Linux
Analysis Report
Kloki.mpsl.elf
Overview
General Information
Sample name: | Kloki.mpsl.elf |
Analysis ID: | 1594521 |
MD5: | 8bac1d6f2b0b06ee318a36bdeb0e6722 |
SHA1: | 009a4fa9f4eeca19fc05c7d05ee180458d7e47e7 |
SHA256: | e2dcccd310db024365d99ed4d2ca34c7df4fe90005ede03b1382c6ec129b24b3 |
Tags: | elfuser-abuse_ch |
Infos: |
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Classification
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1594521 |
Start date and time: | 2025-01-19 04:57:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 47s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | Kloki.mpsl.elf |
Detection: | MAL |
Classification: | mal60.spre.linELF@0/0@1/0 |
Command: | /tmp/Kloki.mpsl.elf |
PID: | 6243 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | suka |
Standard Error: |
- system is lnxubuntu20
- Kloki.mpsl.elf New Fork (PID: 6245, Parent: 6243)
- Kloki.mpsl.elf New Fork (PID: 6247, Parent: 6243)
- Kloki.mpsl.elf New Fork (PID: 6249, Parent: 6247)
- gnome-session-binary New Fork (PID: 6273, Parent: 1477)
- gnome-session-binary New Fork (PID: 6275, Parent: 1477)
- gnome-session-binary New Fork (PID: 6277, Parent: 1477)
- gnome-session-binary New Fork (PID: 6280, Parent: 1477)
- gdm3 New Fork (PID: 6281, Parent: 1320)
- gdm3 New Fork (PID: 6282, Parent: 1320)
- cleanup
⊘No yara matches
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-19T04:57:51.902553+0100 | 2500034 | 2 | Misc Attack | 83.222.191.90 | 13566 | 192.168.2.23 | 42658 | TCP |
- • AV Detection
- • Spreading
- • Networking
- • System Summary
- • Malware Analysis System Evasion
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | String: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | Suricata IDS: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | .symtab present: |
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior | ||
Source: | SIGKILL sent: | Jump to behavior |
Source: | Classification label: |
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | Windows Management Instrumentation | 1 Scripting | Path Interception | Direct Volume Access | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | 1 Service Stop |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
⊘No configs have been found
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Linux.Backdoor.Mirai | ||
100% | Avira | EXP/ELF.Mirai.W |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
secure-network-rebirthltd.ru | 83.222.191.90 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
83.222.117.102 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.22.49 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.181.246 | unknown | Bulgaria | 12615 | GCN-ASGCNAD-SofiaBulgariaBG | false | |
83.222.222.105 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.97.48 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.116.215 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.244.30 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.83.214 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.61.47 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.62.14 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.9.75 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.228.82 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
91.189.91.43 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
91.189.91.42 | unknown | United Kingdom | 41231 | CANONICAL-ASGB | false | |
83.222.6.171 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.40.66 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.73.234 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.78.216 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.70.245 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.112.150 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.58.145 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
