Loading ...

Play interactive tourEdit tour

Linux Analysis Report d8dgn3wGJL

Overview

General Information

Sample Name:d8dgn3wGJL
Analysis ID:452442
MD5:7c8ff25ee476a1cd89bbf529e0ac6af4
SHA1:71e15a4c42d920302925c7d5ba05ca9f0c27a998
SHA256:fcafcefe3e66e811cdf3362820d2a7a6f6ae6005374b535357bad4ff349fd4ec
Tags:32elfmiraisparc
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Uses known network protocols on non-standard ports
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:452442
Start date:22.07.2021
Start time:11:13:15
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 41s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:d8dgn3wGJL
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 59.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
Analysis Mode:default
Detection:MAL
Classification:mal60.troj.lin@0/0@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu1
  • d8dgn3wGJL (PID: 4577, Parent: 4498, MD5: 7c8ff25ee476a1cd89bbf529e0ac6af4) Arguments: /usr/bin/qemu-sparc /tmp/d8dgn3wGJL
  • cleanup

Yara Overview

No yara matches

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: d8dgn3wGJLVirustotal: Detection: 52%Perma Link

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.149.119.210: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.217.150.42: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.171.69: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 89.247.122.202: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 77.93.207.241: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.226.91.226: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 62.143.81.19: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.93.123.213: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.200.163.54: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 174.80.250.104: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.94.210.121: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 71.93.5.131: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 154.93.12.45: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 124.156.224.152: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 58.84.7.159: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.122.254.223: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.125.209: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.12.198.131: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 212.114.226.172: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.105.4.164: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 62.11.163.126: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 212.41.32.46: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 68.149.236.158: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 156.227.232.74: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.157.128.213: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.141.64.89: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.113.161: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.144.146.49: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 50.242.148.249: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.81.151.59: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 109.192.60.227: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.133.118.250: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.74.191.190: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.146.155.170: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 89.166.216.95: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.80.250.78: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.135.119.68: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 47.229.222.43: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.6.30.5: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.195.240.54: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 23.231.80.162: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 27.29.140.221: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 218.97.37.50: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.97.24.113: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.12.217.155: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.74.42.184: -> 192.168.2.20:
Source: TrafficSnort IDS: 716 INFO TELNET access 75.227.207.59:23 -> 192.168.2.20:45260
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 153.120.21.35: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 62.224.216.198: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.151.127.216: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 160.121.107.54: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.53.189.144: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.69.105.153: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 78.55.27.168: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 184.164.65.248: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 107.10.249.140: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 150.95.47.224: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.78.248.43: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.253.169.106: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.194.133.140: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 5.183.225.209: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.249.71.25: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.216.40.233: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.78.97.142: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 212.73.64.17: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.163.109.24: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.47.20.151: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.207.133.219: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 135.148.4.214: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.82.111.241: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.255.161.83: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 18.144.83.161: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.221.103.176: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 72.130.39.76: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.118.176.60: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 72.52.55.214: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.6.124.180: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 81.95.2.194: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.213.197: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 65.51.177.222: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.56.14.98: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.195.137.51: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.33.155.13: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 31.18.214.37: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.220.194.175: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.156.248.170: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.135.213.70: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.189.141.182: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 5.8.126.213: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.132.46.138: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 4.53.160.210: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 23.28.89.40: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 50.220.200.185: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.71.79.226: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.75.17.147: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.9.191.152: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.130.161.75: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 121.5.175.241: -> 192.168.2.20:
Source: TrafficSnort IDS: 716 INFO TELNET access 222.187.46.27:23 -> 192.168.2.20:60006
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.174.41.54: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 45.149.0.193: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.104.174.184: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.156.206.75: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 156.234.1.198: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.73.148.255: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 73.150.160.68: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 164.106.225.17: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 78.35.100.246: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 83.160.66.100: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.59.214.37: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 185.102.75.137: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.51.53.86: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.10.4.32: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 85.29.131.179: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 176.53.159.124: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 89.56.244.162: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.221.164.230: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.171.89: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 1.234.41.69: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.187.33: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 158.43.20.246: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.183.249.98: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.211.25.72: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.153.62.221: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 176.119.33.28: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.83.176.57: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 75.64.225.7: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.111.109: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.156.46.175: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.101.46.224: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.127.145: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.94.92.129: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 37.201.150.216: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.188.13: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.1.105.180: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.75.119.231: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.95.115.34: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 203.218.44.111: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.4.218.157: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.172.248.10: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.133.6.158: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.102.194.18: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 189.90.240.5: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.223.196.5: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.245.10.246: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.136.94.162: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.11.240.179: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.69.214.233: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 61.213.90.151: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.204.99.251: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.128.47.70: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.247.61.41: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.77.240.189: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 104.232.138.116: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.171.180.78: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.150.196.172: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.93.83.188: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.142.212.167: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 73.157.93.164: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.103.216.14: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.151.106: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.16.241.168: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 65.19.78.5: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 83.162.201.175: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.41.242.192: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 149.172.24.18: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.216.240.126: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.220.20.226: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 156.251.132.34: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 156.251.133.58: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.92.112.86: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.72.11.195: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.77.64.1: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.202.238.220: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 65.199.0.219: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 91.235.136.87: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.213.54.128: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.97.23.35: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 160.16.149.40: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.201.125.40: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.6.159.228: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 89.252.188.73: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 78.152.56.101: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.209.255.222: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 72.76.192.206: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 85.10.0.139: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 86.66.74.166: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.179.68.223: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.3.57.111: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.96.179.123: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 32.141.71.90: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.188.205.37: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.213.61.19: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.139.255.38: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 65.79.152.90: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.54.120.139: -> 192.168.2.20:
