Edit tour

Linux Analysis Report
Kloki.mpsl.elf

Overview

General Information

Sample name:Kloki.mpsl.elf
Analysis ID:1594521
MD5:8bac1d6f2b0b06ee318a36bdeb0e6722
SHA1:009a4fa9f4eeca19fc05c7d05ee180458d7e47e7
SHA256:e2dcccd310db024365d99ed4d2ca34c7df4fe90005ede03b1382c6ec129b24b3
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Suricata IDS alerts with low severity for network traffic
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1594521
Start date and time:2025-01-19 04:57:04 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Kloki.mpsl.elf
Detection:MAL
Classification:mal60.spre.linELF@0/0@1/0
Command:/tmp/Kloki.mpsl.elf
PID:6243
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
suka
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 6273, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
  • sh (PID: 6275, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
  • gnome-shell (PID: 6275, Parent: 1477, MD5: da7a257239677622fe4b3a65972c9e87) Arguments: /usr/bin/gnome-shell
  • sh (PID: 6277, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
  • gsd-print-notifications (PID: 6277, Parent: 1477, MD5: 71539698aa691718cee775d6b9450ae2) Arguments: /usr/libexec/gsd-print-notifications
  • sh (PID: 6280, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 6280, Parent: 1477, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • gdm3 New Fork (PID: 6281, Parent: 1320)
  • Default (PID: 6281, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 6282, Parent: 1320)
  • Default (PID: 6282, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-01-19T04:57:51.902553+010025000342Misc Attack83.222.191.9013566192.168.2.2342658TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Kloki.mpsl.elfAvira: detected
Source: Kloki.mpsl.elfReversingLabs: Detection: 28%
Source: Kloki.mpsl.elfString: ppid/proc/net/tcp/proc/self/exe/proc//status/fd//dev/null/dev/consolesocket05/proc/%d/exepkillkillkillallechowgetcurlpsbusyboxiptablesrebootshutdownhaltpoweroffinitsystemctltelinitcatgrepshashbashzshcshkshdashfish
Source: global trafficTCP traffic: 192.168.2.23:42546 -> 83.222.229.165:13566
Source: global trafficTCP traffic: 192.168.2.23:54388 -> 83.222.225.136:13566
Source: global trafficTCP traffic: 192.168.2.23:58286 -> 83.222.67.15:13566
Source: global trafficTCP traffic: 192.168.2.23:43674 -> 83.222.19.92:13566
Source: global trafficTCP traffic: 192.168.2.23:35842 -> 83.222.221.110:13566
Source: global trafficTCP traffic: 192.168.2.23:51408 -> 83.222.117.102:13566
Source: global trafficTCP traffic: 192.168.2.23:32840 -> 83.222.218.61:13566
Source: global trafficTCP traffic: 192.168.2.23:60612 -> 83.222.135.19:13566
Source: global trafficTCP traffic: 192.168.2.23:44156 -> 83.222.40.66:13566
Source: global trafficTCP traffic: 192.168.2.23:37308 -> 83.222.104.31:13566
Source: global trafficTCP traffic: 192.168.2.23:60020 -> 83.222.75.157:13566
Source: global trafficTCP traffic: 192.168.2.23:50768 -> 83.222.226.166:13566
Source: global trafficTCP traffic: 192.168.2.23:55806 -> 83.222.95.169:13566
Source: global trafficTCP traffic: 192.168.2.23:34348 -> 83.222.217.172:13566
Source: global trafficTCP traffic: 192.168.2.23:48848 -> 83.222.102.164:13566
Source: global trafficTCP traffic: 192.168.2.23:49164 -> 83.222.9.75:13566
Source: global trafficTCP traffic: 192.168.2.23:53824 -> 83.222.73.234:13566
Source: global trafficTCP traffic: 192.168.2.23:50964 -> 83.222.211.141:13566
Source: global trafficTCP traffic: 192.168.2.23:41734 -> 83.222.249.231:13566
Source: global trafficTCP traffic: 192.168.2.23:52054 -> 83.222.233.214:13566
Source: global trafficTCP traffic: 192.168.2.23:58624 -> 83.222.85.94:13566
Source: global trafficTCP traffic: 192.168.2.23:44058 -> 83.222.61.47:13566
Source: global trafficTCP traffic: 192.168.2.23:52324 -> 83.222.156.196:13566
Source: global trafficTCP traffic: 192.168.2.23:47816 -> 83.222.66.196:13566
Source: global trafficTCP traffic: 192.168.2.23:45888 -> 83.222.6.171:13566
Source: global trafficTCP traffic: 192.168.2.23:49016 -> 83.222.228.82:13566
Source: global trafficTCP traffic: 192.168.2.23:36942 -> 83.222.72.198:13566
Source: global trafficTCP traffic: 192.168.2.23:57352 -> 83.222.248.167:13566
Source: global trafficTCP traffic: 192.168.2.23:46198 -> 83.222.111.209:13566
Source: global trafficTCP traffic: 192.168.2.23:60478 -> 83.222.83.214:13566
Source: global trafficTCP traffic: 192.168.2.23:49048 -> 83.222.118.92:13566
Source: global trafficTCP traffic: 192.168.2.23:56070 -> 83.222.33.191:13566
Source: global trafficTCP traffic: 192.168.2.23:58736 -> 83.222.70.245:13566
Source: global trafficTCP traffic: 192.168.2.23:56560 -> 83.222.76.64:13566
Source: global trafficTCP traffic: 192.168.2.23:55626 -> 83.222.220.53:13566
Source: global trafficTCP traffic: 192.168.2.23:45998 -> 83.222.22.49:13566
Source: global trafficTCP traffic: 192.168.2.23:47878 -> 83.222.148.83:13566
Source: global trafficTCP traffic: 192.168.2.23:42160 -> 83.222.97.48:13566
Source: global trafficTCP traffic: 192.168.2.23:43780 -> 83.222.23.163:13566
Source: global trafficTCP traffic: 192.168.2.23:37244 -> 83.222.244.30:13566
Source: global trafficTCP traffic: 192.168.2.23:40472 -> 83.222.78.216:13566
Source: global trafficTCP traffic: 192.168.2.23:47574 -> 83.222.112.150:13566
Source: global trafficTCP traffic: 192.168.2.23:35348 -> 83.222.159.104:13566
Source: global trafficTCP traffic: 192.168.2.23:57414 -> 83.222.62.14:13566
Source: global trafficTCP traffic: 192.168.2.23:53024 -> 83.222.58.145:13566
Source: global trafficTCP traffic: 192.168.2.23:42774 -> 83.222.228.176:13566
Source: global trafficTCP traffic: 192.168.2.23:36902 -> 83.222.238.6:13566
Source: global trafficTCP traffic: 192.168.2.23:34304 -> 83.222.111.52:13566
Source: global trafficTCP traffic: 192.168.2.23:46114 -> 83.222.251.188:13566
Source: global trafficTCP traffic: 192.168.2.23:54528 -> 83.222.116.215:13566
Source: global trafficTCP traffic: 192.168.2.23:37360 -> 83.222.241.139:13566
Source: global trafficTCP traffic: 192.168.2.23:57022 -> 83.222.8.133:13566
Source: global trafficTCP traffic: 192.168.2.23:38526 -> 83.222.222.105:13566
Source: global trafficTCP traffic: 192.168.2.23:33564 -> 83.222.181.246:13566
Source: global trafficTCP traffic: 192.168.2.23:39638 -> 83.222.13.170:13566
Source: global trafficTCP traffic: 192.168.2.23:42188 -> 83.222.20.91:13566
Source: global trafficTCP traffic: 192.168.2.23:55890 -> 83.222.130.132:13566
Source: global trafficTCP traffic: 192.168.2.23:60314 -> 83.222.242.33:13566
Source: global trafficTCP traffic: 192.168.2.23:42658 -> 83.222.191.90:13566
Source: /tmp/Kloki.mpsl.elf (PID: 6243)Socket: 127.0.0.1:14435Jump to behavior
Source: Network trafficSuricata IDS: 2500034 - Severity 2 - ET COMPROMISED Known Compromised or Hostile Host Traffic group 18 : 83.222.191.90:13566 -> 192.168.2.23:42658
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.229.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.229.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.229.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.229.165
