Loading ...

Play interactive tourEdit tour

Linux Analysis Report o3ZUDIEL1v

Overview

General Information

Sample Name:o3ZUDIEL1v
Analysis ID:452447
MD5:7694cfd641f968883d3bf665edb563db
SHA1:799787af8312d8ab137f796ce37f209bdb5797bd
SHA256:4609b5c0e2d1442f05c576bb0097e55344de9357643019d74bce4d3d9ed49a4c
Tags:32elfmirairenesas
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Opens /sys/class/net/* files useful for querying network interface information
Sample tries to kill many processes (SIGKILL)
Uses known network protocols on non-standard ports
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Reads system information from the proc file system
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:452447
Start date:22.07.2021
Start time:11:25:16
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 8m 43s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:o3ZUDIEL1v
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 59.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
Analysis Mode:default
Detection:MAL
Classification:mal76.spre.troj.spyw.lin@0/8@0/0
Warnings:
Show All
  • Excluded IPs from analysis (whitelisted): 91.189.92.39, 91.189.92.40, 91.189.92.38, 91.189.92.20, 91.189.92.41, 91.189.92.19
  • Excluded domains from analysis (whitelisted): api.snapcraft.io
  • Report size exceeded maximum capacity and may have missing network information.

Process Tree

  • system is lnxubuntu1
  • o3ZUDIEL1v (PID: 4576, Parent: 4497, MD5: 7694cfd641f968883d3bf665edb563db) Arguments: /usr/bin/qemu-sh4 /tmp/o3ZUDIEL1v
  • systemd New Fork (PID: 4602, Parent: 1)
  • sshd (PID: 4602, Parent: 1, MD5: 661b2a2da3b6c7d7ef41d0b9da1caa3b) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 4614, Parent: 1)
  • NetworkManager (PID: 4614, Parent: 1, MD5: 43dcb4efce9c2c522442ae62538bf659) Arguments: /usr/sbin/NetworkManager --no-daemon
  • systemd New Fork (PID: 4628, Parent: 1)
  • nm-online (PID: 4628, Parent: 1, MD5: ac72f7c256e548d273a5133a245a1638) Arguments: /usr/bin/nm-online -s -q --timeout=30
  • systemd New Fork (PID: 4641, Parent: 1)
  • nm-dispatcher (PID: 4641, Parent: 1, MD5: 7d4ef829ade49b564256f3f295f9c826) Arguments: /usr/lib/NetworkManager/nm-dispatcher
    • 01ifupdown (PID: 4665, Parent: 4641, MD5: 299819a8e64f00a1edbdfc99d05a8594) Arguments: /bin/sh -e /etc/NetworkManager/dispatcher.d/01ifupdown none hostname
  • systemd New Fork (PID: 4654, Parent: 1)
  • systemd-hostnamed (PID: 4654, Parent: 1, MD5: b05764f1a40963131ea2e1cd585f4139) Arguments: /lib/systemd/systemd-hostnamed
  • systemd New Fork (PID: 4679, Parent: 1)
  • snapd (PID: 4679, Parent: 1, MD5: 416402f94a949af355c09e8bccfa0eb0) Arguments: /usr/lib/snapd/snapd
  • systemd New Fork (PID: 4698, Parent: 1)
  • iscsiadm (PID: 4698, Parent: 1, MD5: b9363fe8099be776e324a481e209d7c4) Arguments: /sbin/iscsiadm -k 0 2
  • systemd New Fork (PID: 4722, Parent: 1)
  • sshd (PID: 4722, Parent: 1, MD5: 661b2a2da3b6c7d7ef41d0b9da1caa3b) Arguments: /usr/sbin/sshd -D
  • systemd New Fork (PID: 4774, Parent: 1)
  • systemd-hostnamed (PID: 4774, Parent: 1, MD5: b05764f1a40963131ea2e1cd585f4139) Arguments: /lib/systemd/systemd-hostnamed
  • systemd New Fork (PID: 4797, Parent: 1)
  • snapd (PID: 4797, Parent: 1, MD5: 416402f94a949af355c09e8bccfa0eb0) Arguments: /usr/lib/snapd/snapd
  • systemd New Fork (PID: 4818, Parent: 1)
  • sshd (PID: 4818, Parent: 1, MD5: 661b2a2da3b6c7d7ef41d0b9da1caa3b) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: o3ZUDIEL1vVirustotal: Detection: 50%Perma Link
    Source: o3ZUDIEL1vReversingLabs: Detection: 54%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 193.158.3.50: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.6.219.137: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.12.91.209: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 2.201.175.208: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.242.225.26: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.1.20.239: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.59.7.122: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 104.165.129.108: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 160.121.215.215: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.226.24.131: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 149.11.37.70: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.176.186.11: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.248.116.150: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 159.148.221.137: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 107.164.197.23: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.231.193.45:23 -> 192.168.2.20:36366
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.231.193.45:23 -> 192.168.2.20:36366
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.59.213.113: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.160.117.70: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.219.127.126: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.64.231.222: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.170.47.206: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.157.27.73: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 12.94.8.118: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 45.116.174.27: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.128.194.74: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.110.89.193: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.192.188.228: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 216.128.128.20: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.118.198.106: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 216.164.131.246: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 23.230.252.90: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 154.83.48.176: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 91.150.44.246: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.246.55.9: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 155.133.222.232: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 75.97.29.250: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 133.242.254.184: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 223.26.56.138: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.219.4.32: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.20.172.246: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.18.26.7: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.215.90.148: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 170.250.0.250: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.129.94.197: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.130.35.85: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 115.159.120.164: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.132.143.139: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 85.92.70.197: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 50.242.148.249: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.32.94.121: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 166.49.179.209: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60550
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 39.104.108.153: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.163.217: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.247.45.205: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 96.92.52.197: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 172.121.122.42: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.170.109: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.134.184.54: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.95.146.51: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.163.89: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.11.154.187: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.209.214.217: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 208.181.97.66: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 76.186.212.16: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60576