83.222.249.231 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.72.198 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.148.83 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.229.165 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.156.196 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.248.167 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.238.6 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.159.104 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.111.209 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.23.163 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.67.15 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.228.176 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.225.136 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.66.196 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.104.31 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.95.169 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.233.214 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.19.92 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.135.19 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.217.172 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.221.110 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.242.33 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.75.157 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.211.141 | unknown | Russian Federation | 6854 | SYNTERRA-ASRU | false | |
83.222.20.91 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.118.92 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.85.94 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.191.90 | secure-network-rebirthltd.ru | Bulgaria | 43561 | NET1-ASBG | false | |
83.222.33.191 | unknown | Luxembourg | 8632 | LOL-ASluLU | false | |
109.202.202.202 | unknown | Switzerland | 13030 | INIT7CH | false | |
83.222.218.61 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.111.52 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.130.132 | unknown | Switzerland | 31736 | SENSELAN-ASsenseLANGmbHCH | false | |
83.222.226.166 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.76.64 | unknown | Russian Federation | 16285 | ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRU | false | |
83.222.251.188 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.102.164 | unknown | Russian Federation | 42632 | MNOGOBYTE-ASMoscowRussiaRU | false | |
83.222.220.53 | unknown | Russian Federation | 25159 | SONICDUO-ASRU | false | |
83.222.241.139 | unknown | United Kingdom | 13768 | COGECO-PEER1CA | false | |
83.222.8.133 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false | |
83.222.13.170 | unknown | Russian Federation | 25532 | MASTERHOST-ASMoscowRussiaRU | false |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
83.222.58.145 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
91.189.91.43 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
91.189.91.42 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Mirai | Browse | |||
Get hash | malicious | Prometei | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
secure-network-rebirthltd.ru | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MASTERHOST-ASMoscowRussiaRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
GCN-ASGCNAD-SofiaBulgariaBG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
MNOGOBYTE-ASMoscowRussiaRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 5.423247558159363 |
TrID: |
|
File name: | Kloki.mpsl.elf |
File size: | 84'796 bytes |
MD5: | 8bac1d6f2b0b06ee318a36bdeb0e6722 |
SHA1: | 009a4fa9f4eeca19fc05c7d05ee180458d7e47e7 |
SHA256: | e2dcccd310db024365d99ed4d2ca34c7df4fe90005ede03b1382c6ec129b24b3 |
SHA512: | bede97e9fa1533006ac19debfcc5603a6702895ae79c404a2ca5d0bc75a824c2c2a92618d8bfa2442a1f765b488cdd54d488c10b8e33a2fc4e5b55ac0baa75dc |