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.225.136
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.67.15
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.19.92
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.225.136
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.67.15
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.19.92
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.19.92
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.221.110
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.19.92
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.117.102
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.221.110
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.218.61
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.117.102
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.218.61
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.135.19
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.40.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.135.19
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.104.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.40.66
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.75.157
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.104.31
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.226.166
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.75.157
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.95.169
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.226.166
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.217.172
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.95.169
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.102.164
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.217.172
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.9.75
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.234
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.102.164
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.9.75
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.73.234
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.211.141
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.249.231
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.233.214
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.211.141
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.249.231
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.233.214
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.233.214
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.85.94
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.61.47
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.233.214
Source: unknownTCP traffic detected without corresponding DNS query: 83.222.85.94
Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 904, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 912, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 918, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1532, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1983, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 2302, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6226, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6273, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6275, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6277, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6280, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6282, result: successfulJump to behavior
Source: Initial sampleString containing 'busybox' found: busybox
Source: Initial sampleString containing 'busybox' found: ppid/proc/net/tcp/proc/self/exe/proc//status/fd//dev/null/dev/consolesocket05/proc/%d/exepkillkillkillallechowgetcurlpsbusyboxiptablesrebootshutdownhaltpoweroffinitsystemctltelinitcatgrepshashbashzshcshkshdashfish
Source: ELF static info symbol of initial sample.symtab present: no
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 904, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 912, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 918, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 936, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1532, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1622, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1633, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1638, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 1983, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 2146, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 2302, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6226, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6245, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6273, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6275, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6277, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6280, result: successfulJump to behavior
Source: /tmp/Kloki.mpsl.elf (PID: 6249)SIGKILL sent: pid: 6282, result: successfulJump to behavior
Source: classification engineClassification label: mal60.spre.linELF@0/0@1/0
Source: /tmp/Kloki.mpsl.elf (PID: 6243)Queries kernel information via 'uname': Jump to behavior
Source: Kloki.mpsl.elf, 6243.1.00005575dcba9000.00005575dcc51000.rw-.sdmp, Kloki.mpsl.elf, 6245.1.00005575dcba9000.00005575dcc30000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: Kloki.mpsl.elf, 6243.1.00007ffd3a3e3000.00007ffd3a404000.rw-.sdmp, Kloki.mpsl.elf, 6245.1.00007ffd3a3e3000.00007ffd3a404000.rw-.sdmpBinary or memory string: Lx86_64/usr/bin/qemu-mipsel/tmp/Kloki.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Kloki.mpsl.elf
Source: Kloki.mpsl.elf, 6243.1.00005575dcba9000.00005575dcc51000.rw-.sdmp, Kloki.mpsl.elf, 6245.1.00005575dcba9000.00005575dcc30000.rw-.sdmpBinary or memory string: uU!/etc/qemu-binfmt/mipsel
Source: Kloki.mpsl.elf, 6243.1.00007ffd3a3e3000.00007ffd3a404000.rw-.sdmp, Kloki.mpsl.elf, 6245.1.00007ffd3a3e3000.00007ffd3a404000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid AccountsWindows Management Instrumentation1
Scripting
Path InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network Medium1
Service Stop
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1594521 Sample: Kloki.mpsl.elf Startdate: 19/01/2025 Architecture: LINUX Score: 60 23 83.222.211.141, 13566, 50964 SYNTERRA-ASRU Russian Federation 2->23 25 83.222.217.172, 13566, 34348 SONICDUO-ASRU Russian Federation 2->25 27 60 other IPs or domains 2->27 29 Antivirus / Scanner detection for submitted sample 2->29 31 Multi AV Scanner detection for submitted file 2->31 8 Kloki.mpsl.elf 2->8         started        10 gnome-session-binary sh gnome-shell 2->10         started        12 gnome-session-binary sh gsd-print-notifications 2->12         started        14 4 other processes 2->14 signatures3 process4 process5 16 Kloki.mpsl.elf 8->16         started        18 Kloki.mpsl.elf 8->18         started        process6 20 Kloki.mpsl.elf 16->20         started        signatures7 33 Sample tries to kill multiple processes (SIGKILL) 20->33
