Loading ...

Play interactive tourEdit tour

Linux Analysis Report 61KiF94nKN

Overview

General Information

Sample Name:61KiF94nKN
Analysis ID:533998
MD5:06d58f655cb40ee644bd74e19483ba8b
SHA1:84a92f7b7855ef9f1ec12e10ef38b3bc7045d903
SHA256:e0f8643b2d10593678b16fdaab7bc4a070cdbe4a8a617b0a37bda328f4002235
Tags:32elfmiraisparc
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Connects to many ports of the same IP (likely port scanning)
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:533998
Start date:04.12.2021
Start time:22:44:53
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 45s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:61KiF94nKN
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.troj.lin@0/2@13/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • systemd New Fork (PID: 5263, Parent: 1)
  • sshd (PID: 5263, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -t
  • systemd New Fork (PID: 5264, Parent: 1)
  • sshd (PID: 5264, Parent: 1, MD5: dbca7a6bbf7bf57fedac243d4b2cb340) Arguments: /usr/sbin/sshd -D
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: 61KiF94nKNVirustotal: Detection: 36%Perma Link
    Source: 61KiF94nKNReversingLabs: Detection: 40%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:55898
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 188.225.165.67:23 -> 192.168.2.23:37052
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 188.225.165.67:23 -> 192.168.2.23:37052
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:60090 -> 89.171.39.145:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56610
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56606
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56608
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:50692
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:50696
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:56238 -> 190.105.72.110:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:50740
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56674
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:50752
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56690
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56696
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.136.212.54:23 -> 192.168.2.23:44096
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:56690 -> 223.76.244.29:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:56170
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:50844
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:56172
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:50872
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.136.212.54:23 -> 192.168.2.23:44184
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56910
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56938
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51028
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51034
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:56966
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:50846
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.136.212.54:23 -> 192.168.2.23:44342
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:50864
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:50924
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:56494 -> 183.245.121.8:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:56494
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51176
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51178
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:50980
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57124
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:51502
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:51502
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:51514
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:51514
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57134
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.136.212.54:23 -> 192.168.2.23:44526
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57166
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51032
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51054
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51272
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51064
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51276
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.136.212.54:23 -> 192.168.2.23:44628
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:37274 -> 1.173.125.141:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51086
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57228
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:56664
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51314
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51100
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51106
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51322
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57258
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57264
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51126
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 61.136.212.54:23 -> 192.168.2.23:44660
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51404
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51206
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51428
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57370
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51228
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51234
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:56804
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:51776
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:51776
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:51782
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:51782
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57392
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51254
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51470
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51478
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57402
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:54878 -> 36.239.107.74:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51284
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57434
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51300
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51312
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:51300 -> 218.248.46.241:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 12.247.13.94:23 -> 192.168.2.23:51536
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51338
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57488
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57512
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51390
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:56992 -> 183.245.121.8:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57572
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:56992
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51442
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57492
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51456
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51480
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:57046
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57628
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52042
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52042
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52048
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52048
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57666
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:47088
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:55820 -> 187.115.198.253:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:47116
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51550
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57614
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51588
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:59028
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57734
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51596
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57650
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:33036 -> 89.171.39.145:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51616
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:47088
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:47116
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57678
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57784
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57788
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51670
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57724
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:59164
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51734
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57782
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51740
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57908
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:47330
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:47348
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:57348
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57840
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51798
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57868
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57964
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57966
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51836
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51838
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57984
    Source: TrafficSnort IDS: 716 INFO TELNET access 223.76.244.29:23 -> 192.168.2.23:57982
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:59294
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52384
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52384
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52404
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52404
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57916
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:57966 -> 223.76.244.29:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:47330
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:57982 -> 223.76.244.29:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51902
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:47348
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51904
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51908
    Source: TrafficSnort IDS: 716 INFO TELNET access 45.163.44.227:23 -> 192.168.2.23:55908
    Source: TrafficSnort IDS: 716 INFO TELNET access 45.163.44.227:23 -> 192.168.2.23:55910
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:51928
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 2.179.124.160:23 -> 192.168.2.23:33552
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:57504
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:59404
    Source: TrafficSnort IDS: 716 INFO TELNET access 123.219.169.105:23 -> 192.168.2.23:57972
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:47560