Source: TrafficSnort IDS: 716 INFO TELNET access 83.68.16.199:23 -> 192.168.2.20:44360
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.135.122.90: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 185.9.42.169: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 69.51.31.199: -> 192.168.2.20:
Source: TrafficSnort IDS: 716 INFO TELNET access 121.127.90.145:23 -> 192.168.2.20:48594
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.196.181.239: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 173.10.70.2: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 32.114.112.26: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 119.28.161.253: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.62.166.246: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 95.114.68.119: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.154.247.82: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.210.1.21: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.10.101.4: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 73.222.150.31: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 172.22.5.1: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.210.27.80: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.219.3.173: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 45.207.240.124: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 104.165.197.126: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 41.182.18.31: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.232.160.39: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.22.102.132: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.122.92.166: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 122.254.113.70: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 62.115.178.173: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 194.102.118.249: -> 192.168.2.20:
Source: TrafficSnort IDS: 716 INFO TELNET access 59.158.46.180:23 -> 192.168.2.20:44532
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.205.47.196: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.75.172.40: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.53.106.103: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 195.21.45.138: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.172.81.159: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.12.144.74: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.217.87.115: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.173.75.25: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 31.17.220.28: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.116.255.95: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 89.14.78.24: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.214.64.254: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.9.83.117: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 149.87.185.53: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 161.8.23.60: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 172.80.33.170: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.199.107.161: -> 192.168.2.20:
Source: TrafficSnort IDS: 716 INFO TELNET access 14.52.113.254:23 -> 192.168.2.20:49058
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.246.154.113: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.9.3.15: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 90.153.89.187: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 193.234.156.83: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 212.86.54.131: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.201.167.244: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.253.28.30: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.195.145.248: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 40.134.62.141: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 63.241.135.121: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.54.146.207: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 10.201.61.246: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.61.56.65: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.214.182.74: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 50.233.211.194: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 37.228.166.230: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 192.3.221.15: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.155.185.196: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 77.220.252.22: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.71.153.91: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 90.186.8.76: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 31.19.243.17: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.244.187.227: -> 192.168.2.20:
Source: TrafficSnort IDS: 716 INFO TELNET access 177.135.108.1:23 -> 192.168.2.20:55136
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.76.33.6: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.130.66: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.46.228.99: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.251.65.120: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.142.59.38: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.150.125.155: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.216.104.31: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.171.25.176: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.201.131.6: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.13.24.92: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 154.214.16.94: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 83.162.159.126: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.220.85.55: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.158.231.238: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 119.254.62.124: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.87.171.53: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.98.224.69: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.212.209.112: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.212.200.250: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 176.95.180.234: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.33.49.6: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.22.6.128: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.222.109.36: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 156.232.35.54: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 103.3.189.199: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 168.199.54.26: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.73.81.97: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.246.171.232: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 79.110.188.129: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 128.136.244.70: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 95.222.183.71: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 109.91.143.249: -> 192.168.2.20:
Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 31.150.25.148: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 136.0.240.121: -> 192.168.2.20:
Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 104.149.17.73: -> 192.168.2.20:
Uses known network protocols on non-standard portsShow sources
Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39270
Source: global trafficTCP traffic: 192.168.2.20:35686 -> 37.230.137.227:1312
Source: unknownTCP traffic detected without corresponding DNS query: 37.230.137.227
Source: unknownTCP traffic detected without corresponding DNS query: 180.130.46.34
Source: unknownTCP traffic detected without corresponding DNS query: 105.236.132.34
Source: unknownTCP traffic detected without corresponding DNS query: 92.234.236.52
Source: unknownTCP traffic detected without corresponding DNS query: 212.164.101.30
Source: unknownTCP traffic detected without corresponding DNS query: 18.77.169.252
Source: unknownTCP traffic detected without corresponding DNS query: 147.97.26.63
Source: unknownTCP traffic detected without corresponding DNS query: 53.197.153.131
Source: unknownTCP traffic detected without corresponding DNS query: 201.84.142.86
Source: unknownTCP traffic detected without corresponding DNS query: 109.195.99.194
Source: unknownTCP traffic detected without corresponding DNS query: 188.32.88.90
Source: unknownTCP traffic detected without corresponding DNS query: 112.35.99.249
Source: unknownTCP traffic detected without corresponding DNS query: 158.172.106.31
Source: unknownTCP traffic detected without corresponding DNS query: 192.195.79.108
Source: unknownTCP traffic detected without corresponding DNS query: 188.23.44.229
Source: unknownTCP traffic detected without corresponding DNS query: 31.136.105.138
Source: unknownTCP traffic detected without corresponding DNS query: 183.190.202.216
Source: unknownTCP traffic detected without corresponding DNS query: 166.15.179.195
Source: unknownTCP traffic detected without corresponding DNS query: 194.240.107.221
Source: unknownTCP traffic detected without corresponding DNS query: 101.143.149.34
Source: unknownTCP traffic detected without corresponding DNS query: 219.11.157.6
Source: unknownTCP traffic detected without corresponding DNS query: 198.146.131.193
Source: unknownTCP traffic detected without corresponding DNS query: 223.124.4.251
Source: unknownTCP traffic detected without corresponding DNS query: 166.8.0.125
Source: unknownTCP traffic detected without corresponding DNS query: 101.249.202.153
Source: unknownTCP traffic detected without corresponding DNS query: 157.255.7.1
Source: unknownTCP traffic detected without corresponding DNS query: 220.251.220.39
Source: unknownTCP traffic detected without corresponding DNS query: 36.69.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 200.112.47.141
Source: unknownTCP traffic detected without corresponding DNS query: 46.113.34.200
Source: unknownTCP traffic detected without corresponding DNS query: 78.236.158.44
Source: unknownTCP traffic detected without corresponding DNS query: 27.53.243.194
Source: unknownTCP traffic detected without corresponding DNS query: 93.84.215.82
Source: unknownTCP traffic detected without corresponding DNS query: 255.91.13.229
Source: unknownTCP traffic detected without corresponding DNS query: 109.233.55.61
Source: unknownTCP traffic detected without corresponding DNS query: 17.175.65.191
Source: unknownTCP traffic detected without corresponding DNS query: 161.42.0.250
Source: unknownTCP traffic detected without corresponding DNS query: 24.56.58.134
Source: unknownTCP traffic detected without corresponding DNS query: 170.9.38.57
Source: unknownTCP traffic detected without corresponding DNS query: 120.102.96.94
Source: unknownTCP traffic detected without corresponding DNS query: 114.89.56.214
Source: unknownTCP traffic detected without corresponding DNS query: 103.179.83.227
Source: unknownTCP traffic detected without corresponding DNS query: 178.25.145.67
Source: unknownTCP traffic detected without corresponding DNS query: 74.150.165.252
Source: unknownTCP traffic detected without corresponding DNS query: 12.113.97.251
Source: unknownTCP traffic detected without corresponding DNS query: 195.47.85.209
Source: unknownTCP traffic detected without corresponding DNS query: 217.49.133.15
Source: unknownTCP traffic detected without corresponding DNS query: 31.80.111.48
Source: unknownTCP traffic detected without corresponding DNS query: 240.85.153.239
Source: unknownTCP traffic detected without corresponding DNS query: 116.50.227.1
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.lin@0/0@0/0
Source: submitted sampleStderr: pc: 0001daa8 npc: 0001daac%g0-7: 00000000 00000018 00000000 00000001 000306bc 00000000 00000070 00000000%o0-7: 000306b7 f6ffad53 00000400 0000002c 0001c170 00000000 f6fface0 0001cab4 %l0-7: f6ffad40 f6ffad40 00000000 00000001 000003f0 00000004 00000000 00000000 %i0-7: 000306a4 000306a4 00000400 0000003c 0001c160 00000000 f6ffb148 0001d958 %f00: 0000000000000000 0000000000000000 0000000000000000 0000000000000000%f08: 0000000000000000 0000000000000000 0000000000000000 0000000000000000%f16: 0000000000000000 0000000000000000 0000000000000000 0000000000000000%f24: 0000000000000000 0000000000000000 0000000000000000 0000000000000000psr: 04900001 (icc: N--C SPE: ---) wim: 00000001fsr: 00000000 y: 00000000: exit code = 0