SourceDetectionScannerLabelLink
Kloki.mpsl.elf29%ReversingLabsLinux.Backdoor.Mirai
Kloki.mpsl.elf100%AviraEXP/ELF.Mirai.W
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
secure-network-rebirthltd.ru
83.222.191.90
truefalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    83.222.117.102
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.22.49
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.181.246
    unknownBulgaria
    12615GCN-ASGCNAD-SofiaBulgariaBGfalse
    83.222.222.105
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.97.48
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.116.215
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.244.30
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.83.214
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.61.47
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.62.14
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.9.75
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.228.82
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    83.222.6.171
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.40.66
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.73.234
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.78.216
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.70.245
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.112.150
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.58.145
    unknownLuxembourg
    8632LOL-ASluLUfalse
    83.222.249.231
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.72.198
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.148.83
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.229.165
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.156.196
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.248.167
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.238.6
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.159.104
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.111.209
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.23.163
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.67.15
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.228.176
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.225.136
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.66.196
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.104.31
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.95.169
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.233.214
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.19.92
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.135.19
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.217.172
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.221.110
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.242.33
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.75.157
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.211.141
    unknownRussian Federation
    6854SYNTERRA-ASRUfalse
    83.222.20.91
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.118.92
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.85.94
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.191.90
    secure-network-rebirthltd.ruBulgaria
    43561NET1-ASBGfalse
    83.222.33.191
    unknownLuxembourg
    8632LOL-ASluLUfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    83.222.218.61
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.111.52
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.130.132
    unknownSwitzerland
    31736SENSELAN-ASsenseLANGmbHCHfalse
    83.222.226.166
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.76.64
    unknownRussian Federation
    16285ASN-UMNTechnicheskayaStr18bYekaterinburgRussiaRUfalse
    83.222.251.188
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.102.164
    unknownRussian Federation
    42632MNOGOBYTE-ASMoscowRussiaRUfalse
    83.222.220.53
    unknownRussian Federation
    25159SONICDUO-ASRUfalse
    83.222.241.139
    unknownUnited Kingdom
    13768COGECO-PEER1CAfalse
    83.222.8.133
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    83.222.13.170
    unknownRussian Federation
    25532MASTERHOST-ASMoscowRussiaRUfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    83.222.58.145Kloki.m68k.elfGet hashmaliciousUnknownBrowse
      Kloki.x86.elfGet hashmaliciousUnknownBrowse
        91.189.91.43sh4.elfGet hashmaliciousUnknownBrowse
          na.elfGet hashmaliciousPrometeiBrowse
            Kloki.arm6.elfGet hashmaliciousUnknownBrowse
              loki.x86.elfGet hashmaliciousUnknownBrowse
                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                  loki.arm7.elfGet hashmaliciousMiraiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      loki.arc.elfGet hashmaliciousUnknownBrowse
                        Kloki.arm5.elfGet hashmaliciousUnknownBrowse
                          Kloki.arm7.elfGet hashmaliciousMiraiBrowse
                            91.189.91.42sh4.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                  Kloki.arm6.elfGet hashmaliciousUnknownBrowse
                                    loki.x86.elfGet hashmaliciousUnknownBrowse
                                      Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                        loki.arm7.elfGet hashmaliciousMiraiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            loki.arc.elfGet hashmaliciousUnknownBrowse
                                              Kloki.arm5.elfGet hashmaliciousUnknownBrowse
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                secure-network-rebirthltd.ruloki.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                loki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.191.90
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                MASTERHOST-ASMoscowRussiaRUloki.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.18.196
                                                loki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.28.205
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.12.215
                                                loki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.17.194
                                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.8.97
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.20.238
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.23.89
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.23.89
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.31.69
                                                loki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.9.65
                                                GCN-ASGCNAD-SofiaBulgariaBGloki.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.161.248
                                                loki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.173.106
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.171.105
                                                loki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.171.33
