2.14
        Jan 19, 2025 04:03:00.341176033 CET4039813566192.168.2.1483.222.192.55
        Jan 19, 2025 04:03:00.354085922 CET4353813566192.168.2.1483.222.222.226
        Jan 19, 2025 04:03:00.359054089 CET135664353883.222.222.226192.168.2.14
        Jan 19, 2025 04:03:00.360965014 CET4353813566192.168.2.1483.222.222.226
        Jan 19, 2025 04:03:00.386636019 CET4353813566192.168.2.1483.222.222.226
        Jan 19, 2025 04:03:00.391819954 CET135664353883.222.222.226192.168.2.14
        Jan 19, 2025 04:03:00.392209053 CET4353813566192.168.2.1483.222.222.226
        Jan 19, 2025 04:03:00.400262117 CET5441413566192.168.2.1483.222.1.40
        Jan 19, 2025 04:03:00.405215979 CET3881413566192.168.2.1483.222.36.154
        Jan 19, 2025 04:03:00.405416012 CET135665441483.222.1.40192.168.2.14
        Jan 19, 2025 04:03:00.405466080 CET5441413566192.168.2.1483.222.1.40
        Jan 19, 2025 04:03:00.407102108 CET4142813566192.168.2.1483.222.178.146
        Jan 19, 2025 04:03:00.408881903 CET6006013566192.168.2.1483.222.214.87
        Jan 19, 2025 04:03:00.410265923 CET135663881483.222.36.154192.168.2.14
        Jan 19, 2025 04:03:00.410460949 CET3881413566192.168.2.1483.222.36.154
        Jan 19, 2025 04:03:00.411914110 CET135664142883.222.178.146192.168.2.14
        Jan 19, 2025 04:03:00.412014961 CET4142813566192.168.2.1483.222.178.146
        Jan 19, 2025 04:03:00.413774014 CET135666006083.222.214.87192.168.2.14
        Jan 19, 2025 04:03:00.413984060 CET6006013566192.168.2.1483.222.214.87
        Jan 19, 2025 04:03:00.425909042 CET6006013566192.168.2.1483.222.214.87
        Jan 19, 2025 04:03:00.427054882 CET4947213566192.168.2.1483.222.163.142
        Jan 19, 2025 04:03:00.431169033 CET135666006083.222.214.87192.168.2.14
        Jan 19, 2025 04:03:00.431287050 CET6006013566192.168.2.1483.222.214.87
        Jan 19, 2025 04:03:00.431329012 CET3838013566192.168.2.1483.222.136.120
        Jan 19, 2025 04:03:00.431957006 CET135664947283.222.163.142192.168.2.14
        Jan 19, 2025 04:03:00.432087898 CET4947213566192.168.2.1483.222.163.142
        Jan 19, 2025 04:03:00.436440945 CET135663838083.222.136.120192.168.2.14
        Jan 19, 2025 04:03:00.436494112 CET3838013566192.168.2.1483.222.136.120
        Jan 19, 2025 04:03:00.440377951 CET3838013566192.168.2.1483.222.136.120
        Jan 19, 2025 04:03:00.445589066 CET135663838083.222.136.120192.168.2.14
        Jan 19, 2025 04:03:00.445648909 CET3838013566192.168.2.1483.222.136.120
        Jan 19, 2025 04:03:00.446686029 CET4712213566192.168.2.1483.222.47.247
        Jan 19, 2025 04:03:00.448148012 CET5694213566192.168.2.1483.222.175.102
        Jan 19, 2025 04:03:00.450071096 CET5734813566192.168.2.1483.222.202.34
        Jan 19, 2025 04:03:00.451406002 CET5469013566192.168.2.1483.222.99.109
        Jan 19, 2025 04:03:00.451500893 CET135664712283.222.47.247192.168.2.14
        Jan 19, 2025 04:03:00.451545000 CET4712213566192.168.2.1483.222.47.247
        Jan 19, 2025 04:03:00.452872038 CET5201613566192.168.2.1483.222.102.23
        Jan 19, 2025 04:03:00.453013897 CET135665694283.222.175.102192.168.2.14
        Jan 19, 2025 04:03:00.453057051 CET5694213566192.168.2.1483.222.175.102