Hooking and other Techniques for Hiding and Protection:

barindex
Uses known network protocols on non-standard portsShow sources
Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39270
Source: /tmp/d8dgn3wGJL (PID: 4577)Queries kernel information via 'uname':

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumNon-Standard Port11Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition

Malware Configuration

No configs have been found

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 452442 Sample: d8dgn3wGJL Startdate: 22/07/2021 Architecture: LINUX Score: 60 22 217.244.187.227 DTAGInternetserviceprovideroperationsDE Germany 2->22 24 5.17.148.25, 23 ZTELECOM-ASRU Russian Federation 2->24 26 98 other IPs or domains 2->26 28 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Uses known network protocols on non-standard ports 2->32 8 d8dgn3wGJL 2->8         started        signatures3 process4 process5 10 d8dgn3wGJL 8->10         started        12 d8dgn3wGJL 8->12         started        14 d8dgn3wGJL 8->14         started        process6 16 d8dgn3wGJL 10->16         started        18 d8dgn3wGJL 10->18         started        20 d8dgn3wGJL 10->20         started       

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
d8dgn3wGJL52%VirustotalBrowse

Dropped Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

Contacted IPs

  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Public

IPDomainCountryFlagASNASN NameMalicious
96.80.119.73
unknownUnited States
7922COMCAST-7922USfalse
110.220.205.165
unknownChina
9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
186.8.103.81
unknownUruguay
19422TelefonicaMovilesdelUruguaySAUYfalse
9.151.73.175
unknownUnited States
3356LEVEL3USfalse
244.41.150.76
unknownReserved
unknownunknownfalse
159.169.253.102
unknownUnited States
28686AVECTRIS-ASCHfalse
110.91.165.153
unknownChina
4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
100.138.149.140
unknownUnited States
21928T-MOBILE-AS21928USfalse
31.136.150.35
unknownNetherlands
15480VFNL-ASVodafoneNLAutonomousSystemNLfalse
172.188.114.229
unknownUnited States
7018ATT-INTERNET4USfalse
43.152.190.246
unknownJapan4249LILLY-ASUSfalse
173.97.209.95
unknownUnited States
1239SPRINTLINKUSfalse
170.70.84.141
unknownMexico
10420BancodeMexicoMXfalse
208.179.154.138
unknownUnited States
11509TIERZERO-AS11509USfalse
255.248.130.166
unknownReserved
unknownunknownfalse
59.23.230.78
unknownKorea Republic of
4766KIXS-AS-KRKoreaTelecomKRfalse
63.139.108.31
unknownUnited States
7029WINDSTREAMUSfalse
16.40.26.19
unknownUnited States
unknownunknownfalse
93.171.110.72
unknownCzech Republic
42772A1-BY-ASBYfalse
58.173.90.103
unknownAustralia
1221ASN-TELSTRATelstraCorporationLtdAUfalse
154.44.177.227
unknownUnited States
174COGENT-174USfalse
203.54.53.98
unknownAustralia
1221ASN-TELSTRATelstraCorporationLtdAUfalse
210.37.80.135
unknownChina
4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
162.128.14.245
unknownUnited States
14566AS14566USfalse
152.0.189.16
unknownDominican Republic
6400CompaniaDominicanadeTelefonosSADOfalse
91.102.26.204
unknownNorway
41741BBS-ASNOfalse
163.166.98.3
unknownUnited Kingdom
15914BritishAirwaysGBfalse
202.135.117.234
unknownJapan2687ATGS-MMD-ASUSfalse
62.23.12.103
unknownUnited Kingdom
8220COLTCOLTTechnologyServicesGroupLimitedGBfalse
70.210.119.248
unknownUnited States
6167CELLCO-PARTUSfalse
208.41.125.41
unknownUnited States
4565MEGAPATH2-USfalse
202.146.43.79
unknownIndonesia
38754PRIMENET-AS-IDPRIMEDIAARMOEKADATAINTERNETPTIDfalse
195.225.82.230
unknownunknown
25148BASEFARM-ASNOslo-NorwayNOfalse
96.161.248.210
unknownUnited States
7922COMCAST-7922USfalse
106.79.68.135
unknownIndia
45271ICLNET-AS-APIdeaCellularLimitedINfalse
109.2.36.81
unknownFrance
15557LDCOMNETFRfalse
251.25.165.77
unknownReserved
unknownunknownfalse
193.116.228.182
unknownAustralia
7545TPG-INTERNET-APTPGTelecomLimitedAUfalse
74.52.27.62
unknownUnited States
36351SOFTLAYERUSfalse
191.103.96.36
unknownArgentina
262932COMPANIADECIRCUITOSCERRADOSSAARfalse
9.66.92.155
unknownUnited States
3356LEVEL3USfalse
147.171.5.176
unknownFrance
1942FR-TIGREToileInformatiqueGREnobloiseEUfalse
108.66.209.194
unknownUnited States
7018ATT-INTERNET4USfalse
39.1.255.121
unknownTaiwan; Republic of China (ROC)
18182SONET-TWSonyNetworkTaiwanLimitedTWfalse
60.101.227.11
unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
74.140.211.184
unknownUnited States
10796TWC-10796-MIDWESTUSfalse
149.147.37.110
unknownKuwait
42961GPRS-ASZAINKWfalse
71.94.21.166
unknownUnited States
20115CHARTER-20115USfalse
217.244.187.227
unknownGermany
3320DTAGInternetserviceprovideroperationsDEtrue
158.193.29.18
unknownSlovakia (SLOVAK Republic)
2607SANETSlovakAcademicNetworkSKfalse
177.201.129.228
unknownBrazil
8167BrasilTelecomSA-FilialDistritoFederalBRfalse
79.66.22.135
unknownUnited Kingdom
9105TISCALI-UKTalkTalkCommunicationsLimitedGBfalse
94.213.158.119
unknownNetherlands
33915TNF-ASNLfalse
73.75.1.216
unknownUnited States
7922COMCAST-7922USfalse
47.225.65.210
unknownUnited States
20115CHARTER-20115USfalse
13.185.102.49
unknownUnited States
7018ATT-INTERNET4USfalse
39.151.168.116
unknownChina
24445CMNET-V4HENAN-AS-APHenanMobileCommunicationsCoLtdCNfalse
98.185.68.245
unknownUnited States
22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
14.231.69.168
unknownViet Nam
45899VNPT-AS-VNVNPTCorpVNfalse
65.136.64.248
unknownUnited States
209CENTURYLINK-US-LEGACY-QWESTUSfalse
67.135.133.193
unknownUnited States
23409AS-FOFCOSUSfalse
71.101.97.146
unknownUnited States
701UUNETUSfalse
121.62.40.189
unknownChina
4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
34.92.28.213
unknownUnited States
15169GOOGLEUSfalse
192.215.126.28
unknownUnited States
4266CERNET-ASN-BLOCKUSfalse
34.178.238.199
unknownUnited States
2686ATGS-MMD-ASUSfalse
168.252.211.92
unknownAustralia
7474OPTUSCOM-AS01-AUSingTelOptusPtyLtdAUfalse
247.40.238.252
unknownReserved
unknownunknownfalse
189.238.52.156
unknownMexico
8151UninetSAdeCVMXfalse
211.41.228.12
unknownKorea Republic of
9943KNCTV-ASKangNamCableTVKRfalse
85.190.130.159
unknownGermany
199610MARBISDEfalse
5.17.148.25
unknownRussian Federation
41733ZTELECOM-ASRUfalse
45.173.189.214
unknownBrazil
268886WILLYNETPROVEDORBRfalse
254.4.121.201
unknownReserved
unknownunknownfalse
74.123.239.183
unknownUnited States
17030PRIMERICA-17030USfalse
153.58.29.209
unknownUnited States
14962NCR-252USfalse
194.232.154.71
unknownAustria
5403AS5403ATfalse
13.178.149.151
unknownUnited States
7018ATT-INTERNET4USfalse
251.91.166.212
unknownReserved
unknownunknownfalse
122.9.23.116
unknownChina
4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
210.182.182.179
unknownKorea Republic of
3786LGDACOMLGDACOMCorporationKRfalse
58.231.59.184
unknownKorea Republic of
9318SKB-ASSKBroadbandCoLtdKRfalse
75.106.120.33
unknownUnited States
7155VIASAT-SP-BACKBONEUSfalse
175.252.45.55
unknownKorea Republic of
4766KIXS-AS-KRKoreaTelecomKRfalse
195.222.62.194
unknownBosnia and Herzegowina
9146BIHNETBIHNETAutonomusSystemBAfalse
181.242.187.203
unknownColombia
26611COMCELSACOfalse
36.69.14.93
unknownIndonesia
7713TELKOMNET-AS-APPTTelekomunikasiIndonesiaIDfalse
14.180.45.48
unknownViet Nam
45899VNPT-AS-VNVNPTCorpVNfalse
221.207.216.133
unknownChina
4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
145.87.165.122
unknownNetherlands
29396EUROFIBER-UNETEUROFIBERUNETNetworkNLfalse
152.77.92.14
unknownFrance
1942FR-TIGREToileInformatiqueGREnobloiseEUfalse
162.125.189.94
unknownUnited States
19679DROPBOXUSfalse
168.37.109.99
unknownUnited States
1761TDIR-CAPNETUSfalse
253.207.80.50
unknownReserved
unknownunknownfalse
67.66.161.97
unknownUnited States
7018ATT-INTERNET4USfalse
180.85.234.147
unknownChina
4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
73.229.102.52
unknownUnited States
7922COMCAST-7922USfalse
250.156.175.16
unknownReserved
unknownunknownfalse
198.247.229.28
unknownUnited States
2914NTT-COMMUNICATIONS-2914USfalse
152.124.52.200
unknownUnited States
29992VA-TMP-COREUSfalse