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.76.128.1: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 76.120.153.30: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 94.152.131.202: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 188.34.144.226: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 173.199.122.176: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 35.134.126.236: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 193.45.96.253: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60626
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.226.209.208: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.209.221.35: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 83.236.27.49: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 199.66.91.79: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 2.200.133.248: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.157.131.61: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 164.88.163.70: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.14.215.227: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 95.112.185.117: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.178.83.198: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.56.69: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 116.138.170.156:23 -> 192.168.2.20:59790
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.253.86.16: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 124.65.184.170: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 154.198.194.2: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60674
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.237.174.246: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 2.207.36.76: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.76.198.107: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 95.181.164.220: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 177.2.192.20: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 116.138.170.156:23 -> 192.168.2.20:59816
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 90.153.46.201: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 185.185.24.195: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60694
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 209.115.201.150: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 174.52.60.80: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.8.11.215: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 149.11.0.46: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 65.229.1.176: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 45.79.137.95: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 90.186.83.170: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 95.118.100.121: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.74.169.112: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.209.150.181: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.11.146.98: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60698
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.109.177: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.252.237.23: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 192.145.20.171: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 91.236.239.188: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60706
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 67.182.169.80: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 122.150.47.193: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.61.123.236: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 5.146.118.15: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.89.9.76: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 190.110.180.141: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.143.62.178: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 65.144.158.74: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60716
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 2.203.6.23: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 173.232.158.42: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.123.10.25: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.209.55.110:23 -> 192.168.2.20:36786
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.218.19.20: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.142.61.38: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.103.39.95: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.231.193.45:23 -> 192.168.2.20:36536
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.231.193.45:23 -> 192.168.2.20:36536
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60752
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.80.251.8: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.215.204.205: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.203.148.116: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.136.194.92: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.242.20.98: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 164.82.21.30: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 157.131.120.237: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 75.83.149.97: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 160.121.123.45: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.218.138.193: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.56.185: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 66.75.55.238: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 159.75.209.252: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.109.83.64: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 74.89.8.30: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 133.175.3.60:23 -> 192.168.2.20:60766
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.218.80.54: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 114.55.141.110: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.64.201.110: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.98.209.44: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.216.147.181: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.74.174.215: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.115.113.114: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 111.39.89.50:23 -> 192.168.2.20:54918
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.76.141.250: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 47.104.17.7: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 111.175.232.186: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.44.168.91: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.18.217.240: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.209.55.110:23 -> 192.168.2.20:36890
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.165.112.83: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.27.116.66: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 176.113.80.165: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 108.185.108.224: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.216.48.6: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 12.94.208.21: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 116.138.170.156:23 -> 192.168.2.20:59994
    Source: TrafficSnort IDS: 716 INFO TELNET access 24.37.3.214:23 -> 192.168.2.20:32832
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.76.31.171: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 111.39.89.50:23 -> 192.168.2.20:54988
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 69.204.60.32: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60344
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60344
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.218.6.95: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.172.124.137: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.250.147.149: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.211.138.130: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 173.193.187.84: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.199.255.144: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.236.173.187: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 154.66.2.113: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 201.10.253.76: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.89.92.162:23 -> 192.168.2.20:56626
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60392
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60392