        Jan 19, 2025 04:03:00.454343081 CET3470813566192.168.2.1483.222.194.15
        Jan 19, 2025 04:03:00.454911947 CET135665734883.222.202.34192.168.2.14
        Jan 19, 2025 04:03:00.455077887 CET5734813566192.168.2.1483.222.202.34
        Jan 19, 2025 04:03:00.455765963 CET3380013566192.168.2.1483.222.216.231
        Jan 19, 2025 04:03:00.456243992 CET135665469083.222.99.109192.168.2.14
        Jan 19, 2025 04:03:00.456295013 CET5469013566192.168.2.1483.222.99.109
        Jan 19, 2025 04:03:00.457730055 CET3963613566192.168.2.1483.222.40.152
        Jan 19, 2025 04:03:00.457745075 CET135665201683.222.102.23192.168.2.14
        Jan 19, 2025 04:03:00.457793951 CET5201613566192.168.2.1483.222.102.23
        Jan 19, 2025 04:03:00.459021091 CET6019213566192.168.2.1483.222.30.6
        Jan 19, 2025 04:03:00.459148884 CET135663470883.222.194.15192.168.2.14
        Jan 19, 2025 04:03:00.459311008 CET3470813566192.168.2.1483.222.194.15
        Jan 19, 2025 04:03:00.460551023 CET3628013566192.168.2.1483.222.122.31
        Jan 19, 2025 04:03:00.460566998 CET135663380083.222.216.231192.168.2.14
        Jan 19, 2025 04:03:00.460612059 CET3380013566192.168.2.1483.222.216.231
        Jan 19, 2025 04:03:00.462500095 CET5749213566192.168.2.1483.222.46.158
        Jan 19, 2025 04:03:00.462675095 CET135663963683.222.40.152192.168.2.14
        Jan 19, 2025 04:03:00.462829113 CET3963613566192.168.2.1483.222.40.152
        Jan 19, 2025 04:03:00.463859081 CET135666019283.222.30.6192.168.2.14
        Jan 19, 2025 04:03:00.463902950 CET6019213566192.168.2.1483.222.30.6
        Jan 19, 2025 04:03:00.464462042 CET5498013566192.168.2.1483.222.186.224
        Jan 19, 2025 04:03:00.465394020 CET135663628083.222.122.31192.168.2.14
        Jan 19, 2025 04:03:00.465457916 CET3628013566192.168.2.1483.222.122.31
        Jan 19, 2025 04:03:00.465929985 CET3810213566192.168.2.1483.222.48.144
        Jan 19, 2025 04:03:00.467395067 CET135665749283.222.46.158192.168.2.14
        Jan 19, 2025 04:03:00.467439890 CET5749213566192.168.2.1483.222.46.158
        Jan 19, 2025 04:03:00.467528105 CET4320413566192.168.2.1483.222.55.211
        Jan 19, 2025 04:03:00.469243050 CET3433013566192.168.2.1483.222.30.191
        Jan 19, 2025 04:03:00.469412088 CET135665498083.222.186.224192.168.2.14
        Jan 19, 2025 04:03:00.469573975 CET5498013566192.168.2.1483.222.186.224
        Jan 19, 2025 04:03:00.470662117 CET5895813566192.168.2.1483.222.75.77
        Jan 19, 2025 04:03:00.470829964 CET135663810283.222.48.144192.168.2.14
        Jan 19, 2025 04:03:00.470947981 CET3810213566192.168.2.1483.222.48.144
        Jan 19, 2025 04:03:00.472141027 CET4467213566192.168.2.1483.222.183.251
        Jan 19, 2025 04:03:00.472353935 CET135664320483.222.55.211192.168.2.14
        Jan 19, 2025 04:03:00.472395897 CET4320413566192.168.2.1483.222.55.211
        Jan 19, 2025 04:03:00.473839045 CET4452413566192.168.2.1483.222.179.129
        Jan 19, 2025 04:03:00.474112034 CET135663433083.222.30.191192.168.2.14
        Jan 19, 2025 04:03:00.474153042 CET3433013566192.168.2.1483.222.30.191
        Jan 19, 2025 04:03:00.475522041 CET135665895883.222.75.77192.168.2.14