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52004
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:47604
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52040
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52080
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52092
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:53284
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:53290
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:59564
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52134
    Source: TrafficSnort IDS: 716 INFO TELNET access 45.163.44.227:23 -> 192.168.2.23:56140
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:47560
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:47604
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.187.41:23 -> 192.168.2.23:60670
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.187.41:23 -> 192.168.2.23:60670
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.187.41:23 -> 192.168.2.23:60690
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.187.41:23 -> 192.168.2.23:60690
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52250
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52246
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:57900 -> 183.245.121.8:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:59822
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:53284
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.248.46.241:23 -> 192.168.2.23:52388
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:57884
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:57900
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:53290
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52770
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52770
    Source: TrafficSnort IDS: 716 INFO TELNET access 45.163.44.227:23 -> 192.168.2.23:56176
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52814
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52814
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52816
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52816
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:52818
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:52818
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:48080
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:48074
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 93.103.21.179:23 -> 192.168.2.23:58054
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:60064
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:53812
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:53862
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 93.103.21.179:23 -> 192.168.2.23:58112
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:48080
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:58258
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:54674
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:54674
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:54676
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:54676
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 93.103.21.179:23 -> 192.168.2.23:58148
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:48074
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:60200
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:53812
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:55672 -> 46.164.131.142:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:48404
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:53862
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:54798
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:54798
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:48434
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:54800
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:54800
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:60352
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:54122
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:48404
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.108.203.2:23 -> 192.168.2.23:44254
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:58502
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:54152
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.187.41:23 -> 192.168.2.23:33226
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.187.41:23 -> 192.168.2.23:33226
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:54912
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:54912
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:53476
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:53476
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:53488
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:53488
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:53502
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:53502
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:53500
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:53500
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:58546
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.187.41:23 -> 192.168.2.23:33248
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.187.41:23 -> 192.168.2.23:33248
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:54978
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:54978
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:53478
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:53478
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:48434
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:53522
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:53522
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.238.74.44:23 -> 192.168.2.23:35714
    Source: TrafficSnort IDS: 716 INFO TELNET access 36.152.242.114:23 -> 192.168.2.23:60532
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:48718
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:55092
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:55092
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.108.203.2:23 -> 192.168.2.23:44254
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:60976
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:60978
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:60990
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:32784
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:32794
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:54122
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:32798
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:54152
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:55170
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:55170
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.238.74.44:23 -> 192.168.2.23:35872
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:48900
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:56264 -> 46.164.131.142:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:53734
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:53734
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:55384
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:55384
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:48718
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.108.203.2:23 -> 192.168.2.23:44786
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:60976
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:60976
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:60990
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:60990
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:60978
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:60978
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:32784
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:32784
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:32794
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:32794
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:32798
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:32798
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:55454
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:55454
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:54774
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.238.74.44:23 -> 192.168.2.23:36154
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:54802
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:48900
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:56880 -> 36.239.107.74:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:55752
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:55752
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:54646
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:54646
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:59342
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:49474
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.108.203.2:23 -> 192.168.2.23:44786
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.238.74.44:23 -> 192.168.2.23:36458
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:54662
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:54662
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:54652
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:54652
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:54658
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:54658
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:54664
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:54664
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:58702
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:58702
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:58698
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:58698
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:58718
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:58718
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:55788
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:55788
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:58760
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:58760
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:54264
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:54264
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:58802
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:58802
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:54300
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:54300
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:59460
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:54774
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:54336
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:54336
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:54802
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:58852
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:58852
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:54344
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:54344
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:54396
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:54396
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:49602
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56006
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56006
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.238.74.44:23 -> 192.168.2.23:36752