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.201.3.68: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.134.114.38: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 213.188.117.155: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 45.39.201.83: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 66.216.243.40: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 140.128.251.57: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 210.234.224.18: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.89.92.162:23 -> 192.168.2.20:56626
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.64.216.205: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 78.42.164.176: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.54.120.139: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.161.181.207: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.102.178.107: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.218.127.238: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.214.227.217: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.12.155.40: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60426
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60426
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 156.67.173.2: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.247.40.106: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.229.153.221: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 12.245.110.154: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.89.92.162:23 -> 192.168.2.20:56656
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.209.55.110:23 -> 192.168.2.20:36996
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.165.112.169: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.89.92.162:23 -> 192.168.2.20:56656
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.63.26.203: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.35.81.150: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.208.29.117: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.96.148.61: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.201.199.141: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 37.138.14.54: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 220.229.237.220: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 168.95.75.61: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.138.245.99: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 104.216.97.84: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60446
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60446
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 5.100.35.51: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 89.56.149.54: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.77.248.55: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 207.148.119.104: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 160.116.125.14: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 111.39.89.50:23 -> 192.168.2.20:55078
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.89.92.162:23 -> 192.168.2.20:56676
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.5.34.72: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.58.176.97: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.89.92.162:23 -> 192.168.2.20:56676
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60460
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60460
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.82.219.149: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.198.246.123: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.193.187.159: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 140.238.48.5: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 95.91.111.141: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.59.220.37: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.209.55.110:23 -> 192.168.2.20:37040
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 37.138.187.61: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.55.132.144: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.89.92.162:23 -> 192.168.2.20:56716
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 207.228.16.154: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.89.92.162:23 -> 192.168.2.20:56716
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 83.218.180.221: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.115.185: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60490
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60490
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.136.109.91: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.0.167.89: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.236.250.74: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.87.57.187: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.27.183.48: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 31.19.128.235: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 185.93.109.22: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 220.89.92.162:23 -> 192.168.2.20:56752
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.122.87.154: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 111.39.89.50:23 -> 192.168.2.20:55158
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 164.88.222.116: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.34.99.222: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 73.94.128.115: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 12.244.90.114: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60532
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60532
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.111.246.69:23 -> 192.168.2.20:41000
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.89.92.162:23 -> 192.168.2.20:56752
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.157.128.213: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 208.58.98.110: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 209.191.216.42: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 72.189.86.103: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60556
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60556
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 104.164.235.8: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 24.37.3.214:23 -> 192.168.2.20:33042
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.231.193.45:23 -> 192.168.2.20:36872
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.231.193.45:23 -> 192.168.2.20:36872
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.111.246.69:23 -> 192.168.2.20:41000
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.109.201: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.248.68.122: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 50.220.200.185: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 116.138.170.156:23 -> 192.168.2.20:60226
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.231.117.91: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.13.149.136: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.64.98.181: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 95.35.24.93:23 -> 192.168.2.20:60590
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 95.35.24.93:23 -> 192.168.2.20:60590
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.111.246.69:23 -> 192.168.2.20:41086
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.60.251.160: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 72.177.227.48: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 120.209.55.110:23 -> 192.168.2.20:37186
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 90.153.29.180: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 107.148.14.231: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 111.39.89.50:23 -> 192.168.2.20:55254
    Source: TrafficSnort IDS: 716 INFO TELNET access 116.138.170.156:23 -> 192.168.2.20:60266
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.78.227.221: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.130.120.196: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.135.155.241: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.178.97.177: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 172.87.194.150: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.180.109.205: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.142.13.11: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 50.228.31.102: -> 192.168.2.20:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.111.246.69:23 -> 192.168.2.20:41086