        Jan 19, 2025 04:03:00.475558043 CET3716613566192.168.2.1483.222.29.22
        Jan 19, 2025 04:03:00.475569010 CET5895813566192.168.2.1483.222.75.77
        Jan 19, 2025 04:03:00.476963043 CET135664467283.222.183.251192.168.2.14
        Jan 19, 2025 04:03:00.477009058 CET4467213566192.168.2.1483.222.183.251
        Jan 19, 2025 04:03:00.477190971 CET5435413566192.168.2.1483.222.238.131
        Jan 19, 2025 04:03:00.478665113 CET135664452483.222.179.129192.168.2.14
        Jan 19, 2025 04:03:00.478698969 CET4452413566192.168.2.1483.222.179.129
        Jan 19, 2025 04:03:00.478919029 CET3324413566192.168.2.1483.222.46.177
        Jan 19, 2025 04:03:00.480427027 CET135663716683.222.29.22192.168.2.14
        Jan 19, 2025 04:03:00.480473042 CET3716613566192.168.2.1483.222.29.22
        Jan 19, 2025 04:03:00.480968952 CET4383813566192.168.2.1483.222.146.6
        Jan 19, 2025 04:03:00.482032061 CET135665435483.222.238.131192.168.2.14
        Jan 19, 2025 04:03:00.482069016 CET5435413566192.168.2.1483.222.238.131
        Jan 19, 2025 04:03:00.483707905 CET135663324483.222.46.177192.168.2.14
        Jan 19, 2025 04:03:00.483760118 CET3324413566192.168.2.1483.222.46.177
        Jan 19, 2025 04:03:00.484381914 CET3897613566192.168.2.1483.222.152.187
        Jan 19, 2025 04:03:00.485789061 CET135664383883.222.146.6192.168.2.14
        Jan 19, 2025 04:03:00.485841990 CET4383813566192.168.2.1483.222.146.6
        Jan 19, 2025 04:03:00.486720085 CET4388213566192.168.2.1483.222.158.183
        Jan 19, 2025 04:03:00.488631964 CET3361013566192.168.2.1483.222.193.25
        Jan 19, 2025 04:03:00.489236116 CET135663897683.222.152.187192.168.2.14
        Jan 19, 2025 04:03:00.489283085 CET3897613566192.168.2.1483.222.152.187
        Jan 19, 2025 04:03:00.490525961 CET4961213566192.168.2.1483.222.214.240
        Jan 19, 2025 04:03:00.491547108 CET135664388283.222.158.183192.168.2.14
        Jan 19, 2025 04:03:00.491584063 CET4706613566192.168.2.1483.222.183.144
        Jan 19, 2025 04:03:00.491668940 CET4388213566192.168.2.1483.222.158.183
        Jan 19, 2025 04:03:00.492290974 CET5918213566192.168.2.1483.222.208.232
        Jan 19, 2025 04:03:00.493042946 CET4347013566192.168.2.1483.222.32.8
        Jan 19, 2025 04:03:00.493455887 CET135663361083.222.193.25192.168.2.14
        Jan 19, 2025 04:03:00.493499994 CET3361013566192.168.2.1483.222.193.25
        Jan 19, 2025 04:03:00.493745089 CET5681613566192.168.2.1483.222.187.62
        Jan 19, 2025 04:03:00.494551897 CET5311013566192.168.2.1483.222.199.7
        Jan 19, 2025 04:03:00.495245934 CET3887413566192.168.2.1483.222.139.126
        Jan 19, 2025 04:03:00.495472908 CET135664961283.222.214.240192.168.2.14
        Jan 19, 2025 04:03:00.495536089 CET4961213566192.168.2.1483.222.214.240
        Jan 19, 2025 04:03:00.496022940 CET5062413566192.168.2.1483.222.2.62
        Jan 19, 2025 04:03:00.496459961 CET135664706683.222.183.144192.168.2.14
        Jan 19, 2025 04:03:00.496511936 CET4706613566192.168.2.1483.222.183.144
        Jan 19, 2025 04:03:00.496783018 CET4544413566192.168.2.1483.222.255.31
        Jan 19, 2025 04:03:00.497133017 CET135665918283.222.208.232192.168.2.14