                                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.176.201
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.176.96
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.177.55
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.177.55
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.174.216
                                                loki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.175.167
                                                MNOGOBYTE-ASMoscowRussiaRUloki.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.123.142
                                                loki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.99.79
                                                loki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.123.192
                                                loki.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.106.184
                                                Kloki.arm4.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.114.40
                                                Kloki.m68k.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.100.166
                                                Kloki.i686.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.114.84
                                                loki.x86.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.117.151
                                                Kloki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.105.103
                                                loki.mips.elfGet hashmaliciousUnknownBrowse
                                                • 83.222.113.134
                                                No context
                                                No context
                                                No created / dropped files found
                                                File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                Entropy (8bit):5.423247558159363
                                                TrID:
                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                File name:Kloki.mpsl.elf
                                                File size:84'796 bytes
                                                MD5:8bac1d6f2b0b06ee318a36bdeb0e6722
                                                SHA1:009a4fa9f4eeca19fc05c7d05ee180458d7e47e7
                                                SHA256:e2dcccd310db024365d99ed4d2ca34c7df4fe90005ede03b1382c6ec129b24b3
                                                SHA512:bede97e9fa1533006ac19debfcc5603a6702895ae79c404a2ca5d0bc75a824c2c2a92618d8bfa2442a1f765b488cdd54d488c10b8e33a2fc4e5b55ac0baa75dc
                                                SSDEEP:1536:1SA1rzbZe+i9eFDcpbY16Iu6zVMtTJPjncZuZBvR0Vs/:1X9bZe+ueFmTJ7ncyUs/
                                                TLSH:E283C706BF550FBBDC6FDD370AA9170535CC550A22E83B3A7934D828B64B21B56E3CA4
                                                File Content Preview:.ELF....................`.@.4....I......4. ...(...............@...@. 6.. 6...............@...@E..@E.....x:..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<X..'!...........P!9

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, little endian
                                                Version:1 (current)
                                                Machine:MIPS R3000
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x400260
                                                Flags:0x1007
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:3
                                                Section Header Offset:84236
                                                Section Header Size:40
                                                Number of Section Headers:14
                                                Header String Table Index:13
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                .textPROGBITS0x4001200x1200x120a00x00x6AX0016
                                                .finiPROGBITS0x4121c00x121c00x5c0x00x6AX004
                                                .rodataPROGBITS0x4122200x122200x14000x00x2A0016
                                                .ctorsPROGBITS0x4540000x140000x80x00x3WA004
                                                .dtorsPROGBITS0x4540080x140080x80x00x3WA004
                                                .data.rel.roPROGBITS0x4540140x140140x740x00x3WA004
                                                .dataPROGBITS0x4540900x140900x3c00x00x3WA0016
                                                .gotPROGBITS0x4544500x144500x4580x40x10000003WAp0016
                                                .sbssNOBITS0x4548a80x148a80x1c0x00x10000003WAp004
                                                .bssNOBITS0x4548d00x148a80x31a80x00x3WA0016
                                                .mdebug.abi32PROGBITS0x9fc0x148a80x00x00x0001
                                                .shstrtabSTRTAB0x00x148a80x640x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x4000000x4000000x136200x136205.56040x5R E0x10000.init .text .fini .rodata
                                                LOAD0x140000x4540000x4540000x8a80x3a783.99740x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                Download Network PCAP: filteredfull

                                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                2025-01-19T04:57:51.902553+01002500034ET COMPROMISED Known Compromised or Hostile Host Traffic group 18283.222.191.9013566192.168.2.2342658TCP
                                                • Total Packets: 144
                                                • 13566 undefined
                                                • 443 (HTTPS)
                                                • 80 (HTTP)
                                                • 53 (DNS)
                                                TimestampSource PortDest PortSource IPDest IP
                                                Jan 19, 2025 04:57:51.143492937 CET43928443192.168.2.2391.189.91.42
                                                Jan 19, 2025 04:57:51.579282045 CET4254613566192.168.2.2383.222.229.165
                                                Jan 19, 2025 04:57:51.584366083 CET135664254683.222.229.165192.168.2.23
                                                Jan 19, 2025 04:57:51.584436893 CET4254613566192.168.2.2383.222.229.165
                                                Jan 19, 2025 04:57:51.584481955 CET4254613566192.168.2.2383.222.229.165
                                                Jan 19, 2025 04:57:51.589525938 CET135664254683.222.229.165192.168.2.23
                                                Jan 19, 2025 04:57:51.589684963 CET4254613566192.168.2.2383.222.229.165
                                                Jan 19, 2025 04:57:51.601728916 CET5438813566192.168.2.2383.222.225.136