SSDEEP: | 1536:1SA1rzbZe+i9eFDcpbY16Iu6zVMtTJPjncZuZBvR0Vs/:1X9bZe+ueFmTJ7ncyUs/ |
TLSH: | E283C706BF550FBBDC6FDD370AA9170535CC550A22E83B3A7934D828B64B21B56E3CA4 |
File Content Preview: | .ELF....................`.@.4....I......4. ...(...............@...@. 6.. 6...............@...@E..@E.....x:..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<X..'!...........P!9 |
ELF header | |
---|---|
Class: | |
Data: | |
Version: | |
Machine: | |
Version Number: | |
Type: | |
OS/ABI: | |
ABI Version: | 0 |
Entry Point Address: | |
Flags: | |
ELF Header Size: | 52 |
Program Header Offset: | 52 |
Program Header Size: | 32 |
Number of Program Headers: | 3 |
Section Header Offset: | 84236 |
Section Header Size: | 40 |
Number of Section Headers: | 14 |
Header String Table Index: | 13 |
Name | Type | Address | Offset | Size | EntSize | Flags | Flags Description | Link | Info | Align |
---|---|---|---|---|---|---|---|---|---|---|
NULL | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0 | 0 | 0 | ||
.init | PROGBITS | 0x400094 | 0x94 | 0x8c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.text | PROGBITS | 0x400120 | 0x120 | 0x120a0 | 0x0 | 0x6 | AX | 0 | 0 | 16 |
.fini | PROGBITS | 0x4121c0 | 0x121c0 | 0x5c | 0x0 | 0x6 | AX | 0 | 0 | 4 |
.rodata | PROGBITS | 0x412220 | 0x12220 | 0x1400 | 0x0 | 0x2 | A | 0 | 0 | 16 |
.ctors | PROGBITS | 0x454000 | 0x14000 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.dtors | PROGBITS | 0x454008 | 0x14008 | 0x8 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data.rel.ro | PROGBITS | 0x454014 | 0x14014 | 0x74 | 0x0 | 0x3 | WA | 0 | 0 | 4 |
.data | PROGBITS | 0x454090 | 0x14090 | 0x3c0 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.got | PROGBITS | 0x454450 | 0x14450 | 0x458 | 0x4 | 0x10000003 | WAp | 0 | 0 | 16 |
.sbss | NOBITS | 0x4548a8 | 0x148a8 | 0x1c | 0x0 | 0x10000003 | WAp | 0 | 0 | 4 |
.bss | NOBITS | 0x4548d0 | 0x148a8 | 0x31a8 | 0x0 | 0x3 | WA | 0 | 0 | 16 |
.mdebug.abi32 | PROGBITS | 0x9fc | 0x148a8 | 0x0 | 0x0 | 0x0 | 0 | 0 | 1 | |
.shstrtab | STRTAB | 0x0 | 0x148a8 | 0x64 | 0x0 | 0x0 | 0 | 0 | 1 |
Type | Offset | Virtual Address | Physical Address | File Size | Memory Size | Entropy | Flags | Flags Description | Align | Prog Interpreter | Section Mappings |
---|---|---|---|---|---|---|---|---|---|---|---|
LOAD | 0x0 | 0x400000 | 0x400000 | 0x13620 | 0x13620 | 5.5604 | 0x5 | R E | 0x10000 | .init .text .fini .rodata | |
LOAD | 0x14000 | 0x454000 | 0x454000 | 0x8a8 | 0x3a78 | 3.9974 | 0x6 | RW | 0x10000 | .ctors .dtors .data.rel.ro .data .got .sbss .bss | |
GNU_STACK | 0x0 | 0x0 | 0x0 | 0x0 | 0x0 | 0.0000 | 0x7 | RWE | 0x4 |
Download Network PCAP: filtered – full
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-19T04:57:51.902553+0100 | 2500034 | ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 | 2 | 83.222.191.90 | 13566 | 192.168.2.23 | 42658 | TCP |
- Total Packets: 144
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 19, 2025 04:57:51.143492937 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 19, 2025 04:57:51.579282045 CET | 42546 | 13566 | 192.168.2.23 | 83.222.229.165 |
Jan 19, 2025 04:57:51.584366083 CET | 13566 | 42546 | 83.222.229.165 | 192.168.2.23 |
Jan 19, 2025 04:57:51.584436893 CET | 42546 | 13566 | 192.168.2.23 | 83.222.229.165 |
Jan 19, 2025 04:57:51.584481955 CET | 42546 | 13566 | 192.168.2.23 | 83.222.229.165 |
Jan 19, 2025 04:57:51.589525938 CET | 13566 | 42546 | 83.222.229.165 | 192.168.2.23 |
Jan 19, 2025 04:57:51.589684963 CET | 42546 | 13566 | 192.168.2.23 | 83.222.229.165 |
Jan 19, 2025 04:57:51.601728916 CET | 54388 | 13566 | 192.168.2.23 | 83.222.225.136 |
Jan 19, 2025 04:57:51.604068995 CET | 58286 | 13566 | 192.168.2.23 | 83.222.67.15 |
Jan 19, 2025 04:57:51.605680943 CET | 43674 | 13566 | 192.168.2.23 | 83.222.19.92 |
Jan 19, 2025 04:57:51.606704950 CET | 13566 | 54388 | 83.222.225.136 | 192.168.2.23 |