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.82.53.177: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.160.178.76: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 216.161.197.154: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 162.253.155.19: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.105.13: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 167.99.65.119: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 203.86.201.126: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.174.150.128: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.218.129.10: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 141.98.90.198: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 83.99.81.239: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 85.16.230.250: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.6.24.128: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 65.113.81.182: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 60.40.78.131: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.12.60.151: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.255.247.161: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 62.155.168.123: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.58.148.99: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.119.32.69: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 103.236.179.6: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.195.230.125: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 193.80.237.187: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.8.140.240: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 75.97.224.89: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.63.216.163: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.191.34.37: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.158.130.151: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.220.33.22: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 213.233.9.25: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 194.79.197.48: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.129.157: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 170.250.183.238: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 197.221.9.10: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 89.56.248.229: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 217.16.1.80: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.202.200.116: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.217.95.199: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.15.217.171: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 104.252.59.236: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 211.203.78.9:23 -> 192.168.2.20:42540
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.83.172.98: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 208.58.223.65: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.140.248.107: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.39.49.138: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 160.121.155.195: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.6.105.180: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.200.10.237: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 154.36.247.214: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52544
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 213.34.116.89: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.24.214.249: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.179.248.171: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 168.95.221.221: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 61.112.54.102: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52556
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 75.97.99.100: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.40.112.232: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 212.131.67.242: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.176.237.103: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.181.65.46: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52562
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.203.78.9:23 -> 192.168.2.20:42540
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.203.78.9:23 -> 192.168.2.20:42540
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.6.93.36: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.226.46.156: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.201.1.121: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.151.15.161: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.89.207.214: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 78.47.192.113: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52570
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.131.26: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.180.198.203:23 -> 192.168.2.20:36396
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52582
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 159.48.45.44: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.12.27.198: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 89.0.205.240: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.213.208.137: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52588
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.185.32.156: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.192.233.142: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.244.233.144: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.142.202.31: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 93.104.214.147: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.171.67.68: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.150.12.27: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 82.144.193.62: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52596
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.5.113.2: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.174.85: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 79.194.168.240: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 5.231.145.203: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.96.169.2: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52604
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 216.116.10.130: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 119.180.198.203:23 -> 192.168.2.20:36396
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 119.180.198.203:23 -> 192.168.2.20:36396
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.217.152.84: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 85.16.225.65: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52616
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 81.95.2.194: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55708
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.222.173.161: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.160.102.62:23 -> 192.168.2.20:52632
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 154.61.46.182: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.75.55.64: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.133.229.225: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55716
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.165.113: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 77.6.131.172: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 213.249.87.20: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.21.238.1: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.153.183.87: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 46.86.189.72: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.251.202:23 -> 192.168.2.20:35022
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 150.99.188.138: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55730