Runtime Messages

Command:/tmp/d8dgn3wGJL
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Connected To CNC
Unhandled trap: 0x7
Standard Error:pc: 0001daa8 npc: 0001daac
%g0-7: 00000000 00000018 00000000 00000001 000306bc 00000000 00000070 00000000
%o0-7: 000306b7 f6ffad53 00000400 0000002c 0001c170 00000000 f6fface0 0001cab4
%l0-7: f6ffad40 f6ffad40 00000000 00000001 000003f0 00000004 00000000 00000000
%i0-7: 000306a4 000306a4 00000400 0000003c 0001c160 00000000 f6ffb148 0001d958
%f00: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
%f08: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
%f16: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
%f24: 0000000000000000 0000000000000000 0000000000000000 0000000000000000
psr: 04900001 (icc: N--C SPE: ---) wim: 00000001
fsr: 00000000 y: 00000000

Joe Sandbox View / Context

IPs

No context

Domains

No context

ASN

MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
LEVEL3USsDwNKSpuhBGet hashmaliciousBrowse
  • 8.89.10.151
8ZJ0cPowTyGet hashmaliciousBrowse
  • 9.190.139.100
XuQRPW44hiGet hashmaliciousBrowse
  • 4.17.92.85
Taf5zLti30Get hashmaliciousBrowse
  • 63.213.20.124
5qpsqg7U0GGet hashmaliciousBrowse
  • 4.223.97.64
GEso3CniSkGet hashmaliciousBrowse
  • 4.67.189.0
U4r9W64doyGet hashmaliciousBrowse
  • 8.125.111.71
C4PozjQdGEGet hashmaliciousBrowse
  • 9.163.192.142
CefN2XNyFiGet hashmaliciousBrowse
  • 63.211.32.24
Qka3fi8NpLGet hashmaliciousBrowse
  • 4.85.160.229
c51w5YSYdOGet hashmaliciousBrowse
  • 9.18.53.156
Xr3hmBQcmwGet hashmaliciousBrowse
  • 4.176.67.159
xjYvqOne1tGet hashmaliciousBrowse
  • 4.225.49.79
rxfttQnoO5Get hashmaliciousBrowse
  • 209.84.172.192
sora.arm7Get hashmaliciousBrowse
  • 4.42.84.14
iUmNR6tkEdGet hashmaliciousBrowse
  • 4.9.157.144
LDWhPg4vRMGet hashmaliciousBrowse
  • 9.160.127.38
CGjf615z6vGet hashmaliciousBrowse
  • 9.245.2.66
u47x3rc20tGet hashmaliciousBrowse
  • 4.143.149.176
SvmxfeZM5ZGet hashmaliciousBrowse
  • 9.26.96.16
TelefonicaMovilesdelUruguaySAUYFN0ZF2Nm21Get hashmaliciousBrowse
  • 186.8.115.24
COMCAST-7922USs54l0GKMh9Get hashmaliciousBrowse
  • 24.131.135.95
D1dU3jQ1IIGet hashmaliciousBrowse
  • 73.221.68.185
sDwNKSpuhBGet hashmaliciousBrowse
  • 66.31.123.8
A7X93JRxhpGet hashmaliciousBrowse
  • 174.160.234.12
92CRMNlBq8Get hashmaliciousBrowse
  • 96.129.115.21
XuQRPW44hiGet hashmaliciousBrowse
  • 96.75.11.28
Taf5zLti30Get hashmaliciousBrowse
  • 73.105.22.60
5qpsqg7U0GGet hashmaliciousBrowse
  • 50.150.213.54
LyxN1ckWTWGet hashmaliciousBrowse
  • 73.76.173.103
VGi1EK6T17Get hashmaliciousBrowse
  • 96.193.32.170
U4r9W64doyGet hashmaliciousBrowse
  • 76.142.58.170
C4PozjQdGEGet hashmaliciousBrowse
  • 74.30.218.252
CefN2XNyFiGet hashmaliciousBrowse
  • 96.191.119.186
7OAzOUL9cdGet hashmaliciousBrowse
  • 67.184.88.190
MD5OxTSc6iGet hashmaliciousBrowse
  • 24.128.44.113
Qka3fi8NpLGet hashmaliciousBrowse
  • 74.156.139.185
Xr3hmBQcmwGet hashmaliciousBrowse
  • 96.80.132.77
xjYvqOne1tGet hashmaliciousBrowse
  • 73.136.89.242
SUpODCSauSGet hashmaliciousBrowse
  • 71.197.70.248
sora.arm7Get hashmaliciousBrowse
  • 98.245.173.86
CTTNETChinaTieTongTelecommunicationsCorporationCNsDwNKSpuhBGet hashmaliciousBrowse
  • 36.219.130.2
A7X93JRxhpGet hashmaliciousBrowse
  • 110.206.233.25
Taf5zLti30Get hashmaliciousBrowse
  • 123.87.164.15
5qpsqg7U0GGet hashmaliciousBrowse
  • 122.95.10.12
U5q75RGCmQGet hashmaliciousBrowse
  • 122.71.101.44
GEso3CniSkGet hashmaliciousBrowse
  • 222.45.77.49
BTNNG17tlhGet hashmaliciousBrowse
  • 122.71.101.71
U4r9W64doyGet hashmaliciousBrowse
  • 110.216.8.38
C4PozjQdGEGet hashmaliciousBrowse
  • 175.75.128.119
kb5IbEJU8cGet hashmaliciousBrowse
  • 110.59.218.218
7OAzOUL9cdGet hashmaliciousBrowse
  • 122.93.45.57
MD5OxTSc6iGet hashmaliciousBrowse
  • 110.123.21.115
Qka3fi8NpLGet hashmaliciousBrowse
  • 123.88.172.170
c51w5YSYdOGet hashmaliciousBrowse
  • 101.147.99.54
rxfttQnoO5Get hashmaliciousBrowse
  • 111.151.61.171
LDWhPg4vRMGet hashmaliciousBrowse
  • 101.150.83.171
CGjf615z6vGet hashmaliciousBrowse
  • 122.73.224.9
yZEHOt8K7XGet hashmaliciousBrowse
  • 111.151.185.213
ehn0f1d63MGet hashmaliciousBrowse
  • 101.155.119.242
qgQgEjI283Get hashmaliciousBrowse
  • 36.221.14.98