Jan 19, 2025 04:57:51.606759071 CET | 54388 | 13566 | 192.168.2.23 | 83.222.225.136 |
Jan 19, 2025 04:57:51.609049082 CET | 13566 | 58286 | 83.222.67.15 | 192.168.2.23 |
Jan 19, 2025 04:57:51.609128952 CET | 58286 | 13566 | 192.168.2.23 | 83.222.67.15 |
Jan 19, 2025 04:57:51.610675097 CET | 13566 | 43674 | 83.222.19.92 | 192.168.2.23 |
Jan 19, 2025 04:57:51.610750914 CET | 43674 | 13566 | 192.168.2.23 | 83.222.19.92 |
Jan 19, 2025 04:57:51.640834093 CET | 43674 | 13566 | 192.168.2.23 | 83.222.19.92 |
Jan 19, 2025 04:57:51.642973900 CET | 35842 | 13566 | 192.168.2.23 | 83.222.221.110 |
Jan 19, 2025 04:57:51.645802021 CET | 13566 | 43674 | 83.222.19.92 | 192.168.2.23 |
Jan 19, 2025 04:57:51.645860910 CET | 43674 | 13566 | 192.168.2.23 | 83.222.19.92 |
Jan 19, 2025 04:57:51.646502972 CET | 51408 | 13566 | 192.168.2.23 | 83.222.117.102 |
Jan 19, 2025 04:57:51.648047924 CET | 13566 | 35842 | 83.222.221.110 | 192.168.2.23 |
Jan 19, 2025 04:57:51.648273945 CET | 35842 | 13566 | 192.168.2.23 | 83.222.221.110 |
Jan 19, 2025 04:57:51.648432970 CET | 32840 | 13566 | 192.168.2.23 | 83.222.218.61 |
Jan 19, 2025 04:57:51.651397943 CET | 13566 | 51408 | 83.222.117.102 | 192.168.2.23 |
Jan 19, 2025 04:57:51.651447058 CET | 51408 | 13566 | 192.168.2.23 | 83.222.117.102 |
Jan 19, 2025 04:57:51.653203011 CET | 13566 | 32840 | 83.222.218.61 | 192.168.2.23 |
Jan 19, 2025 04:57:51.653264046 CET | 32840 | 13566 | 192.168.2.23 | 83.222.218.61 |
Jan 19, 2025 04:57:51.653264046 CET | 60612 | 13566 | 192.168.2.23 | 83.222.135.19 |
Jan 19, 2025 04:57:51.657252073 CET | 44156 | 13566 | 192.168.2.23 | 83.222.40.66 |
Jan 19, 2025 04:57:51.658174038 CET | 13566 | 60612 | 83.222.135.19 | 192.168.2.23 |
Jan 19, 2025 04:57:51.658334017 CET | 60612 | 13566 | 192.168.2.23 | 83.222.135.19 |
Jan 19, 2025 04:57:51.660785913 CET | 37308 | 13566 | 192.168.2.23 | 83.222.104.31 |
Jan 19, 2025 04:57:51.662250042 CET | 13566 | 44156 | 83.222.40.66 | 192.168.2.23 |
Jan 19, 2025 04:57:51.662292004 CET | 44156 | 13566 | 192.168.2.23 | 83.222.40.66 |
Jan 19, 2025 04:57:51.663398981 CET | 60020 | 13566 | 192.168.2.23 | 83.222.75.157 |
Jan 19, 2025 04:57:51.665735006 CET | 13566 | 37308 | 83.222.104.31 | 192.168.2.23 |
Jan 19, 2025 04:57:51.665776968 CET | 37308 | 13566 | 192.168.2.23 | 83.222.104.31 |
Jan 19, 2025 04:57:51.666665077 CET | 50768 | 13566 | 192.168.2.23 | 83.222.226.166 |
Jan 19, 2025 04:57:51.668242931 CET | 13566 | 60020 | 83.222.75.157 | 192.168.2.23 |
Jan 19, 2025 04:57:51.668279886 CET | 60020 | 13566 | 192.168.2.23 | 83.222.75.157 |
Jan 19, 2025 04:57:51.669536114 CET | 55806 | 13566 | 192.168.2.23 | 83.222.95.169 |
Jan 19, 2025 04:57:51.671513081 CET | 13566 | 50768 | 83.222.226.166 | 192.168.2.23 |
Jan 19, 2025 04:57:51.671571970 CET | 50768 | 13566 | 192.168.2.23 | 83.222.226.166 |
Jan 19, 2025 04:57:51.672563076 CET | 34348 | 13566 | 192.168.2.23 | 83.222.217.172 |
Jan 19, 2025 04:57:51.674562931 CET | 13566 | 55806 | 83.222.95.169 | 192.168.2.23 |
Jan 19, 2025 04:57:51.674617052 CET | 55806 | 13566 | 192.168.2.23 | 83.222.95.169 |
Jan 19, 2025 04:57:51.676215887 CET | 48848 | 13566 | 192.168.2.23 | 83.222.102.164 |
Jan 19, 2025 04:57:51.677650928 CET | 13566 | 34348 | 83.222.217.172 | 192.168.2.23 |
Jan 19, 2025 04:57:51.677687883 CET | 34348 | 13566 | 192.168.2.23 | 83.222.217.172 |
Jan 19, 2025 04:57:51.679284096 CET | 49164 | 13566 | 192.168.2.23 | 83.222.9.75 |
Jan 19, 2025 04:57:51.681250095 CET | 53824 | 13566 | 192.168.2.23 | 83.222.73.234 |
Jan 19, 2025 04:57:51.681309938 CET | 13566 | 48848 | 83.222.102.164 | 192.168.2.23 |
Jan 19, 2025 04:57:51.681380987 CET | 48848 | 13566 | 192.168.2.23 | 83.222.102.164 |
Jan 19, 2025 04:57:51.684343100 CET | 13566 | 49164 | 83.222.9.75 | 192.168.2.23 |
Jan 19, 2025 04:57:51.684526920 CET | 49164 | 13566 | 192.168.2.23 | 83.222.9.75 |
Jan 19, 2025 04:57:51.686126947 CET | 13566 | 53824 | 83.222.73.234 | 192.168.2.23 |