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.108.203.2:23 -> 192.168.2.23:45414
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:49474
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:33708
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:33710
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.187.41:23 -> 192.168.2.23:34238
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.187.41:23 -> 192.168.2.23:34238
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:33726
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56064
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56064
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.187.41:23 -> 192.168.2.23:34414
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.187.41:23 -> 192.168.2.23:34414
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:55428
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:55442
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:55230
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:55230
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.238.74.44:23 -> 192.168.2.23:36912
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56244
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56244
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:49602
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:54692
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:54692
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.245.121.8:23 -> 192.168.2.23:59796
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.108.203.2:23 -> 192.168.2.23:45414
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:49972
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:33710
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:33710
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:33708
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:33708
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56314
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56314
    Source: TrafficSnort IDS: 2024980 ET EXPLOIT Actiontec C1000A backdoor account M2 192.168.2.23:41674 -> 201.163.61.109:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:33726
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:33726
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:55428
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.238.74.44:23 -> 192.168.2.23:37152
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:55442
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56450
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56450
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:50088
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 202.101.183.165:23 -> 192.168.2.23:39500
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.108.203.2:23 -> 192.168.2.23:45882
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56500
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56500
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.143.24.158:23 -> 192.168.2.23:53200
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.143.24.158:23 -> 192.168.2.23:53200
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 212.143.24.158:23 -> 192.168.2.23:53208
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 212.143.24.158:23 -> 192.168.2.23:53208
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:59636
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:59636
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:59634
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:59634
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:55104
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:55104
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:55108
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:55108
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:59638
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:59638
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:59648
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:59648
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:55924
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:55118
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:55118
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:59662
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:59662
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:49972
    Source: TrafficSnort IDS: 716 INFO TELNET access 60.161.155.91:23 -> 192.168.2.23:55930
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56690
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56690
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:55136
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:55136
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:55678
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:55678
    Source: TrafficSnort IDS: 716 INFO TELNET access 45.163.44.227:23 -> 192.168.2.23:58578
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:55700
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:55700
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 211.23.119.114:23 -> 192.168.2.23:59684
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 211.23.119.114:23 -> 192.168.2.23:59684
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.26.231.214:23 -> 192.168.2.23:54238
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:55166
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:55166
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:55706
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:55706
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 122.226.46.82:23 -> 192.168.2.23:50088
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.19.94.216:23 -> 192.168.2.23:55696
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.19.94.216:23 -> 192.168.2.23:55696
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 113.108.203.2:23 -> 192.168.2.23:45882
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:34362
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:34364
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.208.6:23 -> 192.168.2.23:56774
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.208.6:23 -> 192.168.2.23:56774
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:34366
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:34368
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:34372
    Source: TrafficSnort IDS: 716 INFO TELNET access 90.117.64.194:23 -> 192.168.2.23:34370
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.26.231.214:23 -> 192.168.2.23:54342
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:50442
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:55930
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 60.161.155.91:23 -> 192.168.2.23:55924
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 46.181.66.105:23 -> 192.168.2.23:55410
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 46.181.66.105:23 -> 192.168.2.23:55410
    Source: TrafficSnort IDS: 716 INFO TELNET access 122.226.46.82:23 -> 192.168.2.23:50494
    Source: TrafficSnort IDS: 716 INFO TELNET access 113.108.203.2:23 -> 192.168.2.23:46256
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 219.85.187.41:23 -> 192.168.2.23:35200
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 219.85.187.41:23 -> 192.168.2.23:35200
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:34362
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:34362
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:34366
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:34366
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:34368
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:34368
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:34372
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:34372
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:34364
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:34364
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 90.117.64.194:23 -> 192.168.2.23:34370
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 90.117.64.194:23 -> 192.168.2.23:34370
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37334
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37340
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37348
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37356
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37364
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37376
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37416
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39298
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39318
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39320
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39326
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39328
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39334
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39336
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39340
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39338
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39344
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39460
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39552
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39690
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39712
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46008
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46052
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46068
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46086
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46096
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46108
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46130
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46144
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46164
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46210
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33984
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34002
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34010
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34012
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34022
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34044
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34046
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34058
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34062
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34064
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34082
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34090
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34108
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34114
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34116
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34162
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34172
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34210
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34226
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34278
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34314
    Connects to many ports of the same IP (likely port scanning)Show sources
    Source: global trafficTCP traffic: 107.189.5.196 ports 3175,62947,1,3,5,7