JA3 Fingerprints

No context

Dropped Files

No context

Created / dropped Files

No created / dropped files found

Static File Info

General

File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
Entropy (8bit):6.035606314487842
TrID:
  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
File name:d8dgn3wGJL
File size:60412
MD5:7c8ff25ee476a1cd89bbf529e0ac6af4
SHA1:71e15a4c42d920302925c7d5ba05ca9f0c27a998
SHA256:fcafcefe3e66e811cdf3362820d2a7a6f6ae6005374b535357bad4ff349fd4ec
SHA512:176111ad556af440f0031cb0e03d15c19a16e4169d2aafef86a4d50ebc4dab3df9a8ec23eb49807732a500d04738f9c125ff7440c2f7e350a5947474183ba117
SSDEEP:768:eLobAxU6q9Hfymp0xginuYvCkLB6WsTwIC1DQdszoDaS0O+DCDm:eL0AxvSHfymp0xgunvCkV6vTMDaul
File Content Preview:.ELF...........................4...l.....4. ...(.......................................................x............dt.Q................................@..(....@.8R................#.....b0..`.....!..... ...@.....".........`......$ ... ...@...........`....

Static ELF Info

ELF header

Class:ELF32
Data:2's complement, big endian
Version:1 (current)
Machine:Sparc
Version Number:0x1
Type:EXEC (Executable file)
OS/ABI:UNIX - System V
ABI Version:0
Entry Point Address:0x101a4
Flags:0x0
ELF Header Size:52
Program Header Offset:52
Program Header Size:32
Number of Program Headers:3
Section Header Offset:60012
Section Header Size:40
Number of Section Headers:10
Header String Table Index:9

Sections

NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
NULL0x00x00x00x00x0000
.initPROGBITS0x100940x940x1c0x00x6AX004
.textPROGBITS0x100b00xb00xe1800x00x6AX004
.finiPROGBITS0x1e2300xe2300x140x00x6AX004
.rodataPROGBITS0x1e2480xe2480x6680x00x2A008
.ctorsPROGBITS0x2e8b40xe8b40x80x00x3WA004
.dtorsPROGBITS0x2e8bc0xe8bc0x80x00x3WA004
.dataPROGBITS0x2e8c80xe8c80x1640x00x3WA008
.bssNOBITS0x2ea300xea2c0x2880x00x3WA008
.shstrtabSTRTAB0x00xea2c0x3e0x00x0001

Program Segments

TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
LOAD0x00x100000x100000xe8b00xe8b03.38830x5R E0x10000.init .text .fini .rodata
LOAD0xe8b40x2e8b40x2e8b40x1780x4040.31830x6RW 0x10000.ctors .dtors .data .bss
GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