        Jan 19, 2025 04:03:00.497179985 CET5918213566192.168.2.1483.222.208.232
        Jan 19, 2025 04:03:00.497462034 CET3887613566192.168.2.1483.222.85.238
        Jan 19, 2025 04:03:00.497832060 CET135664347083.222.32.8192.168.2.14
        Jan 19, 2025 04:03:00.498028040 CET4347013566192.168.2.1483.222.32.8
        Jan 19, 2025 04:03:00.498174906 CET5009813566192.168.2.1483.222.162.131
        Jan 19, 2025 04:03:00.498512983 CET135665681683.222.187.62192.168.2.14
        Jan 19, 2025 04:03:00.498554945 CET5681613566192.168.2.1483.222.187.62
        Jan 19, 2025 04:03:00.498884916 CET3941813566192.168.2.1483.222.159.53
        Jan 19, 2025 04:03:00.499350071 CET135665311083.222.199.7192.168.2.14
        Jan 19, 2025 04:03:00.499424934 CET5311013566192.168.2.1483.222.199.7
        Jan 19, 2025 04:03:00.499619007 CET5101413566192.168.2.1483.222.137.55
        Jan 19, 2025 04:03:00.500032902 CET135663887483.222.139.126192.168.2.14
        Jan 19, 2025 04:03:00.500078917 CET3887413566192.168.2.1483.222.139.126
        Jan 19, 2025 04:03:00.500327110 CET3880613566192.168.2.1483.222.240.39
        Jan 19, 2025 04:03:00.500822067 CET135665062483.222.2.62192.168.2.14
        Jan 19, 2025 04:03:00.500891924 CET5062413566192.168.2.1483.222.2.62
        Jan 19, 2025 04:03:00.501087904 CET4932413566192.168.2.1483.222.238.177
        Jan 19, 2025 04:03:00.501737118 CET135664544483.222.255.31192.168.2.14
        Jan 19, 2025 04:03:00.501799107 CET4958013566192.168.2.1483.222.64.197
        Jan 19, 2025 04:03:00.501914978 CET4544413566192.168.2.1483.222.255.31
        Jan 19, 2025 04:03:00.502310038 CET135663887683.222.85.238192.168.2.14
        Jan 19, 2025 04:03:00.502353907 CET3887613566192.168.2.1483.222.85.238
        Jan 19, 2025 04:03:00.502495050 CET4232013566192.168.2.1483.222.161.248
        Jan 19, 2025 04:03:00.503042936 CET135665009883.222.162.131192.168.2.14
        Jan 19, 2025 04:03:00.503099918 CET5009813566192.168.2.1483.222.162.131
        Jan 19, 2025 04:03:00.503232956 CET4051213566192.168.2.1483.222.85.114
        Jan 19, 2025 04:03:00.503745079 CET135663941883.222.159.53192.168.2.14
        Jan 19, 2025 04:03:00.503794909 CET3941813566192.168.2.1483.222.159.53
        Jan 19, 2025 04:03:00.503966093 CET4005013566192.168.2.1483.222.224.118
        Jan 19, 2025 04:03:00.504492044 CET135665101483.222.137.55192.168.2.14
        Jan 19, 2025 04:03:00.504601002 CET5101413566192.168.2.1483.222.137.55
        Jan 19, 2025 04:03:00.504700899 CET4208813566192.168.2.1483.222.122.155
        Jan 19, 2025 04:03:00.505182981 CET135663880683.222.240.39192.168.2.14
        Jan 19, 2025 04:03:00.505259991 CET3880613566192.168.2.1483.222.240.39
        Jan 19, 2025 04:03:00.505481005 CET5227813566192.168.2.1483.222.180.65
        Jan 19, 2025 04:03:00.505877018 CET135664932483.222.238.177192.168.2.14
        Jan 19, 2025 04:03:00.505935907 CET4932413566192.168.2.1483.222.238.177
        Jan 19, 2025 04:03:00.506194115 CET4582413566192.168.2.1483.222.162.64
        Jan 19, 2025 04:03:00.506582975 CET135664958083.222.64.197192.168.2.14
        Jan 19, 2025 04:03:00.506640911 CET4958013566192.168.2.1483.222.64.197