Jan 19, 2025 04:57:51.686177015 CET | 53824 | 13566 | 192.168.2.23 | 83.222.73.234 |
Jan 19, 2025 04:57:51.687558889 CET | 50964 | 13566 | 192.168.2.23 | 83.222.211.141 |
Jan 19, 2025 04:57:51.690341949 CET | 41734 | 13566 | 192.168.2.23 | 83.222.249.231 |
Jan 19, 2025 04:57:51.691307068 CET | 52054 | 13566 | 192.168.2.23 | 83.222.233.214 |
Jan 19, 2025 04:57:51.692648888 CET | 13566 | 50964 | 83.222.211.141 | 192.168.2.23 |
Jan 19, 2025 04:57:51.692821026 CET | 50964 | 13566 | 192.168.2.23 | 83.222.211.141 |
Jan 19, 2025 04:57:51.695383072 CET | 13566 | 41734 | 83.222.249.231 | 192.168.2.23 |
Jan 19, 2025 04:57:51.695621014 CET | 41734 | 13566 | 192.168.2.23 | 83.222.249.231 |
Jan 19, 2025 04:57:51.696224928 CET | 13566 | 52054 | 83.222.233.214 | 192.168.2.23 |
Jan 19, 2025 04:57:51.696275949 CET | 52054 | 13566 | 192.168.2.23 | 83.222.233.214 |
Jan 19, 2025 04:57:51.708776951 CET | 52054 | 13566 | 192.168.2.23 | 83.222.233.214 |
Jan 19, 2025 04:57:51.709131002 CET | 58624 | 13566 | 192.168.2.23 | 83.222.85.94 |
Jan 19, 2025 04:57:51.710011005 CET | 44058 | 13566 | 192.168.2.23 | 83.222.61.47 |
Jan 19, 2025 04:57:51.713802099 CET | 13566 | 52054 | 83.222.233.214 | 192.168.2.23 |
Jan 19, 2025 04:57:51.713865042 CET | 52054 | 13566 | 192.168.2.23 | 83.222.233.214 |
Jan 19, 2025 04:57:51.714134932 CET | 13566 | 58624 | 83.222.85.94 | 192.168.2.23 |
Jan 19, 2025 04:57:51.714175940 CET | 58624 | 13566 | 192.168.2.23 | 83.222.85.94 |
Jan 19, 2025 04:57:51.714864016 CET | 13566 | 44058 | 83.222.61.47 | 192.168.2.23 |
Jan 19, 2025 04:57:51.714915037 CET | 44058 | 13566 | 192.168.2.23 | 83.222.61.47 |
Jan 19, 2025 04:57:51.726041079 CET | 44058 | 13566 | 192.168.2.23 | 83.222.61.47 |
Jan 19, 2025 04:57:51.726516962 CET | 52324 | 13566 | 192.168.2.23 | 83.222.156.196 |
Jan 19, 2025 04:57:51.727291107 CET | 47816 | 13566 | 192.168.2.23 | 83.222.66.196 |
Jan 19, 2025 04:57:51.730901957 CET | 13566 | 44058 | 83.222.61.47 | 192.168.2.23 |
Jan 19, 2025 04:57:51.730956078 CET | 44058 | 13566 | 192.168.2.23 | 83.222.61.47 |
Jan 19, 2025 04:57:51.731451035 CET | 13566 | 52324 | 83.222.156.196 | 192.168.2.23 |
Jan 19, 2025 04:57:51.731523037 CET | 52324 | 13566 | 192.168.2.23 | 83.222.156.196 |
Jan 19, 2025 04:57:51.732176065 CET | 13566 | 47816 | 83.222.66.196 | 192.168.2.23 |
Jan 19, 2025 04:57:51.732232094 CET | 47816 | 13566 | 192.168.2.23 | 83.222.66.196 |
Jan 19, 2025 04:57:51.759438038 CET | 47816 | 13566 | 192.168.2.23 | 83.222.66.196 |
Jan 19, 2025 04:57:51.760823011 CET | 45888 | 13566 | 192.168.2.23 | 83.222.6.171 |
Jan 19, 2025 04:57:51.763686895 CET | 49016 | 13566 | 192.168.2.23 | 83.222.228.82 |
Jan 19, 2025 04:57:51.765769958 CET | 13566 | 47816 | 83.222.66.196 | 192.168.2.23 |
Jan 19, 2025 04:57:51.765865088 CET | 36942 | 13566 | 192.168.2.23 | 83.222.72.198 |
Jan 19, 2025 04:57:51.765914917 CET | 47816 | 13566 | 192.168.2.23 | 83.222.66.196 |
Jan 19, 2025 04:57:51.766630888 CET | 57352 | 13566 | 192.168.2.23 | 83.222.248.167 |
Jan 19, 2025 04:57:51.767021894 CET | 13566 | 45888 | 83.222.6.171 | 192.168.2.23 |
Jan 19, 2025 04:57:51.767070055 CET | 45888 | 13566 | 192.168.2.23 | 83.222.6.171 |
Jan 19, 2025 04:57:51.769854069 CET | 13566 | 49016 | 83.222.228.82 | 192.168.2.23 |
Jan 19, 2025 04:57:51.770129919 CET | 49016 | 13566 | 192.168.2.23 | 83.222.228.82 |
Jan 19, 2025 04:57:51.771893978 CET | 13566 | 36942 | 83.222.72.198 | 192.168.2.23 |
Jan 19, 2025 04:57:51.771944046 CET | 36942 | 13566 | 192.168.2.23 | 83.222.72.198 |
Jan 19, 2025 04:57:51.772577047 CET | 13566 | 57352 | 83.222.248.167 | 192.168.2.23 |
Jan 19, 2025 04:57:51.772618055 CET | 57352 | 13566 | 192.168.2.23 | 83.222.248.167 |
Jan 19, 2025 04:57:51.787033081 CET | 46198 | 13566 | 192.168.2.23 | 83.222.111.209 |
Jan 19, 2025 04:57:51.792107105 CET | 60478 | 13566 | 192.168.2.23 | 83.222.83.214 |
Jan 19, 2025 04:57:51.792171955 CET | 13566 | 46198 | 83.222.111.209 | 192.168.2.23 |