Network Behavior

Network Port Distribution

TCP Packets

TimestampSource PortDest PortSource IPDest IP
Jul 22, 2021 11:13:50.767258883 CEST356861312192.168.2.2037.230.137.227
Jul 22, 2021 11:13:50.773401022 CEST2172423192.168.2.20180.130.46.34
Jul 22, 2021 11:13:50.773467064 CEST2172423192.168.2.20105.236.132.34
Jul 22, 2021 11:13:50.773492098 CEST2172423192.168.2.20110.194.80.32
Jul 22, 2021 11:13:50.773504019 CEST2172423192.168.2.2092.234.236.52
Jul 22, 2021 11:13:50.773514986 CEST2172423192.168.2.20212.164.101.30
Jul 22, 2021 11:13:50.773526907 CEST2172423192.168.2.20210.116.140.216
Jul 22, 2021 11:13:50.773540020 CEST2172423192.168.2.2018.77.169.252
Jul 22, 2021 11:13:50.773559093 CEST2172423192.168.2.20147.97.26.63
Jul 22, 2021 11:13:50.773575068 CEST2172423192.168.2.2053.197.153.131
Jul 22, 2021 11:13:50.773582935 CEST2172423192.168.2.20201.84.142.86
Jul 22, 2021 11:13:50.773587942 CEST2172423192.168.2.20109.195.99.194
Jul 22, 2021 11:13:50.773690939 CEST2172423192.168.2.20188.32.88.90
Jul 22, 2021 11:13:50.773689985 CEST2172423192.168.2.20112.35.99.249
Jul 22, 2021 11:13:50.773732901 CEST2172423192.168.2.20158.172.106.31
Jul 22, 2021 11:13:50.773803949 CEST2172423192.168.2.20192.195.79.108
Jul 22, 2021 11:13:50.773824930 CEST2172423192.168.2.20188.23.44.229
Jul 22, 2021 11:13:50.773843050 CEST2172423192.168.2.2031.136.105.138
Jul 22, 2021 11:13:50.773858070 CEST2172423192.168.2.20183.190.202.216
Jul 22, 2021 11:13:50.773864031 CEST2172423192.168.2.20166.15.179.195
Jul 22, 2021 11:13:50.773871899 CEST2172423192.168.2.20194.240.107.221
Jul 22, 2021 11:13:50.773878098 CEST2172423192.168.2.20101.143.149.34
Jul 22, 2021 11:13:50.773895025 CEST2172423192.168.2.20219.11.157.6
Jul 22, 2021 11:13:50.773910999 CEST2172423192.168.2.20198.146.131.193
Jul 22, 2021 11:13:50.773927927 CEST2172423192.168.2.20223.124.4.251
Jul 22, 2021 11:13:50.773982048 CEST2172423192.168.2.20166.8.0.125
Jul 22, 2021 11:13:50.773984909 CEST2172423192.168.2.20101.249.202.153
Jul 22, 2021 11:13:50.773998022 CEST2172423192.168.2.20157.255.7.1
Jul 22, 2021 11:13:50.774007082 CEST2172423192.168.2.20220.251.220.39
Jul 22, 2021 11:13:50.774017096 CEST2172423192.168.2.2036.69.14.93
Jul 22, 2021 11:13:50.774035931 CEST2172423192.168.2.20200.112.47.141
Jul 22, 2021 11:13:50.774038076 CEST2172423192.168.2.2046.113.34.200
Jul 22, 2021 11:13:50.774055004 CEST2172423192.168.2.2078.236.158.44
Jul 22, 2021 11:13:50.774065971 CEST2172423192.168.2.2027.53.243.194
Jul 22, 2021 11:13:50.774090052 CEST2172423192.168.2.2093.84.215.82
Jul 22, 2021 11:13:50.774100065 CEST2172423192.168.2.20255.91.13.229
Jul 22, 2021 11:13:50.774121046 CEST2172423192.168.2.20109.233.55.61
Jul 22, 2021 11:13:50.774166107 CEST2172423192.168.2.2017.175.65.191
Jul 22, 2021 11:13:50.774178982 CEST2172423192.168.2.20161.42.0.250
Jul 22, 2021 11:13:50.774190903 CEST2172423192.168.2.2024.56.58.134
Jul 22, 2021 11:13:50.774216890 CEST2172423192.168.2.20170.9.38.57
Jul 22, 2021 11:13:50.774216890 CEST2172423192.168.2.20120.102.96.94
Jul 22, 2021 11:13:50.774229050 CEST2172423192.168.2.20114.89.56.214
Jul 22, 2021 11:13:50.774235010 CEST2172423192.168.2.20103.179.83.227
Jul 22, 2021 11:13:50.774239063 CEST2172423192.168.2.20178.25.145.67
Jul 22, 2021 11:13:50.774277925 CEST2172423192.168.2.2074.150.165.252
Jul 22, 2021 11:13:50.774279118 CEST2172423192.168.2.2012.113.97.251
Jul 22, 2021 11:13:50.774286985 CEST2172423192.168.2.20195.47.85.209
Jul 22, 2021 11:13:50.774313927 CEST2172423192.168.2.20217.49.133.15