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.174.43.104: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.8.85.192: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.78.87.42: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 211.203.78.9:23 -> 192.168.2.20:42662
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55738
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.117.61.67: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 107.2.176.21: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55740
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.67.228.227: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 185.252.245.92: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 37.49.40.27: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.206.38.146: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 149.172.188.96: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55746
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 124.133.251.202:23 -> 192.168.2.20:35022
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55764
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.225.94.163: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.106.89.95: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.97.153.57: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 160.16.66.29: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 154.81.188.249: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55798
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.184.217.82: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 176.199.135.224: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.158.94.227: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 86.79.225.164: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.82.159.12: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.121.113: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 119.180.198.203:23 -> 192.168.2.20:36566
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55832
    Source: TrafficSnort IDS: 716 INFO TELNET access 222.90.79.58:23 -> 192.168.2.20:45038
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 80.101.46.99: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.203.78.9:23 -> 192.168.2.20:42662
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.203.78.9:23 -> 192.168.2.20:42662
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.10.243.76: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.132.141.122: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.12.62.146: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 81.70.33.142: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.169.85.44:23 -> 192.168.2.20:55848
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.168.103.217: -> 192.168.2.20:
    Source: TrafficSnort IDS: 716 INFO TELNET access 124.133.251.202:23 -> 192.168.2.20:35148
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 92.208.225.213: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 188.192.56.180: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 217.228.248.161: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 178.12.166.79: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 24.228.195.143: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.66.240.0: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 107.11.6.140: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.163.173: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 87.189.21.198: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.248.253.47: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.173.221: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.224.108.96: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 88.64.74.200: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 73.253.65.136: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 91.77.64.1: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 94.219.191.194: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.17.32.41: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 84.159.230.115: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 218.248.162.237: -> 192.168.2.20:
    Source: TrafficSnort IDS: 486 ICMP Destination Unreachable Communication with Destination Host is Administratively Prohibited 23.239.4.61: -> 192.168.2.20:
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 222.118.131.166:23 -> 192.168.2.20:57586
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 222.118.131.166:23 -> 192.168.2.20:57586
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 119.180.198.203:23 -> 192.168.2.20:36566
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 119.180.198.203:23 -> 192.168.2.20:36566
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 124.133.251.202:23 -> 192.168.2.20:35148
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 2.204.86.193: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 93.194.47.4: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 151.63.15.206: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 70.34.131.62: -> 192.168.2.20:
    Source: TrafficSnort IDS: 485 ICMP Destination Unreachable Communication Administratively Prohibited 68.175.0.3: -> 192.168.2.20:
    Opens /sys/class/net/* files useful for querying network interface informationShow sources
    Source: /usr/sbin/NetworkManager (PID: 4614)Opens: /sys/class/net/ens160/ueventJump to behavior
    Source: /usr/sbin/NetworkManager (PID: 4614)Opens: /sys/class/net/Jump to behavior
    Source: /usr/sbin/NetworkManager (PID: 4614)Opens: /sys/class/net/lo/phys_port_idJump to behavior
    Source: /usr/sbin/NetworkManager (PID: 4614)Opens: /sys/class/net/lo/dev_idJump to behavior
    Source: /usr/sbin/NetworkManager (PID: 4614)Opens: /sys/class/net/ens160/phys_port_idJump to behavior
    Source: /usr/sbin/NetworkManager (PID: 4614)Opens: /sys/class/net/ens160/dev_idJump to behavior
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33264
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33266
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33268
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33270
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33280
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33284
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49098
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49108
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49128
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49160
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49168
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49190
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49196
    Source: global trafficTCP traffic: 192.168.2.20:35686 -> 37.230.137.227:1312
    Source: /tmp/o3ZUDIEL1v (PID: 4582)Socket: 0.0.0.0::0Jump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)Socket: 0.0.0.0::53413Jump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)Socket: 0.0.0.0::80Jump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4587)Socket: 0.0.0.0::0Jump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4587)Socket: 0.0.0.0::53413Jump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4587)Socket: 0.0.0.0::80Jump to behavior
    Source: /usr/sbin/sshd (PID: 4602)Socket: 0.0.0.0::22Jump to behavior
    Source: /usr/sbin/sshd (PID: 4602)Socket: [::]::22Jump to behavior
    Source: /usr/sbin/sshd (PID: 4722)Socket: 0.0.0.0::22Jump to behavior
    Source: /usr/sbin/sshd (PID: 4722)Socket: [::]::22Jump to behavior
    Source: /usr/sbin/sshd (PID: 4818)Socket: 0.0.0.0::22Jump to behavior
    Source: /usr/sbin/sshd (PID: 4818)Socket: [::]::22Jump to behavior
    Source: unknownTCP traffic detected without corresponding DNS query: 37.230.137.227
    Source: unknownTCP traffic detected without corresponding DNS query: 243.26.191.247
    Source: unknownTCP traffic detected without corresponding DNS query: 9.86.21.247
    Source: unknownTCP traffic detected without corresponding DNS query: 1.103.128.240
    Source: unknownTCP traffic detected without corresponding DNS query: 4.42.65.113
    Source: unknownTCP traffic detected without corresponding DNS query: 99.132.34.171
    Source: unknownTCP traffic detected without corresponding DNS query: 4.143.4.193
    Source: unknownTCP traffic detected without corresponding DNS query: 186.164.107.66