        Jan 19, 2025 04:03:00.506889105 CET4439213566192.168.2.1483.222.192.164
        Jan 19, 2025 04:03:00.507397890 CET135664232083.222.161.248192.168.2.14
        Jan 19, 2025 04:03:00.507445097 CET4232013566192.168.2.1483.222.161.248
        Jan 19, 2025 04:03:00.507605076 CET4494413566192.168.2.1483.222.126.191
        Jan 19, 2025 04:03:00.508059978 CET135664051283.222.85.114192.168.2.14
        Jan 19, 2025 04:03:00.508142948 CET4051213566192.168.2.1483.222.85.114
        Jan 19, 2025 04:03:00.508352041 CET5091013566192.168.2.1483.222.195.211
        Jan 19, 2025 04:03:00.508740902 CET135664005083.222.224.118192.168.2.14
        Jan 19, 2025 04:03:00.508785009 CET4005013566192.168.2.1483.222.224.118
        Jan 19, 2025 04:03:00.509071112 CET4267013566192.168.2.1483.222.173.102
        Jan 19, 2025 04:03:00.509510994 CET135664208883.222.122.155192.168.2.14
        Jan 19, 2025 04:03:00.509557009 CET4208813566192.168.2.1483.222.122.155
        Jan 19, 2025 04:03:00.509788036 CET5366813566192.168.2.1483.222.86.76
        Jan 19, 2025 04:03:00.510319948 CET135665227883.222.180.65192.168.2.14
        Jan 19, 2025 04:03:00.510366917 CET5227813566192.168.2.1483.222.180.65
        Jan 19, 2025 04:03:00.510494947 CET3308613566192.168.2.1483.222.155.223
        Jan 19, 2025 04:03:00.511054039 CET135664582483.222.162.64192.168.2.14
        Jan 19, 2025 04:03:00.511172056 CET4582413566192.168.2.1483.222.162.64
        Jan 19, 2025 04:03:00.511329889 CET5559813566192.168.2.1483.222.132.139
        Jan 19, 2025 04:03:00.511734009 CET135664439283.222.192.164192.168.2.14
        Jan 19, 2025 04:03:00.511789083 CET4439213566192.168.2.1483.222.192.164
        Jan 19, 2025 04:03:00.512098074 CET3305013566192.168.2.1483.222.7.114
        Jan 19, 2025 04:03:00.512459040 CET135664494483.222.126.191192.168.2.14
        Jan 19, 2025 04:03:00.512509108 CET4494413566192.168.2.1483.222.126.191
        Jan 19, 2025 04:03:00.512691021 CET5752013566192.168.2.1483.222.60.71
        Jan 19, 2025 04:03:00.513220072 CET135665091083.222.195.211192.168.2.14
        Jan 19, 2025 04:03:00.513278008 CET5091013566192.168.2.1483.222.195.211
        Jan 19, 2025 04:03:00.513397932 CET3733613566192.168.2.1483.222.55.222
        Jan 19, 2025 04:03:00.513839960 CET135664267083.222.173.102192.168.2.14
        Jan 19, 2025 04:03:00.513909101 CET4267013566192.168.2.1483.222.173.102
        Jan 19, 2025 04:03:00.514113903 CET4037013566192.168.2.1483.222.63.141
        Jan 19, 2025 04:03:00.514606953 CET135665366883.222.86.76192.168.2.14
        Jan 19, 2025 04:03:00.514663935 CET5366813566192.168.2.1483.222.86.76
        Jan 19, 2025 04:03:00.514872074 CET5943413566192.168.2.1483.222.80.31
        Jan 19, 2025 04:03:00.515350103 CET135663308683.222.155.223192.168.2.14
        Jan 19, 2025 04:03:00.515388966 CET3308613566192.168.2.1483.222.155.223
        Jan 19, 2025 04:03:00.515572071 CET5082213566192.168.2.1483.222.3.202
        Jan 19, 2025 04:03:00.516237974 CET135665559883.222.132.139192.168.2.14
        Jan 19, 2025 04:03:00.516304970 CET4457413566192.168.2.1483.222.187.183
        Jan 19, 2025 04:03:00.516397953 CET5559813566192.168.2.1483.222.132.139