Jul 22, 2021 11:13:50.774317026 CEST2172423192.168.2.2031.80.111.48
Jul 22, 2021 11:13:50.774359941 CEST2172423192.168.2.20240.85.153.239
Jul 22, 2021 11:13:50.774399996 CEST2172423192.168.2.20116.50.227.1
Jul 22, 2021 11:13:50.774430037 CEST2172423192.168.2.2040.159.4.48
Jul 22, 2021 11:13:50.774451971 CEST2172423192.168.2.2078.100.119.65
Jul 22, 2021 11:13:50.774499893 CEST2172423192.168.2.2065.196.47.30
Jul 22, 2021 11:13:50.774499893 CEST2172423192.168.2.2034.97.17.5
Jul 22, 2021 11:13:50.774504900 CEST2172423192.168.2.20201.158.136.11
Jul 22, 2021 11:13:50.774509907 CEST2172423192.168.2.20221.34.115.79
Jul 22, 2021 11:13:50.774558067 CEST2172423192.168.2.20247.178.30.67
Jul 22, 2021 11:13:50.774594069 CEST2172423192.168.2.20161.164.3.35
Jul 22, 2021 11:13:50.774600029 CEST2172423192.168.2.2014.185.202.164
Jul 22, 2021 11:13:50.774602890 CEST2172423192.168.2.2066.224.64.166
Jul 22, 2021 11:13:50.774602890 CEST2172423192.168.2.20102.148.29.182
Jul 22, 2021 11:13:50.774606943 CEST2172423192.168.2.20180.144.190.181
Jul 22, 2021 11:13:50.774624109 CEST2172423192.168.2.2099.230.58.195
Jul 22, 2021 11:13:50.774627924 CEST2172423192.168.2.2075.107.205.0
Jul 22, 2021 11:13:50.774631023 CEST2172423192.168.2.20126.108.215.70
Jul 22, 2021 11:13:50.774632931 CEST2172423192.168.2.20133.95.162.230
Jul 22, 2021 11:13:50.774637938 CEST2172423192.168.2.20158.34.180.220
Jul 22, 2021 11:13:50.774646044 CEST2172423192.168.2.20183.56.189.108
Jul 22, 2021 11:13:50.774646044 CEST2172423192.168.2.20190.25.126.158
Jul 22, 2021 11:13:50.774657011 CEST2172423192.168.2.20197.236.205.164
Jul 22, 2021 11:13:50.774669886 CEST2172423192.168.2.2016.57.116.63
Jul 22, 2021 11:13:50.774672031 CEST2172423192.168.2.20210.147.38.251
Jul 22, 2021 11:13:50.774672985 CEST2172423192.168.2.20210.76.224.16
Jul 22, 2021 11:13:50.774677038 CEST2172423192.168.2.20221.212.175.201
Jul 22, 2021 11:13:50.774683952 CEST2172423192.168.2.2012.21.241.247
Jul 22, 2021 11:13:50.774688005 CEST2172423192.168.2.2059.179.208.250
Jul 22, 2021 11:13:50.774688005 CEST2172423192.168.2.20146.246.88.106
Jul 22, 2021 11:13:50.774693012 CEST2172423192.168.2.2045.127.98.77
Jul 22, 2021 11:13:50.774694920 CEST2172423192.168.2.20174.182.40.71
Jul 22, 2021 11:13:50.774703026 CEST2172423192.168.2.20105.102.213.3
Jul 22, 2021 11:13:50.774727106 CEST2172423192.168.2.20241.232.111.189
Jul 22, 2021 11:13:50.774760008 CEST2172423192.168.2.2037.104.136.110
Jul 22, 2021 11:13:50.774776936 CEST2172423192.168.2.2017.122.161.163
Jul 22, 2021 11:13:50.774784088 CEST2172423192.168.2.20169.114.134.243
Jul 22, 2021 11:13:50.774791956 CEST2172423192.168.2.2083.19.93.215
Jul 22, 2021 11:13:50.774804115 CEST2172423192.168.2.2076.31.88.222
Jul 22, 2021 11:13:50.774832010 CEST2172423192.168.2.20174.242.91.38
Jul 22, 2021 11:13:50.774846077 CEST2172423192.168.2.202.153.178.37
Jul 22, 2021 11:13:50.774846077 CEST2172423192.168.2.20109.163.192.102
Jul 22, 2021 11:13:50.774856091 CEST2172423192.168.2.20175.8.16.158
Jul 22, 2021 11:13:50.774873972 CEST2172423192.168.2.20117.213.98.139
Jul 22, 2021 11:13:50.774893045 CEST2172423192.168.2.2045.183.123.204
Jul 22, 2021 11:13:50.776525021 CEST2172423192.168.2.2090.124.132.91
Jul 22, 2021 11:13:50.776566982 CEST2172423192.168.2.20179.192.73.212
Jul 22, 2021 11:13:50.776567936 CEST2172423192.168.2.2099.203.92.79
Jul 22, 2021 11:13:50.776568890 CEST2172423192.168.2.20103.20.203.119
Jul 22, 2021 11:13:50.776595116 CEST2172423192.168.2.20154.121.40.220
Jul 22, 2021 11:13:50.776598930 CEST2172423192.168.2.20145.81.2.22