Jan 19, 2025 04:57:51.792365074 CET | 46198 | 13566 | 192.168.2.23 | 83.222.111.209 |
Jan 19, 2025 04:57:51.797189951 CET | 13566 | 60478 | 83.222.83.214 | 192.168.2.23 |
Jan 19, 2025 04:57:51.797257900 CET | 60478 | 13566 | 192.168.2.23 | 83.222.83.214 |
Jan 19, 2025 04:57:51.807638884 CET | 49048 | 13566 | 192.168.2.23 | 83.222.118.92 |
Jan 19, 2025 04:57:51.811693907 CET | 56070 | 13566 | 192.168.2.23 | 83.222.33.191 |
Jan 19, 2025 04:57:51.812551975 CET | 13566 | 49048 | 83.222.118.92 | 192.168.2.23 |
Jan 19, 2025 04:57:51.812727928 CET | 49048 | 13566 | 192.168.2.23 | 83.222.118.92 |
Jan 19, 2025 04:57:51.815280914 CET | 58736 | 13566 | 192.168.2.23 | 83.222.70.245 |
Jan 19, 2025 04:57:51.816760063 CET | 13566 | 56070 | 83.222.33.191 | 192.168.2.23 |
Jan 19, 2025 04:57:51.816929102 CET | 56070 | 13566 | 192.168.2.23 | 83.222.33.191 |
Jan 19, 2025 04:57:51.818389893 CET | 56560 | 13566 | 192.168.2.23 | 83.222.76.64 |
Jan 19, 2025 04:57:51.819828987 CET | 55626 | 13566 | 192.168.2.23 | 83.222.220.53 |
Jan 19, 2025 04:57:51.820242882 CET | 13566 | 58736 | 83.222.70.245 | 192.168.2.23 |
Jan 19, 2025 04:57:51.820292950 CET | 58736 | 13566 | 192.168.2.23 | 83.222.70.245 |
Jan 19, 2025 04:57:51.822772980 CET | 45998 | 13566 | 192.168.2.23 | 83.222.22.49 |
Jan 19, 2025 04:57:51.823263884 CET | 13566 | 56560 | 83.222.76.64 | 192.168.2.23 |
Jan 19, 2025 04:57:51.823329926 CET | 56560 | 13566 | 192.168.2.23 | 83.222.76.64 |
Jan 19, 2025 04:57:51.824692965 CET | 13566 | 55626 | 83.222.220.53 | 192.168.2.23 |
Jan 19, 2025 04:57:51.824747086 CET | 55626 | 13566 | 192.168.2.23 | 83.222.220.53 |
Jan 19, 2025 04:57:51.827156067 CET | 47878 | 13566 | 192.168.2.23 | 83.222.148.83 |
Jan 19, 2025 04:57:51.827575922 CET | 13566 | 45998 | 83.222.22.49 | 192.168.2.23 |
Jan 19, 2025 04:57:51.827625036 CET | 45998 | 13566 | 192.168.2.23 | 83.222.22.49 |
Jan 19, 2025 04:57:51.831954002 CET | 13566 | 47878 | 83.222.148.83 | 192.168.2.23 |
Jan 19, 2025 04:57:51.832005024 CET | 47878 | 13566 | 192.168.2.23 | 83.222.148.83 |
Jan 19, 2025 04:57:51.832808971 CET | 42160 | 13566 | 192.168.2.23 | 83.222.97.48 |
Jan 19, 2025 04:57:51.837600946 CET | 13566 | 42160 | 83.222.97.48 | 192.168.2.23 |
Jan 19, 2025 04:57:51.837645054 CET | 42160 | 13566 | 192.168.2.23 | 83.222.97.48 |
Jan 19, 2025 04:57:51.840539932 CET | 43780 | 13566 | 192.168.2.23 | 83.222.23.163 |
Jan 19, 2025 04:57:51.845467091 CET | 13566 | 43780 | 83.222.23.163 | 192.168.2.23 |
Jan 19, 2025 04:57:51.845505953 CET | 43780 | 13566 | 192.168.2.23 | 83.222.23.163 |
Jan 19, 2025 04:57:51.845566988 CET | 37244 | 13566 | 192.168.2.23 | 83.222.244.30 |
Jan 19, 2025 04:57:51.847254992 CET | 40472 | 13566 | 192.168.2.23 | 83.222.78.216 |
Jan 19, 2025 04:57:51.849143982 CET | 47574 | 13566 | 192.168.2.23 | 83.222.112.150 |
Jan 19, 2025 04:57:51.850408077 CET | 13566 | 37244 | 83.222.244.30 | 192.168.2.23 |
Jan 19, 2025 04:57:51.850455999 CET | 37244 | 13566 | 192.168.2.23 | 83.222.244.30 |
Jan 19, 2025 04:57:51.850509882 CET | 35348 | 13566 | 192.168.2.23 | 83.222.159.104 |
Jan 19, 2025 04:57:51.851329088 CET | 57414 | 13566 | 192.168.2.23 | 83.222.62.14 |
Jan 19, 2025 04:57:51.852344036 CET | 13566 | 40472 | 83.222.78.216 | 192.168.2.23 |
Jan 19, 2025 04:57:51.852394104 CET | 40472 | 13566 | 192.168.2.23 | 83.222.78.216 |
Jan 19, 2025 04:57:51.852394104 CET | 53024 | 13566 | 192.168.2.23 | 83.222.58.145 |
Jan 19, 2025 04:57:51.853951931 CET | 13566 | 47574 | 83.222.112.150 | 192.168.2.23 |
Jan 19, 2025 04:57:51.854015112 CET | 47574 | 13566 | 192.168.2.23 | 83.222.112.150 |
Jan 19, 2025 04:57:51.855427027 CET | 13566 | 35348 | 83.222.159.104 | 192.168.2.23 |
Jan 19, 2025 04:57:51.855674982 CET | 35348 | 13566 | 192.168.2.23 | 83.222.159.104 |
Jan 19, 2025 04:57:51.855885029 CET | 42774 | 13566 | 192.168.2.23 | 83.222.228.176 |