                                                Jan 19, 2025 04:57:51.604068995 CET5828613566192.168.2.2383.222.67.15
                                                Jan 19, 2025 04:57:51.605680943 CET4367413566192.168.2.2383.222.19.92
                                                Jan 19, 2025 04:57:51.606704950 CET135665438883.222.225.136192.168.2.23
                                                Jan 19, 2025 04:57:51.606759071 CET5438813566192.168.2.2383.222.225.136
                                                Jan 19, 2025 04:57:51.609049082 CET135665828683.222.67.15192.168.2.23
                                                Jan 19, 2025 04:57:51.609128952 CET5828613566192.168.2.2383.222.67.15
                                                Jan 19, 2025 04:57:51.610675097 CET135664367483.222.19.92192.168.2.23
                                                Jan 19, 2025 04:57:51.610750914 CET4367413566192.168.2.2383.222.19.92
                                                Jan 19, 2025 04:57:51.640834093 CET4367413566192.168.2.2383.222.19.92
                                                Jan 19, 2025 04:57:51.642973900 CET3584213566192.168.2.2383.222.221.110
                                                Jan 19, 2025 04:57:51.645802021 CET135664367483.222.19.92192.168.2.23
                                                Jan 19, 2025 04:57:51.645860910 CET4367413566192.168.2.2383.222.19.92
                                                Jan 19, 2025 04:57:51.646502972 CET5140813566192.168.2.2383.222.117.102
                                                Jan 19, 2025 04:57:51.648047924 CET135663584283.222.221.110192.168.2.23
                                                Jan 19, 2025 04:57:51.648273945 CET3584213566192.168.2.2383.222.221.110
                                                Jan 19, 2025 04:57:51.648432970 CET3284013566192.168.2.2383.222.218.61
                                                Jan 19, 2025 04:57:51.651397943 CET135665140883.222.117.102192.168.2.23
                                                Jan 19, 2025 04:57:51.651447058 CET5140813566192.168.2.2383.222.117.102
                                                Jan 19, 2025 04:57:51.653203011 CET135663284083.222.218.61192.168.2.23
                                                Jan 19, 2025 04:57:51.653264046 CET3284013566192.168.2.2383.222.218.61
                                                Jan 19, 2025 04:57:51.653264046 CET6061213566192.168.2.2383.222.135.19
                                                Jan 19, 2025 04:57:51.657252073 CET4415613566192.168.2.2383.222.40.66
                                                Jan 19, 2025 04:57:51.658174038 CET135666061283.222.135.19192.168.2.23
                                                Jan 19, 2025 04:57:51.658334017 CET6061213566192.168.2.2383.222.135.19
                                                Jan 19, 2025 04:57:51.660785913 CET3730813566192.168.2.2383.222.104.31
                                                Jan 19, 2025 04:57:51.662250042 CET135664415683.222.40.66192.168.2.23
                                                Jan 19, 2025 04:57:51.662292004 CET4415613566192.168.2.2383.222.40.66
                                                Jan 19, 2025 04:57:51.663398981 CET6002013566192.168.2.2383.222.75.157
                                                Jan 19, 2025 04:57:51.665735006 CET135663730883.222.104.31192.168.2.23
                                                Jan 19, 2025 04:57:51.665776968 CET3730813566192.168.2.2383.222.104.31
                                                Jan 19, 2025 04:57:51.666665077 CET5076813566192.168.2.2383.222.226.166
                                                Jan 19, 2025 04:57:51.668242931 CET135666002083.222.75.157192.168.2.23
                                                Jan 19, 2025 04:57:51.668279886 CET6002013566192.168.2.2383.222.75.157
                                                Jan 19, 2025 04:57:51.669536114 CET5580613566192.168.2.2383.222.95.169
                                                Jan 19, 2025 04:57:51.671513081 CET135665076883.222.226.166192.168.2.23
                                                Jan 19, 2025 04:57:51.671571970 CET5076813566192.168.2.2383.222.226.166
                                                Jan 19, 2025 04:57:51.672563076 CET3434813566192.168.2.2383.222.217.172
                                                Jan 19, 2025 04:57:51.674562931 CET135665580683.222.95.169192.168.2.23
                                                Jan 19, 2025 04:57:51.674617052 CET5580613566192.168.2.2383.222.95.169
                                                Jan 19, 2025 04:57:51.676215887 CET4884813566192.168.2.2383.222.102.164
                                                Jan 19, 2025 04:57:51.677650928 CET135663434883.222.217.172192.168.2.23
                                                Jan 19, 2025 04:57:51.677687883 CET3434813566192.168.2.2383.222.217.172
                                                Jan 19, 2025 04:57:51.679284096 CET4916413566192.168.2.2383.222.9.75
                                                Jan 19, 2025 04:57:51.681250095 CET5382413566192.168.2.2383.222.73.234
                                                Jan 19, 2025 04:57:51.681309938 CET135664884883.222.102.164192.168.2.23
                                                Jan 19, 2025 04:57:51.681380987 CET4884813566192.168.2.2383.222.102.164
                                                Jan 19, 2025 04:57:51.684343100 CET135664916483.222.9.75192.168.2.23
                                                Jan 19, 2025 04:57:51.684526920 CET4916413566192.168.2.2383.222.9.75
                                                Jan 19, 2025 04:57:51.686126947 CET135665382483.222.73.234192.168.2.23
                                                Jan 19, 2025 04:57:51.686177015 CET5382413566192.168.2.2383.222.73.234
                                                Jan 19, 2025 04:57:51.687558889 CET5096413566192.168.2.2383.222.211.141
                                                Jan 19, 2025 04:57:51.690341949 CET4173413566192.168.2.2383.222.249.231
                                                Jan 19, 2025 04:57:51.691307068 CET5205413566192.168.2.2383.222.233.214
                                                Jan 19, 2025 04:57:51.692648888 CET135665096483.222.211.141192.168.2.23
                                                Jan 19, 2025 04:57:51.692821026 CET5096413566192.168.2.2383.222.211.141
                                                Jan 19, 2025 04:57:51.695383072 CET135664173483.222.249.231192.168.2.23
                                                Jan 19, 2025 04:57:51.695621014 CET4173413566192.168.2.2383.222.249.231
                                                Jan 19, 2025 04:57:51.696224928 CET135665205483.222.233.214192.168.2.23
                                                Jan 19, 2025 04:57:51.696275949 CET5205413566192.168.2.2383.222.233.214