    Source: unknownTCP traffic detected without corresponding DNS query: 148.79.21.135
    Source: unknownTCP traffic detected without corresponding DNS query: 141.1.98.58
    Source: unknownTCP traffic detected without corresponding DNS query: 204.137.150.71
    Source: unknownTCP traffic detected without corresponding DNS query: 59.73.176.127
    Source: unknownTCP traffic detected without corresponding DNS query: 196.132.213.224
    Source: unknownTCP traffic detected without corresponding DNS query: 192.27.249.233
    Source: unknownTCP traffic detected without corresponding DNS query: 135.236.222.132
    Source: unknownTCP traffic detected without corresponding DNS query: 175.66.69.148
    Source: unknownTCP traffic detected without corresponding DNS query: 19.231.199.74
    Source: unknownTCP traffic detected without corresponding DNS query: 183.230.245.230
    Source: unknownTCP traffic detected without corresponding DNS query: 92.133.180.50
    Source: unknownTCP traffic detected without corresponding DNS query: 13.239.22.222
    Source: unknownTCP traffic detected without corresponding DNS query: 2.71.134.148
    Source: unknownTCP traffic detected without corresponding DNS query: 193.59.99.199
    Source: unknownTCP traffic detected without corresponding DNS query: 59.73.197.194
    Source: unknownTCP traffic detected without corresponding DNS query: 216.92.227.31
    Source: unknownTCP traffic detected without corresponding DNS query: 166.74.189.55
    Source: unknownTCP traffic detected without corresponding DNS query: 254.4.252.215
    Source: unknownTCP traffic detected without corresponding DNS query: 87.21.174.182
    Source: unknownTCP traffic detected without corresponding DNS query: 97.252.85.99
    Source: unknownTCP traffic detected without corresponding DNS query: 57.206.83.89
    Source: unknownTCP traffic detected without corresponding DNS query: 69.226.211.85
    Source: unknownTCP traffic detected without corresponding DNS query: 117.198.250.17
    Source: unknownTCP traffic detected without corresponding DNS query: 117.130.158.105
    Source: unknownTCP traffic detected without corresponding DNS query: 71.76.187.11
    Source: unknownTCP traffic detected without corresponding DNS query: 241.3.141.59
    Source: unknownTCP traffic detected without corresponding DNS query: 62.157.87.169
    Source: unknownTCP traffic detected without corresponding DNS query: 157.184.155.228
    Source: unknownTCP traffic detected without corresponding DNS query: 168.18.45.144
    Source: unknownTCP traffic detected without corresponding DNS query: 157.42.156.242
    Source: unknownTCP traffic detected without corresponding DNS query: 139.222.108.43
    Source: unknownTCP traffic detected without corresponding DNS query: 53.82.141.221
    Source: unknownTCP traffic detected without corresponding DNS query: 208.19.17.255
    Source: unknownTCP traffic detected without corresponding DNS query: 255.136.182.34
    Source: unknownTCP traffic detected without corresponding DNS query: 121.125.254.22
    Source: unknownTCP traffic detected without corresponding DNS query: 78.245.161.152
    Source: unknownTCP traffic detected without corresponding DNS query: 72.218.31.188
    Source: unknownTCP traffic detected without corresponding DNS query: 241.36.218.141
    Source: unknownTCP traffic detected without corresponding DNS query: 60.5.54.0
    Source: unknownTCP traffic detected without corresponding DNS query: 44.146.169.199
    Source: unknownTCP traffic detected without corresponding DNS query: 63.195.178.169
    Source: unknownTCP traffic detected without corresponding DNS query: 209.169.225.120

    System Summary:

    barindex
    Sample tries to kill many processes (SIGKILL)Show sources
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1059, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1065, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1091, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1362, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1363, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3289, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3308, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3484, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3491, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3496, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3501, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3596, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3601, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3606, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3611, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3616, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3790, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3791, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4584, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4587, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4596, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4602, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4614, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4679, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4722, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4587)SIGKILL sent: pid: 1339, result: successfulJump to behavior
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1059, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1065, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1091, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1362, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 1363, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3289, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3308, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3484, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3491, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3496, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3501, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3596, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3601, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3606, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3611, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3616, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3790, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 3791, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4584, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4587, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4596, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4602, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4614, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4679, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)SIGKILL sent: pid: 4722, result: successfulJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4587)SIGKILL sent: pid: 1339, result: successfulJump to behavior
    Source: classification engineClassification label: mal76.spre.troj.spyw.lin@0/8@0/0