Jan 19, 2025 04:57:51.856149912 CET | 13566 | 57414 | 83.222.62.14 | 192.168.2.23 |
Jan 19, 2025 04:57:51.856189966 CET | 57414 | 13566 | 192.168.2.23 | 83.222.62.14 |
Jan 19, 2025 04:57:51.857295036 CET | 13566 | 53024 | 83.222.58.145 | 192.168.2.23 |
Jan 19, 2025 04:57:51.857462883 CET | 53024 | 13566 | 192.168.2.23 | 83.222.58.145 |
Jan 19, 2025 04:57:51.857702971 CET | 36902 | 13566 | 192.168.2.23 | 83.222.238.6 |
Jan 19, 2025 04:57:51.859772921 CET | 34304 | 13566 | 192.168.2.23 | 83.222.111.52 |
Jan 19, 2025 04:57:51.860761881 CET | 13566 | 42774 | 83.222.228.176 | 192.168.2.23 |
Jan 19, 2025 04:57:51.860799074 CET | 42774 | 13566 | 192.168.2.23 | 83.222.228.176 |
Jan 19, 2025 04:57:51.861659050 CET | 46114 | 13566 | 192.168.2.23 | 83.222.251.188 |
Jan 19, 2025 04:57:51.862600088 CET | 13566 | 36902 | 83.222.238.6 | 192.168.2.23 |
Jan 19, 2025 04:57:51.862751007 CET | 36902 | 13566 | 192.168.2.23 | 83.222.238.6 |
Jan 19, 2025 04:57:51.863694906 CET | 54528 | 13566 | 192.168.2.23 | 83.222.116.215 |
Jan 19, 2025 04:57:51.864625931 CET | 13566 | 34304 | 83.222.111.52 | 192.168.2.23 |
Jan 19, 2025 04:57:51.864669085 CET | 34304 | 13566 | 192.168.2.23 | 83.222.111.52 |
Jan 19, 2025 04:57:51.865641117 CET | 37360 | 13566 | 192.168.2.23 | 83.222.241.139 |
Jan 19, 2025 04:57:51.866565943 CET | 13566 | 46114 | 83.222.251.188 | 192.168.2.23 |
Jan 19, 2025 04:57:51.866740942 CET | 46114 | 13566 | 192.168.2.23 | 83.222.251.188 |
Jan 19, 2025 04:57:51.867615938 CET | 57022 | 13566 | 192.168.2.23 | 83.222.8.133 |
Jan 19, 2025 04:57:51.868529081 CET | 13566 | 54528 | 83.222.116.215 | 192.168.2.23 |
Jan 19, 2025 04:57:51.868565083 CET | 54528 | 13566 | 192.168.2.23 | 83.222.116.215 |
Jan 19, 2025 04:57:51.869018078 CET | 38526 | 13566 | 192.168.2.23 | 83.222.222.105 |
Jan 19, 2025 04:57:51.870507002 CET | 33564 | 13566 | 192.168.2.23 | 83.222.181.246 |
Jan 19, 2025 04:57:51.870534897 CET | 13566 | 37360 | 83.222.241.139 | 192.168.2.23 |
Jan 19, 2025 04:57:51.870599031 CET | 37360 | 13566 | 192.168.2.23 | 83.222.241.139 |
Jan 19, 2025 04:57:51.872438908 CET | 13566 | 57022 | 83.222.8.133 | 192.168.2.23 |
Jan 19, 2025 04:57:51.872490883 CET | 57022 | 13566 | 192.168.2.23 | 83.222.8.133 |
Jan 19, 2025 04:57:51.873166084 CET | 39638 | 13566 | 192.168.2.23 | 83.222.13.170 |
Jan 19, 2025 04:57:51.873931885 CET | 13566 | 38526 | 83.222.222.105 | 192.168.2.23 |
Jan 19, 2025 04:57:51.874118090 CET | 38526 | 13566 | 192.168.2.23 | 83.222.222.105 |
Jan 19, 2025 04:57:51.875302076 CET | 13566 | 33564 | 83.222.181.246 | 192.168.2.23 |
Jan 19, 2025 04:57:51.875350952 CET | 33564 | 13566 | 192.168.2.23 | 83.222.181.246 |
Jan 19, 2025 04:57:51.875611067 CET | 42188 | 13566 | 192.168.2.23 | 83.222.20.91 |
Jan 19, 2025 04:57:51.878007889 CET | 13566 | 39638 | 83.222.13.170 | 192.168.2.23 |
Jan 19, 2025 04:57:51.878066063 CET | 39638 | 13566 | 192.168.2.23 | 83.222.13.170 |
Jan 19, 2025 04:57:51.878552914 CET | 55890 | 13566 | 192.168.2.23 | 83.222.130.132 |
Jan 19, 2025 04:57:51.880417109 CET | 13566 | 42188 | 83.222.20.91 | 192.168.2.23 |
Jan 19, 2025 04:57:51.880456924 CET | 42188 | 13566 | 192.168.2.23 | 83.222.20.91 |
Jan 19, 2025 04:57:51.881426096 CET | 60314 | 13566 | 192.168.2.23 | 83.222.242.33 |
Jan 19, 2025 04:57:51.883394003 CET | 13566 | 55890 | 83.222.130.132 | 192.168.2.23 |
Jan 19, 2025 04:57:51.883900881 CET | 55890 | 13566 | 192.168.2.23 | 83.222.130.132 |
Jan 19, 2025 04:57:51.886394024 CET | 13566 | 60314 | 83.222.242.33 | 192.168.2.23 |
Jan 19, 2025 04:57:51.886440039 CET | 60314 | 13566 | 192.168.2.23 | 83.222.242.33 |