                                                Jan 19, 2025 04:57:51.708776951 CET5205413566192.168.2.2383.222.233.214
                                                Jan 19, 2025 04:57:51.709131002 CET5862413566192.168.2.2383.222.85.94
                                                Jan 19, 2025 04:57:51.710011005 CET4405813566192.168.2.2383.222.61.47
                                                Jan 19, 2025 04:57:51.713802099 CET135665205483.222.233.214192.168.2.23
                                                Jan 19, 2025 04:57:51.713865042 CET5205413566192.168.2.2383.222.233.214
                                                Jan 19, 2025 04:57:51.714134932 CET135665862483.222.85.94192.168.2.23
                                                Jan 19, 2025 04:57:51.714175940 CET5862413566192.168.2.2383.222.85.94
                                                Jan 19, 2025 04:57:51.714864016 CET135664405883.222.61.47192.168.2.23
                                                Jan 19, 2025 04:57:51.714915037 CET4405813566192.168.2.2383.222.61.47
                                                Jan 19, 2025 04:57:51.726041079 CET4405813566192.168.2.2383.222.61.47
                                                Jan 19, 2025 04:57:51.726516962 CET5232413566192.168.2.2383.222.156.196
                                                Jan 19, 2025 04:57:51.727291107 CET4781613566192.168.2.2383.222.66.196
                                                Jan 19, 2025 04:57:51.730901957 CET135664405883.222.61.47192.168.2.23
                                                Jan 19, 2025 04:57:51.730956078 CET4405813566192.168.2.2383.222.61.47
                                                Jan 19, 2025 04:57:51.731451035 CET135665232483.222.156.196192.168.2.23
                                                Jan 19, 2025 04:57:51.731523037 CET5232413566192.168.2.2383.222.156.196
                                                Jan 19, 2025 04:57:51.732176065 CET135664781683.222.66.196192.168.2.23
                                                Jan 19, 2025 04:57:51.732232094 CET4781613566192.168.2.2383.222.66.196
                                                Jan 19, 2025 04:57:51.759438038 CET4781613566192.168.2.2383.222.66.196
                                                Jan 19, 2025 04:57:51.760823011 CET4588813566192.168.2.2383.222.6.171
                                                Jan 19, 2025 04:57:51.763686895 CET4901613566192.168.2.2383.222.228.82
                                                Jan 19, 2025 04:57:51.765769958 CET135664781683.222.66.196192.168.2.23
                                                Jan 19, 2025 04:57:51.765865088 CET3694213566192.168.2.2383.222.72.198
                                                Jan 19, 2025 04:57:51.765914917 CET4781613566192.168.2.2383.222.66.196
                                                Jan 19, 2025 04:57:51.766630888 CET5735213566192.168.2.2383.222.248.167
                                                Jan 19, 2025 04:57:51.767021894 CET135664588883.222.6.171192.168.2.23
                                                Jan 19, 2025 04:57:51.767070055 CET4588813566192.168.2.2383.222.6.171
                                                Jan 19, 2025 04:57:51.769854069 CET135664901683.222.228.82192.168.2.23
                                                Jan 19, 2025 04:57:51.770129919 CET4901613566192.168.2.2383.222.228.82
                                                Jan 19, 2025 04:57:51.771893978 CET135663694283.222.72.198192.168.2.23
                                                Jan 19, 2025 04:57:51.771944046 CET3694213566192.168.2.2383.222.72.198
                                                Jan 19, 2025 04:57:51.772577047 CET135665735283.222.248.167192.168.2.23
                                                Jan 19, 2025 04:57:51.772618055 CET5735213566192.168.2.2383.222.248.167
                                                Jan 19, 2025 04:57:51.787033081 CET4619813566192.168.2.2383.222.111.209
                                                Jan 19, 2025 04:57:51.792107105 CET6047813566192.168.2.2383.222.83.214
                                                Jan 19, 2025 04:57:51.792171955 CET135664619883.222.111.209192.168.2.23
                                                Jan 19, 2025 04:57:51.792365074 CET4619813566192.168.2.2383.222.111.209
                                                Jan 19, 2025 04:57:51.797189951 CET135666047883.222.83.214192.168.2.23
                                                Jan 19, 2025 04:57:51.797257900 CET6047813566192.168.2.2383.222.83.214
                                                Jan 19, 2025 04:57:51.807638884 CET4904813566192.168.2.2383.222.118.92
                                                Jan 19, 2025 04:57:51.811693907 CET5607013566192.168.2.2383.222.33.191
                                                Jan 19, 2025 04:57:51.812551975 CET135664904883.222.118.92192.168.2.23
                                                Jan 19, 2025 04:57:51.812727928 CET4904813566192.168.2.2383.222.118.92
                                                Jan 19, 2025 04:57:51.815280914 CET5873613566192.168.2.2383.222.70.245
                                                Jan 19, 2025 04:57:51.816760063 CET135665607083.222.33.191192.168.2.23
                                                Jan 19, 2025 04:57:51.816929102 CET5607013566192.168.2.2383.222.33.191
                                                Jan 19, 2025 04:57:51.818389893 CET5656013566192.168.2.2383.222.76.64
                                                Jan 19, 2025 04:57:51.819828987 CET5562613566192.168.2.2383.222.220.53
                                                Jan 19, 2025 04:57:51.820242882 CET135665873683.222.70.245192.168.2.23
                                                Jan 19, 2025 04:57:51.820292950 CET5873613566192.168.2.2383.222.70.245
                                                Jan 19, 2025 04:57:51.822772980 CET4599813566192.168.2.2383.222.22.49
                                                Jan 19, 2025 04:57:51.823263884 CET135665656083.222.76.64192.168.2.23
                                                Jan 19, 2025 04:57:51.823329926 CET5656013566192.168.2.2383.222.76.64
                                                Jan 19, 2025 04:57:51.824692965 CET135665562683.222.220.53192.168.2.23
                                                Jan 19, 2025 04:57:51.824747086 CET5562613566192.168.2.2383.222.220.53
                                                Jan 19, 2025 04:57:51.827156067 CET4787813566192.168.2.2383.222.148.83
                                                Jan 19, 2025 04:57:51.827575922 CET135664599883.222.22.49192.168.2.23
                                                Jan 19, 2025 04:57:51.827625036 CET4599813566192.168.2.2383.222.22.49
                                                Jan 19, 2025 04:57:51.831954002 CET135664787883.222.148.83192.168.2.23
                                                Jan 19, 2025 04:57:51.832005024 CET4787813566192.168.2.2383.222.148.83