System Behavior

General

Start time:11:13:49
Start date:22/07/2021
Path:/tmp/d8dgn3wGJL
Arguments:/usr/bin/qemu-sparc /tmp/d8dgn3wGJL
File size:60412 bytes
MD5 hash:7c8ff25ee476a1cd89bbf529e0ac6af4

General

Start time:11:13:49
Start date:22/07/2021
Path:/tmp/d8dgn3wGJL
Arguments:n/a
File size:60412 bytes
MD5 hash:7c8ff25ee476a1cd89bbf529e0ac6af4

General

Start time:11:13:49
Start date:22/07/2021
Path:/tmp/d8dgn3wGJL
Arguments:n/a
File size:60412 bytes
MD5 hash:7c8ff25ee476a1cd89bbf529e0ac6af4

General

Start time:11:13:49
Start date:22/07/2021
Path:/tmp/d8dgn3wGJL
Arguments:n/a
File size:60412 bytes
MD5 hash:7c8ff25ee476a1cd89bbf529e0ac6af4

General

Start time:11:13:49
Start date:22/07/2021
Path:/tmp/d8dgn3wGJL
Arguments:n/a
File size:60412 bytes
MD5 hash:7c8ff25ee476a1cd89bbf529e0ac6af4

General

Start time:11:13:49
Start date:22/07/2021
Path:/tmp/d8dgn3wGJL
Arguments:n/a
File size:60412 bytes
MD5 hash:7c8ff25ee476a1cd89bbf529e0ac6af4

General

Start time:11:13:49
Start date:22/07/2021
Path:/tmp/d8dgn3wGJL
Arguments:n/a
File size:60412 bytes
MD5 hash:7c8ff25ee476a1cd89bbf529e0ac6af4