    Source: /usr/sbin/NetworkManager (PID: 4614)Directory: /root/.cacheJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1065/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1065/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3485/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3485/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3485/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3484/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3484/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1062/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1062/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1062/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3482/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3482/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3482/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3481/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3481/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3481/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1060/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1060/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1060/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1059/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1059/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3479/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3479/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3479/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3512/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3512/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3512/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3477/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3477/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3477/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1452/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1452/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1452/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/514/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3632/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3632/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3632/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4722/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4602/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/519/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3518/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3518/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3518/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4582/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4582/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4584/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4584/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3497/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3497/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3497/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3133/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3133/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3133/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3496/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3496/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1072/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1072/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1072/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3491/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3491/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/483/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3527/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3527/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3527/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3525/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3525/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3525/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3524/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3524/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3524/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1346/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1346/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1346/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3523/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3523/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3523/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3488/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3488/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3488/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3920/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4614/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4596/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/4596/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1363/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1363/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3541/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3541/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3541/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1362/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1362/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3262/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3262/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3262/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1084/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1084/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/1084/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3380/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3380/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/3380/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/496/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/496/exeJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/496/fdJump to behavior
    Source: /tmp/o3ZUDIEL1v (PID: 4582)File opened: /proc/410/exeJump to behavior
    Source: /usr/lib/snapd/snapd (PID: 4679)Reads from proc file: /proc/sys/net/core/somaxconnJump to behavior
    Source: /usr/lib/snapd/snapd (PID: 4679)Reads from proc file: /proc/sys/kernel/hostnameJump to behavior
    Source: /usr/lib/snapd/snapd (PID: 4797)Reads from proc file: /proc/sys/net/core/somaxconnJump to behavior
    Source: /usr/lib/snapd/snapd (PID: 4797)Reads from proc file: /proc/sys/kernel/hostnameJump to behavior

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33264
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33266
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33268
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33270
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33280
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33282
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33284
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33286
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49098
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49108
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49128
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49150
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49160
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49168
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49190
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 49196
    Source: /tmp/o3ZUDIEL1v (PID: 4576)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/sbin/NetworkManager (PID: 4614)Queries kernel information via 'uname': Jump to behavior
    Source: /lib/systemd/systemd-hostnamed (PID: 4654)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/snapd/snapd (PID: 4679)Queries kernel information via 'uname': Jump to behavior
    Source: /lib/systemd/systemd-hostnamed (PID: 4774)Queries kernel information via 'uname': Jump to behavior
    Source: /usr/lib/snapd/snapd (PID: 4797)Queries kernel information via 'uname': Jump to behavior

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionHidden Files and Directories1OS Credential Dumping1Security Software Discovery1Remote ServicesNetwork Information Discovery1Exfiltration Over Other Network MediumNon-Standard Port11Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 452447 Sample: o3ZUDIEL1v Startdate: 22/07/2021 Architecture: LINUX Score: 76 49 196.141.123.204 Vodafone-EG Egypt 2->49 51 94.62.226.117 VODAFONE-PTVodafonePortugalPT Portugal 2->51 53 98 other IPs or domains 2->53 57 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->57 59 Multi AV Scanner detection for submitted file 2->59 61 Yara detected Mirai 2->61 63 Uses known network protocols on non-standard ports 2->63 10 o3ZUDIEL1v 2->10         started        12 systemd NetworkManager 2->12         started        15 systemd nm-dispatcher 2->15         started        17 9 other processes 2->17 signatures3 process4 signatures5 19 o3ZUDIEL1v 10->19         started        22 o3ZUDIEL1v 10->22         started        24 o3ZUDIEL1v 10->24         started        67 Opens /sys/class/net/* files useful for querying network interface information 12->67 26 nm-dispatcher 01ifupdown 15->26         started        process6 signatures7 65 Sample tries to kill many processes (SIGKILL) 19->65 28 o3ZUDIEL1v 19->28         started        30 o3ZUDIEL1v 19->30         started        32 o3ZUDIEL1v 22->32         started        35 o3ZUDIEL1v