        Jan 19, 2025 04:03:00.516987085 CET135663305083.222.7.114192.168.2.14
        Jan 19, 2025 04:03:00.517004967 CET5916013566192.168.2.1483.222.11.93
        Jan 19, 2025 04:03:00.517050028 CET3305013566192.168.2.1483.222.7.114
        Jan 19, 2025 04:03:00.517546892 CET135665752083.222.60.71192.168.2.14
        Jan 19, 2025 04:03:00.517604113 CET5752013566192.168.2.1483.222.60.71
        Jan 19, 2025 04:03:00.517704010 CET4029413566192.168.2.1483.222.247.203
        Jan 19, 2025 04:03:00.518220901 CET135663733683.222.55.222192.168.2.14
        Jan 19, 2025 04:03:00.518296957 CET3733613566192.168.2.1483.222.55.222
        Jan 19, 2025 04:03:00.518395901 CET4847413566192.168.2.1483.222.2.118
        Jan 19, 2025 04:03:00.518913031 CET135664037083.222.63.141192.168.2.14
        Jan 19, 2025 04:03:00.518959045 CET4037013566192.168.2.1483.222.63.141
        Jan 19, 2025 04:03:00.519103050 CET5954613566192.168.2.1483.222.139.197
        Jan 19, 2025 04:03:00.519649982 CET135665943483.222.80.31192.168.2.14
        Jan 19, 2025 04:03:00.519704103 CET5943413566192.168.2.1483.222.80.31
        Jan 19, 2025 04:03:00.519824028 CET5569413566192.168.2.1483.222.73.56
        Jan 19, 2025 04:03:00.520396948 CET135665082283.222.3.202192.168.2.14
        Jan 19, 2025 04:03:00.520445108 CET5082213566192.168.2.1483.222.3.202
        Jan 19, 2025 04:03:00.520529032 CET6040213566192.168.2.1483.222.43.160
        Jan 19, 2025 04:03:00.521147966 CET135664457483.222.187.183192.168.2.14
        Jan 19, 2025 04:03:00.521194935 CET4457413566192.168.2.1483.222.187.183
        Jan 19, 2025 04:03:00.521339893 CET4967213566192.168.2.1483.222.133.198
        Jan 19, 2025 04:03:00.521832943 CET135665916083.222.11.93192.168.2.14
        Jan 19, 2025 04:03:00.521876097 CET5916013566192.168.2.1483.222.11.93
        Jan 19, 2025 04:03:00.521969080 CET3899613566192.168.2.1483.222.127.9
        Jan 19, 2025 04:03:00.522505999 CET135664029483.222.247.203192.168.2.14
        Jan 19, 2025 04:03:00.522552013 CET4029413566192.168.2.1483.222.247.203
        Jan 19, 2025 04:03:00.522722960 CET4547213566192.168.2.1483.222.81.134
        Jan 19, 2025 04:03:00.523240089 CET135664847483.222.2.118192.168.2.14
        Jan 19, 2025 04:03:00.523315907 CET4847413566192.168.2.1483.222.2.118
        Jan 19, 2025 04:03:00.523417950 CET5447613566192.168.2.1483.222.123.142
        Jan 19, 2025 04:03:00.523911953 CET135665954683.222.139.197192.168.2.14
        Jan 19, 2025 04:03:00.523960114 CET5954613566192.168.2.1483.222.139.197
        Jan 19, 2025 04:03:00.524108887 CET3986213566192.168.2.1483.222.206.179
        Jan 19, 2025 04:03:00.524594069 CET135665569483.222.73.56192.168.2.14
        Jan 19, 2025 04:03:00.524714947 CET5569413566192.168.2.1483.222.73.56
        Jan 19, 2025 04:03:00.524871111 CET3844613566192.168.2.1483.222.108.13
        Jan 19, 2025 04:03:00.525398970 CET135666040283.222.43.160192.168.2.14
        Jan 19, 2025 04:03:00.526248932 CET6040213566192.168.2.1483.222.43.160
        Jan 19, 2025 04:03:00.526262045 CET135664967283.222.133.198192.168.2.14
        Jan 19, 2025 04:03:00.526335955 CET4967213566192.168.2.1483.222.133.198