Jan 19, 2025 04:57:51.897608995 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:57:51.902553082 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:57:51.902667046 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:57:51.905420065 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:57:51.910274029 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:57:51.910343885 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:57:51.915307045 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:57:56.774852991 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 19, 2025 04:57:57.798624992 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 19, 2025 04:58:01.914154053 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:58:01.919394970 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:58:02.128716946 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:58:02.128967047 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:58:02.484690905 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:58:02.485003948 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:58:11.876635075 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 19, 2025 04:58:24.162866116 CET | 42836 | 443 | 192.168.2.23 | 91.189.91.43 |
Jan 19, 2025 04:58:28.258505106 CET | 42516 | 80 | 192.168.2.23 | 109.202.202.202 |
Jan 19, 2025 04:58:52.831103086 CET | 43928 | 443 | 192.168.2.23 | 91.189.91.42 |
Jan 19, 2025 04:59:02.513159037 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:59:02.518238068 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:59:02.716372013 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:59:02.716583967 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Jan 19, 2025 04:59:03.484093904 CET | 13566 | 42658 | 83.222.191.90 | 192.168.2.23 |
Jan 19, 2025 04:59:03.484272957 CET | 42658 | 13566 | 192.168.2.23 | 83.222.191.90 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 19, 2025 04:57:51.886432886 CET | 37875 | 53 | 192.168.2.23 | 8.8.8.8 |
Jan 19, 2025 04:57:51.895147085 CET | 53 | 37875 | 8.8.8.8 | 192.168.2.23 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 19, 2025 04:57:51.886432886 CET | 192.168.2.23 | 8.8.8.8 | 0x3fb5 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 19, 2025 04:57:51.895147085 CET | 8.8.8.8 | 192.168.2.23 | 0x3fb5 | No error (0) | 83.222.191.90 | A (IP address) | IN (0x0001) | false |
System Behavior
Start time (UTC): | 03:57:50 |
Start date (UTC): | 19/01/2025 |
Path: | /tmp/Kloki.mpsl.elf |
Arguments: | /tmp/Kloki.mpsl.elf |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 03:57:50 |
Start date (UTC): | 19/01/2025 |
Path: | /tmp/Kloki.mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 03:57:50 |
Start date (UTC): | 19/01/2025 |
Path: | /tmp/Kloki.mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 03:57:50 |
Start date (UTC): | 19/01/2025 |
Path: | /tmp/Kloki.mpsl.elf |
Arguments: | - |
File size: | 5773336 bytes |
MD5 hash: | 0d6f61f82cf2f781c6eb0661071d42d9 |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/bin/gnome-shell |
Arguments: | /usr/bin/gnome-shell |
File size: | 23168 bytes |
MD5 hash: | da7a257239677622fe4b3a65972c9e87 |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/libexec/gsd-print-notifications |
Arguments: | /usr/libexec/gsd-print-notifications |
File size: | 51840 bytes |
MD5 hash: | 71539698aa691718cee775d6b9450ae2 |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/libexec/gnome-session-binary |
Arguments: | - |
File size: | 334664 bytes |
MD5 hash: | d9b90be4f7db60cb3c2d3da6a1d31bfb |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /bin/sh |
Arguments: | /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/libexec/gsd-rfkill |
Arguments: | /usr/libexec/gsd-rfkill |
File size: | 51808 bytes |
MD5 hash: | 88a16a3c0aba1759358c06215ecfb5cc |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /usr/sbin/gdm3 |
Arguments: | - |
File size: | 453296 bytes |
MD5 hash: | 2492e2d8d34f9377e3e530a61a15674f |
Start time (UTC): | 03:57:51 |
Start date (UTC): | 19/01/2025 |
Path: | /etc/gdm3/PrimeOff/Default |
Arguments: | /etc/gdm3/PrimeOff/Default |
File size: | 129816 bytes |
MD5 hash: | 1e6b1c887c59a315edb7eb9a315fc84c |