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:47856 -> 107.189.5.196:3175
    Source: /tmp/61KiF94nKN (PID: 5226)Socket: 0.0.0.0::0
    Source: /tmp/61KiF94nKN (PID: 5226)Socket: 0.0.0.0::23
    Source: /tmp/61KiF94nKN (PID: 5226)Socket: 0.0.0.0::53413
    Source: /tmp/61KiF94nKN (PID: 5226)Socket: 0.0.0.0::80
    Source: /tmp/61KiF94nKN (PID: 5226)Socket: 0.0.0.0::52869
    Source: /tmp/61KiF94nKN (PID: 5226)Socket: 0.0.0.0::81
    Source: /tmp/61KiF94nKN (PID: 5232)Socket: 0.0.0.0::0
    Source: /usr/sbin/sshd (PID: 5264)Socket: 0.0.0.0::22
    Source: /usr/sbin/sshd (PID: 5264)Socket: [::]::22
    Source: unknownDNS traffic detected: queries for: xia.ddcch4ckserver.top
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 248.193.244.74
    Source: unknownTCP traffic detected without corresponding DNS query: 182.30.202.74
    Source: unknownTCP traffic detected without corresponding DNS query: 20.170.254.210
    Source: unknownTCP traffic detected without corresponding DNS query: 217.222.231.113
    Source: unknownTCP traffic detected without corresponding DNS query: 42.200.189.153
    Source: unknownTCP traffic detected without corresponding DNS query: 144.57.51.77
    Source: unknownTCP traffic detected without corresponding DNS query: 154.26.157.215
    Source: unknownTCP traffic detected without corresponding DNS query: 78.244.182.235
    Source: unknownTCP traffic detected without corresponding DNS query: 175.76.251.170
    Source: unknownTCP traffic detected without corresponding DNS query: 162.167.22.164
    Source: unknownTCP traffic detected without corresponding DNS query: 147.174.188.3
    Source: unknownTCP traffic detected without corresponding DNS query: 247.30.146.27
    Source: unknownTCP traffic detected without corresponding DNS query: 84.163.75.219
    Source: unknownTCP traffic detected without corresponding DNS query: 86.231.94.30
    Source: unknownTCP traffic detected without corresponding DNS query: 65.54.249.74
    Source: unknownTCP traffic detected without corresponding DNS query: 148.124.160.183
    Source: unknownTCP traffic detected without corresponding DNS query: 219.149.150.55
    Source: unknownTCP traffic detected without corresponding DNS query: 41.108.222.11
    Source: unknownTCP traffic detected without corresponding DNS query: 107.112.201.203
    Source: unknownTCP traffic detected without corresponding DNS query: 8.46.29.60
    Source: unknownTCP traffic detected without corresponding DNS query: 62.3.116.251
    Source: unknownTCP traffic detected without corresponding DNS query: 177.206.148.136
    Source: unknownTCP traffic detected without corresponding DNS query: 165.130.187.97
    Source: unknownTCP traffic detected without corresponding DNS query: 198.52.223.117
    Source: unknownTCP traffic detected without corresponding DNS query: 79.205.208.191
    Source: unknownTCP traffic detected without corresponding DNS query: 38.142.35.158
    Source: unknownTCP traffic detected without corresponding DNS query: 217.16.189.179
    Source: unknownTCP traffic detected without corresponding DNS query: 194.15.246.151
    Source: unknownTCP traffic detected without corresponding DNS query: 24.21.13.6
    Source: unknownTCP traffic detected without corresponding DNS query: 219.178.164.254
    Source: unknownTCP traffic detected without corresponding DNS query: 75.114.192.193
    Source: unknownTCP traffic detected without corresponding DNS query: 12.184.52.122
    Source: unknownTCP traffic detected without corresponding DNS query: 219.106.239.212
    Source: unknownTCP traffic detected without corresponding DNS query: 139.242.243.69
    Source: unknownTCP traffic detected without corresponding DNS query: 184.59.166.130
    Source: unknownTCP traffic detected without corresponding DNS query: 205.127.95.157
    Source: unknownTCP traffic detected without corresponding DNS query: 146.62.124.63
    Source: unknownTCP traffic detected without corresponding DNS query: 35.56.18.171
    Source: unknownTCP traffic detected without corresponding DNS query: 211.176.55.53
    Source: unknownTCP traffic detected without corresponding DNS query: 122.224.69.236
    Source: unknownTCP traffic detected without corresponding DNS query: 186.80.70.220
    Source: unknownTCP traffic detected without corresponding DNS query: 255.184.148.169
    Source: unknownTCP traffic detected without corresponding DNS query: 79.70.199.5
    Source: unknownTCP traffic detected without corresponding DNS query: 222.165.116.129
    Source: unknownTCP traffic detected without corresponding DNS query: 94.5.75.117
    Source: unknownTCP traffic detected without corresponding DNS query: 208.30.158.0
    Source: unknownTCP traffic detected without corresponding DNS query: 118.37.220.185
    Source: unknownTCP traffic detected without corresponding DNS query: 221.26.196.176
    Source: unknownTCP traffic detected without corresponding DNS query: 160.119.26.52
    Source: unknownTCP traffic detected without corresponding DNS query: 191.148.55.190
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: /tmp/61KiF94nKN (PID: 5226)SIGKILL sent: pid: 936, result: successful
    Source: /tmp/61KiF94nKN (PID: 5232)SIGKILL sent: pid: 5266, result: successful
    Source: /tmp/61KiF94nKN (PID: 5232)SIGKILL sent: pid: 5269, result: successful
    Source: classification engineClassification label: mal72.troj.lin@0/2@13/0
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5261/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5261/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5262/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5262/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5264/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5264/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5266/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2033/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2033/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1582/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1582/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2275/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2275/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5260/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5260/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1612/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1612/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1579/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1579/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1699/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1699/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1335/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1335/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1698/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1698/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2028/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2028/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1334/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1334/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1576/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1576/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2302/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2302/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/3236/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/3236/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2025/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2025/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2146/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2146/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5258/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5258/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5259/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5259/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/912/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/912/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/759/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/759/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2307/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2307/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/918/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/918/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1594/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1594/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2285/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2285/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2281/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2281/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1349/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1349/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1623/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1623/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/761/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/761/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1622/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1622/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/884/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/884/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1983/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1983/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2038/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2038/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1586/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1586/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1465/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1465/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1344/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1344/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1860/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1860/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1463/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1463/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2156/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2156/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/800/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/800/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/5269/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/801/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/801/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1629/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1629/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1627/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1627/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1900/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1900/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/491/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/491/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/491/exe
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2294/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2294/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2050/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/2050/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1877/fd
    Source: /tmp/61KiF94nKN (PID: 5232)File opened: /proc/1877/fd