        Jan 19, 2025 04:03:00.526809931 CET135663899683.222.127.9192.168.2.14
        Jan 19, 2025 04:03:00.526858091 CET3899613566192.168.2.1483.222.127.9
        Jan 19, 2025 04:03:00.527587891 CET135664547283.222.81.134192.168.2.14
        Jan 19, 2025 04:03:00.527652025 CET4547213566192.168.2.1483.222.81.134
        Jan 19, 2025 04:03:00.528234959 CET135665447683.222.123.142192.168.2.14
        Jan 19, 2025 04:03:00.528321981 CET5447613566192.168.2.1483.222.123.142
        Jan 19, 2025 04:03:00.528966904 CET135663986283.222.206.179192.168.2.14
        Jan 19, 2025 04:03:00.529015064 CET3986213566192.168.2.1483.222.206.179
        Jan 19, 2025 04:03:00.529717922 CET135663844683.222.108.13192.168.2.14
        Jan 19, 2025 04:03:00.529772997 CET3844613566192.168.2.1483.222.108.13
        Jan 19, 2025 04:03:00.537703991 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:03:00.542570114 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:03:00.542728901 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:03:00.544454098 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:03:00.549448013 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:03:00.549577951 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:03:00.554650068 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:03:10.554613113 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:03:10.559740067 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:03:10.766478062 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:03:10.767244101 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:03:11.113066912 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:03:11.113254070 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:04:11.171952963 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:04:11.177000046 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:04:11.365968943 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:04:11.366199970 CET5653813566192.168.2.1483.222.191.90
        Jan 19, 2025 04:04:12.114937067 CET135665653883.222.191.90192.168.2.14
        Jan 19, 2025 04:04:12.115395069 CET5653813566192.168.2.1483.222.191.90
        TimestampSource PortDest PortSource IPDest IP
        Jan 19, 2025 04:03:00.527098894 CET4991353192.168.2.148.8.8.8
        Jan 19, 2025 04:03:00.536047935 CET53499138.8.8.8192.168.2.14
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Jan 19, 2025 04:03:00.527098894 CET192.168.2.148.8.8.80x49deStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Jan 19, 2025 04:03:00.536047935 CET8.8.8.8192.168.2.140x49deNo error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

        System Behavior

        Start time (UTC):03:02:58
        Start date (UTC):19/01/2025
        Path:/tmp/loki.arm5.elf
        Arguments:/tmp/loki.arm5.elf
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

        Start time (UTC):03:02:58
        Start date (UTC):19/01/2025
        Path:/tmp/loki.arm5.elf
        Arguments:-
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

        Start time (UTC):03:02:58
        Start date (UTC):19/01/2025
        Path:/tmp/loki.arm5.elf
        Arguments:-
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1