                                                Jan 19, 2025 04:57:51.832808971 CET4216013566192.168.2.2383.222.97.48
                                                Jan 19, 2025 04:57:51.837600946 CET135664216083.222.97.48192.168.2.23
                                                Jan 19, 2025 04:57:51.837645054 CET4216013566192.168.2.2383.222.97.48
                                                Jan 19, 2025 04:57:51.840539932 CET4378013566192.168.2.2383.222.23.163
                                                Jan 19, 2025 04:57:51.845467091 CET135664378083.222.23.163192.168.2.23
                                                Jan 19, 2025 04:57:51.845505953 CET4378013566192.168.2.2383.222.23.163
                                                Jan 19, 2025 04:57:51.845566988 CET3724413566192.168.2.2383.222.244.30
                                                Jan 19, 2025 04:57:51.847254992 CET4047213566192.168.2.2383.222.78.216
                                                Jan 19, 2025 04:57:51.849143982 CET4757413566192.168.2.2383.222.112.150
                                                Jan 19, 2025 04:57:51.850408077 CET135663724483.222.244.30192.168.2.23
                                                Jan 19, 2025 04:57:51.850455999 CET3724413566192.168.2.2383.222.244.30
                                                Jan 19, 2025 04:57:51.850509882 CET3534813566192.168.2.2383.222.159.104
                                                Jan 19, 2025 04:57:51.851329088 CET5741413566192.168.2.2383.222.62.14
                                                Jan 19, 2025 04:57:51.852344036 CET135664047283.222.78.216192.168.2.23
                                                Jan 19, 2025 04:57:51.852394104 CET4047213566192.168.2.2383.222.78.216
                                                Jan 19, 2025 04:57:51.852394104 CET5302413566192.168.2.2383.222.58.145
                                                Jan 19, 2025 04:57:51.853951931 CET135664757483.222.112.150192.168.2.23
                                                Jan 19, 2025 04:57:51.854015112 CET4757413566192.168.2.2383.222.112.150
                                                Jan 19, 2025 04:57:51.855427027 CET135663534883.222.159.104192.168.2.23
                                                Jan 19, 2025 04:57:51.855674982 CET3534813566192.168.2.2383.222.159.104
                                                Jan 19, 2025 04:57:51.855885029 CET4277413566192.168.2.2383.222.228.176
                                                Jan 19, 2025 04:57:51.856149912 CET135665741483.222.62.14192.168.2.23
                                                Jan 19, 2025 04:57:51.856189966 CET5741413566192.168.2.2383.222.62.14
                                                Jan 19, 2025 04:57:51.857295036 CET135665302483.222.58.145192.168.2.23
                                                Jan 19, 2025 04:57:51.857462883 CET5302413566192.168.2.2383.222.58.145
                                                Jan 19, 2025 04:57:51.857702971 CET3690213566192.168.2.2383.222.238.6
                                                Jan 19, 2025 04:57:51.859772921 CET3430413566192.168.2.2383.222.111.52
                                                Jan 19, 2025 04:57:51.860761881 CET135664277483.222.228.176192.168.2.23
                                                Jan 19, 2025 04:57:51.860799074 CET4277413566192.168.2.2383.222.228.176
                                                Jan 19, 2025 04:57:51.861659050 CET4611413566192.168.2.2383.222.251.188
                                                Jan 19, 2025 04:57:51.862600088 CET135663690283.222.238.6192.168.2.23
                                                Jan 19, 2025 04:57:51.862751007 CET3690213566192.168.2.2383.222.238.6
                                                Jan 19, 2025 04:57:51.863694906 CET5452813566192.168.2.2383.222.116.215
                                                Jan 19, 2025 04:57:51.864625931 CET135663430483.222.111.52192.168.2.23
                                                Jan 19, 2025 04:57:51.864669085 CET3430413566192.168.2.2383.222.111.52
                                                Jan 19, 2025 04:57:51.865641117 CET3736013566192.168.2.2383.222.241.139
                                                Jan 19, 2025 04:57:51.866565943 CET135664611483.222.251.188192.168.2.23
                                                Jan 19, 2025 04:57:51.866740942 CET4611413566192.168.2.2383.222.251.188
                                                Jan 19, 2025 04:57:51.867615938 CET5702213566192.168.2.2383.222.8.133
                                                Jan 19, 2025 04:57:51.868529081 CET135665452883.222.116.215192.168.2.23
                                                Jan 19, 2025 04:57:51.868565083 CET5452813566192.168.2.2383.222.116.215
                                                Jan 19, 2025 04:57:51.869018078 CET3852613566192.168.2.2383.222.222.105
                                                Jan 19, 2025 04:57:51.870507002 CET3356413566192.168.2.2383.222.181.246
                                                Jan 19, 2025 04:57:51.870534897 CET135663736083.222.241.139192.168.2.23
                                                Jan 19, 2025 04:57:51.870599031 CET3736013566192.168.2.2383.222.241.139
                                                Jan 19, 2025 04:57:51.872438908 CET135665702283.222.8.133192.168.2.23
                                                Jan 19, 2025 04:57:51.872490883 CET5702213566192.168.2.2383.222.8.133
                                                Jan 19, 2025 04:57:51.873166084 CET3963813566192.168.2.2383.222.13.170
                                                Jan 19, 2025 04:57:51.873931885 CET135663852683.222.222.105192.168.2.23
                                                Jan 19, 2025 04:57:51.874118090 CET3852613566192.168.2.2383.222.222.105
                                                Jan 19, 2025 04:57:51.875302076 CET135663356483.222.181.246192.168.2.23
                                                Jan 19, 2025 04:57:51.875350952 CET3356413566192.168.2.2383.222.181.246
                                                Jan 19, 2025 04:57:51.875611067 CET4218813566192.168.2.2383.222.20.91
                                                Jan 19, 2025 04:57:51.878007889 CET135663963883.222.13.170192.168.2.23
                                                Jan 19, 2025 04:57:51.878066063 CET3963813566192.168.2.2383.222.13.170
                                                Jan 19, 2025 04:57:51.878552914 CET5589013566192.168.2.2383.222.130.132
                                                Jan 19, 2025 04:57:51.880417109 CET135664218883.222.20.91192.168.2.23
                                                Jan 19, 2025 04:57:51.880456924 CET4218813566192.168.2.2383.222.20.91
                                                Jan 19, 2025 04:57:51.881426096 CET6031413566192.168.2.2383.222.242.33