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37334
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37340
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37348
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37356
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37364
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37376
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37416
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39298
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39318
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39320
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39326
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39328
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39334
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39336
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39340
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39338
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39344
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39360
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39352
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39460
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39552
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39690
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39712
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39782
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46008
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46052
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46068
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46086
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46096
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46108
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46130
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46144
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46164
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46210
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33984
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 33998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34002
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34010
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34012
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34022
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34044
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34046
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34058
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34062
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34064
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34082
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34090
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34108
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34114
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34116
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34142
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34162
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34172
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34210
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34226
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34274
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34278
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34288
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 34314
    Source: /tmp/61KiF94nKN (PID: 5224)Queries kernel information via 'uname':
    Source: 61KiF94nKN, 5224.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5226.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5265.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5266.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5269.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5276.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5272.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5227.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5232.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5233.1.00000000af324111.000000003135ad2c.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
    Source: 61KiF94nKN, 5224.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5226.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5265.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5266.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5269.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5276.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5272.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5227.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5232.1.00000000af324111.000000003135ad2c.rw-.sdmp, 61KiF94nKN, 5233.1.00000000af324111.000000003135ad2c.rw-.sdmpBinary or memory string: &4V!/etc/qemu-binfmt/sparc
    Source: 61KiF94nKN, 5224.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5226.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5265.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5266.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5269.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5276.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5272.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5227.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5232.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5233.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmpBinary or memory string: !x86_64/usr/bin/qemu-sparc/tmp/61KiF94nKNSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/61KiF94nKN
    Source: 61KiF94nKN, 5224.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5226.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5265.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5266.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5269.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5276.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5272.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5227.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5232.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmp, 61KiF94nKN, 5233.1.0000000028cb689c.00000000ff2bb44d.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1Security Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol2SIM Card SwapCarrier Billing Fraud

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 533998 Sample: 61KiF94nKN Startdate: 04/12/2021 Architecture: LINUX Score: 72 64 xia.ddcch4ckserver.top 2->64 66 209.198.18.216, 23 ZOOMTCUS United States 2->66 68 99 other IPs or domains 2->68 70 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->70 72 Multi AV Scanner detection for submitted file 2->72 74 Yara detected Mirai 2->74 76 2 other signatures 2->76 12 61KiF94nKN 2->12         started        14 systemd sshd 2->14         started        16 systemd sshd 2->16         started        signatures3 process4 process5 18 61KiF94nKN 12->18         started        20 61KiF94nKN 12->20         started        22 61KiF94nKN 12->22         started        process6 24 61KiF94nKN 18->24         started        26 61KiF94nKN 18->26         started        28 61KiF94nKN 20->28         started        30 61KiF94nKN 20->30         started        32 61KiF94nKN 20->32         started        process7 34 61KiF94nKN 24->34         started        36 61KiF94nKN 24->36         started        38 61KiF94nKN 24->38         started        40 61KiF94nKN 28->40         started        42 61KiF94nKN 28->42         started        process8 44 61KiF94nKN 34->44         started        46 61KiF94nKN 34->46         started        48 61KiF94nKN 36->48         started        50 61KiF94nKN 36->50         started        52 61KiF94nKN 40->52         started        54 61KiF94nKN 42->54         started        process9 56 61KiF94nKN 44->56         started        58 61KiF94nKN 52->58         started        60 61KiF94nKN 52->60         started        process10 62 61KiF94nKN 58->62         started       