                                                Jan 19, 2025 04:57:51.883394003 CET135665589083.222.130.132192.168.2.23
                                                Jan 19, 2025 04:57:51.883900881 CET5589013566192.168.2.2383.222.130.132
                                                Jan 19, 2025 04:57:51.886394024 CET135666031483.222.242.33192.168.2.23
                                                Jan 19, 2025 04:57:51.886440039 CET6031413566192.168.2.2383.222.242.33
                                                Jan 19, 2025 04:57:51.897608995 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:57:51.902553082 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:57:51.902667046 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:57:51.905420065 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:57:51.910274029 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:57:51.910343885 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:57:51.915307045 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:57:56.774852991 CET42836443192.168.2.2391.189.91.43
                                                Jan 19, 2025 04:57:57.798624992 CET4251680192.168.2.23109.202.202.202
                                                Jan 19, 2025 04:58:01.914154053 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:58:01.919394970 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:58:02.128716946 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:58:02.128967047 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:58:02.484690905 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:58:02.485003948 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:58:11.876635075 CET43928443192.168.2.2391.189.91.42
                                                Jan 19, 2025 04:58:24.162866116 CET42836443192.168.2.2391.189.91.43
                                                Jan 19, 2025 04:58:28.258505106 CET4251680192.168.2.23109.202.202.202
                                                Jan 19, 2025 04:58:52.831103086 CET43928443192.168.2.2391.189.91.42
                                                Jan 19, 2025 04:59:02.513159037 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:59:02.518238068 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:59:02.716372013 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:59:02.716583967 CET4265813566192.168.2.2383.222.191.90
                                                Jan 19, 2025 04:59:03.484093904 CET135664265883.222.191.90192.168.2.23
                                                Jan 19, 2025 04:59:03.484272957 CET4265813566192.168.2.2383.222.191.90
                                                TimestampSource PortDest PortSource IPDest IP
                                                Jan 19, 2025 04:57:51.886432886 CET3787553192.168.2.238.8.8.8
                                                Jan 19, 2025 04:57:51.895147085 CET53378758.8.8.8192.168.2.23
                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                Jan 19, 2025 04:57:51.886432886 CET192.168.2.238.8.8.80x3fb5Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                Jan 19, 2025 04:57:51.895147085 CET8.8.8.8192.168.2.230x3fb5No error (0)secure-network-rebirthltd.ru83.222.191.90A (IP address)IN (0x0001)false

                                                System Behavior

                                                Start time (UTC):03:57:50
                                                Start date (UTC):19/01/2025
                                                Path:/tmp/Kloki.mpsl.elf
                                                Arguments:/tmp/Kloki.mpsl.elf
                                                File size:5773336 bytes
                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                Start time (UTC):03:57:50
                                                Start date (UTC):19/01/2025
                                                Path:/tmp/Kloki.mpsl.elf
                                                Arguments:-
                                                File size:5773336 bytes
                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                Start time (UTC):03:57:50
                                                Start date (UTC):19/01/2025
                                                Path:/tmp/Kloki.mpsl.elf
                                                Arguments:-
                                                File size:5773336 bytes
                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                Start time (UTC):03:57:50
                                                Start date (UTC):19/01/2025
                                                Path:/tmp/Kloki.mpsl.elf
                                                Arguments:-
                                                File size:5773336 bytes
                                                MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-sharing
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/bin/gnome-shell
                                                Arguments:/usr/bin/gnome-shell
                                                File size:23168 bytes
                                                MD5 hash:da7a257239677622fe4b3a65972c9e87

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/libexec/gsd-print-notifications
                                                Arguments:/usr/libexec/gsd-print-notifications
                                                File size:51840 bytes
                                                MD5 hash:71539698aa691718cee775d6b9450ae2

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/libexec/gsd-rfkill
                                                Arguments:/usr/libexec/gsd-rfkill
                                                File size:51808 bytes
                                                MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/sbin/gdm3
                                                Arguments:-
                                                File size:453296 bytes
                                                MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/etc/gdm3/PrimeOff/Default
                                                Arguments:/etc/gdm3/PrimeOff/Default
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/usr/sbin/gdm3
                                                Arguments:-
                                                File size:453296 bytes
                                                MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                                                Start time (UTC):03:57:51
                                                Start date (UTC):19/01/2025
                                                Path:/etc/gdm3/PrimeOff/Default
                                                Arguments:/etc/gdm3/PrimeOff/Default
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c