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    61KiF94nKN37%VirustotalBrowse
    61KiF94nKN40%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    SourceDetectionScannerLabelLink
    xia.ddcch4ckserver.top13%VirustotalBrowse

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    xia.ddcch4ckserver.top
    107.189.5.196
    truetrueunknown

    Contacted IPs

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Public

    IPDomainCountryFlagASNASN NameMalicious
    246.249.140.98
    unknownReserved
    unknownunknownfalse
    170.45.110.90
    unknownUnited States
    264957CoopercitrusCooperativadeProdutoresRuraisBRfalse
    47.252.160.8
    unknownUnited States
    45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
    60.98.164.176
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    243.254.229.225
    unknownReserved
    unknownunknownfalse
    5.218.173.229
    unknownIran (ISLAMIC Republic Of)
    197207MCCI-ASIRfalse
    185.65.70.223
    unknownTurkey
    201735PROPHASE-ASESfalse
    168.71.172.254
    unknownUnited States
    7018ATT-INTERNET4USfalse
    163.112.118.125
    unknownFrance
    17816CHINA169-GZChinaUnicomIPnetworkChina169Guangdongprovifalse
    68.151.112.93
    unknownCanada
    6327SHAWCAfalse
    133.89.64.217
    unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
    244.197.160.238
    unknownReserved
    unknownunknownfalse
    211.188.243.31
    unknownKorea Republic of
    9644SKTELECOM-NET-ASSKTelecomKRfalse
    80.124.79.187
    unknownFrance
    15557LDCOMNETFRfalse
    73.10.41.195
    unknownUnited States
    7922COMCAST-7922USfalse
    9.246.160.133
    unknownUnited States
    3356LEVEL3USfalse
    193.1.217.2
    unknownIreland
    1213HEANETIEfalse
    89.82.198.141
    unknownFrance
    5410BOUYGTEL-ISPFRfalse
    191.82.108.49
    unknownArgentina
    22927TelefonicadeArgentinaARfalse
    221.171.214.240
    unknownJapan2518BIGLOBEBIGLOBEIncJPfalse
    83.173.196.243
    unknownSwitzerland
    3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
    157.213.248.246
    unknownUnited States
    4704SANNETRakutenMobileIncJPfalse
    81.132.68.181
    unknownUnited Kingdom
    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
    23.224.58.144
    unknownUnited States
    40065CNSERVERSUSfalse
    68.131.63.99
    unknownUnited States
    701UUNETUSfalse
    185.167.210.138
    unknownCzech Republic
    199657TOUSKOVNETCZfalse
    74.112.219.16
    unknownUnited States
    46132VENTYX-AN-ABB-COMPANYUSfalse
    158.220.98.141
    unknownSwitzerland
    8556LEVANTISCHfalse
    90.216.180.27
    unknownUnited Kingdom
    5607BSKYB-BROADBAND-ASGBfalse
    38.89.204.151
    unknownUnited States
    174COGENT-174USfalse
    254.94.23.229
    unknownReserved
    unknownunknownfalse
    62.200.46.62
    unknownEuropean Union
    2686ATGS-MMD-ASUSfalse
    59.51.33.190
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    143.28.20.34
    unknownUnited States
    264008LANCAMANTOANISERVICOSDEINFORMATICALTDA-MEBRfalse
    241.155.183.174
    unknownReserved
    unknownunknownfalse
    45.234.130.236
    unknownBrazil
    267365GigaTecnologiaemRedeseInternetEIRELIBRfalse
    165.193.73.81
    unknownUnited States
    3561CENTURYLINK-LEGACY-SAVVISUSfalse
    48.185.159.34
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    135.93.177.171
    unknownUnited States
    10455LUCENT-CIOUSfalse
    41.228.193.93
    unknownTunisia
    37693TUNISIANATNfalse
    142.5.110.19
    unknownCanada
    46606UNIFIEDLAYER-AS-1USfalse
    163.61.118.81
    unknownunknown
    2516KDDIKDDICORPORATIONJPfalse
    62.191.178.99
    unknownUnited Kingdom
    5586MCI-INTGBfalse
    125.175.21.204
    unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
    120.113.153.90
    unknownTaiwan; Republic of China (ROC)
    17716NTU-TWNationalTaiwanUniversityTWfalse
    171.113.147.123
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    135.46.199.217
    unknownUnited States
    54614CIKTELECOM-CABLECAfalse
    166.149.86.237
    unknownUnited States
    22394CELLCOUSfalse
    8.138.12.41
    unknownSingapore
    37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
    243.192.141.18
    unknownReserved
    unknownunknownfalse
    192.237.118.230
    unknownUnited States
    393238IMONCUSfalse
    189.227.127.163
    unknownMexico
    8151UninetSAdeCVMXfalse
    138.238.166.203
    unknownUnited States
    33084DC-NETUSfalse
    2.134.183.227
    unknownKazakhstan
    9198KAZTELECOM-ASKZfalse
    161.2.40.141
    unknownUnited Kingdom
    15914BritishAirwaysGBfalse
    173.154.95.216
    unknownUnited States
    10507SPCSUSfalse
    173.118.241.83
    unknownUnited States
    10507SPCSUSfalse
    115.234.54.210
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    222.124.195.220
    unknownIndonesia
    17974TELKOMNET-AS2-APPTTelekomunikasiIndonesiaIDfalse
    105.16.125.186
    unknownMauritius
    37100SEACOM-ASMUfalse
    255.1.14.8
    unknownReserved
    unknownunknownfalse
    147.59.82.120
    unknownUnited States
    1533DNIC-AS-01533USfalse
    160.176.253.216
    unknownMorocco
    36903MT-MPLSMAfalse
    141.228.157.156
    unknownUnited Kingdom
    12701BARCAPLondonGBfalse
    109.146.97.99
    unknownUnited Kingdom
    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
    77.229.193.246
    unknownSpain
    12430VODAFONE_ESESfalse
    205.213.14.73
    unknownUnited States
    2381WISCNET1-ASUSfalse
    85.33.215.213
    unknownItaly
    3269ASN-IBSNAZITfalse
    84.116.116.153
    unknownNetherlands
    6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
    161.252.120.236
    unknownKuwait
    42781ZNETAS-KWfalse
    123.179.22.94
    unknownChina
    4809CHINATELECOM-CORE-WAN-CN2ChinaTelecomNextGenerationCarrfalse
    194.215.184.123
    unknownFinland
    1759TSF-IP-CORETeliaFinlandOyjEUfalse
    146.24.187.201
    unknownUnited States
    197938TRAVIANGAMESDEfalse
    44.79.138.141
    unknownUnited States
    7377UCSDUSfalse
    99.190.186.31
    unknownUnited States
    7018ATT-INTERNET4USfalse
    119.47.10.35
    unknownJapan55385DADigitalAllianceCoLtdJPfalse
    145.25.161.151
    unknownNetherlands
    1103SURFNET-NLSURFnetTheNetherlandsNLfalse
    177.185.203.216
    unknownBrazil
    28299IPV6InternetLtdaBRfalse
    110.62.148.219
    unknownChina
    9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
    213.198.183.239
    unknownItaly
    15589ASN-CLOUDITALIAITfalse
    97.82.62.213
    unknownUnited States
    20115CHARTER-20115USfalse
    14.45.175.64
    unknownKorea Republic of
    4766KIXS-AS-KRKoreaTelecomKRfalse
    95.194.248.76
    unknownSweden
    3301TELIANET-SWEDENTeliaCompanySEfalse
    209.198.18.216
    unknownUnited States
    31996ZOOMTCUSfalse
    85.40.82.1
    unknownItaly
    3269ASN-IBSNAZITfalse
    70.37.55.85
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    98.155.194.88
    unknownUnited States
    20001TWC-20001-PACWESTUSfalse
    18.125.179.241
    unknownUnited States
    3MIT-GATEWAYSUSfalse
    148.43.100.233
    unknownUnited States
    6400CompaniaDominicanadeTelefonosSADOfalse
    19.44.33.247
    unknownUnited States
    3MIT-GATEWAYSUSfalse
    219.181.80.241
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    89.207.8.195
    unknownSwitzerland
    31662KNSURSELVAKommunikationsNetzSurselvaCHfalse
    35.198.202.160
    unknownUnited States
    15169GOOGLEUSfalse
    43.133.6.103
    unknownJapan4249LILLY-ASUSfalse
    53.71.21.3
    unknownGermany
    31399DAIMLER-ASITIGNGlobalNetworkDEfalse
    113.19.180.129
    unknownIndia
    23772ORTELNET-ASMsOrtelCommunicationsLtdINfalse
    194.12.240.1
    unknownBulgaria
    8262EVOLINK-ASBGfalse
    253.82.17.118
    unknownReserved
    unknownunknownfalse
    218.124.198.24
    unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
    92.98.39.146
    unknownUnited Arab Emirates
    5384EMIRATES-INTERNETEmiratesInternetAEfalse


    Runtime Messages

    Command:/tmp/61KiF94nKN
    Exit Code:0
    Exit Code Info:
    Killed:False
    Standard Output:
    Infected By Akiru
    Standard Error:

    Joe Sandbox View / Context

    IPs

    MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
    254.94.23.229Darknet.x86Get hashmaliciousBrowse
      211.188.243.313DAMhv0DFIGet hashmaliciousBrowse
        193.1.217.2X5bKvoLX1EGet hashmaliciousBrowse

          Domains

          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
          xia.ddcch4ckserver.topGuSrMsLH0yGet hashmaliciousBrowse
          • 107.189.5.196
          e8cvIYg1a3Get hashmaliciousBrowse
          • 107.189.5.196
          wCEe6Y5TGIGet hashmaliciousBrowse
          • 107.189.5.196
          Xp9AXIBaBpGet hashmaliciousBrowse
          • 107.189.5.196

          ASN

          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
          CoopercitrusCooperativadeProdutoresRuraisBRsora.x86Get hashmaliciousBrowse
          • 170.37.47.60
          l8np4x8FGLGet hashmaliciousBrowse
          • 170.40.43.249
          ZOi52gHoIYGet hashmaliciousBrowse
          • 170.40.43.244
          M0ek1k58Q3Get hashmaliciousBrowse
          • 170.41.140.221
          KKveTTgaAAsecNNaaaa.x86-20211122-0650Get hashmaliciousBrowse
          • 170.1.225.236
          6L1AGNUMgkGet hashmaliciousBrowse
          • 170.45.183.59
          mfFr814HupGet hashmaliciousBrowse
          • 170.40.43.210
          4i9Yl7vp8BGet hashmaliciousBrowse
          • 170.40.43.243
          8cpsKRnU4rGet hashmaliciousBrowse
          • 170.45.183.54
          K1kUt3MxkSGet hashmaliciousBrowse
          • 170.0.2.234
          bRQTHkekvvGet hashmaliciousBrowse
          • 170.43.8.208
          RJHE1O7ZBFGet hashmaliciousBrowse
          • 170.45.183.15
          HT7gBWexDXGet hashmaliciousBrowse
          • 170.45.183.36
          DGxCnji49SGet hashmaliciousBrowse
          • 170.45.134.66
          iQGF9sgxaBGet hashmaliciousBrowse
          • 170.44.221.217
          z0x3n.x86-20211110-2150Get hashmaliciousBrowse
          • 170.36.107.18
          pt7DJSPfnaGet hashmaliciousBrowse
          • 170.37.13.129
          QsSD7q2BROGet hashmaliciousBrowse
          • 170.45.109.60
          sora.armGet hashmaliciousBrowse
          • 170.40.43.246
          wRmHCEnowIGet hashmaliciousBrowse
          • 170.40.43.214
          GIGAINFRASoftbankBBCorpJPGuSrMsLH0yGet hashmaliciousBrowse
          • 221.75.228.134
          wCEe6Y5TGIGet hashmaliciousBrowse
          • 220.0.129.221
          arm7Get hashmaliciousBrowse
          • 218.121.111.189
          x86Get hashmaliciousBrowse
          • 221.87.19.65
          armGet hashmaliciousBrowse
          • 126.22.226.224
          rELGr0VELqGet hashmaliciousBrowse
          • 126.165.234.100
          ThhBCrYJCmGet hashmaliciousBrowse
          • 221.73.91.128
          R5UqytMpoFGet hashmaliciousBrowse
          • 126.25.240.2
          sora.x86Get hashmaliciousBrowse
          • 220.19.206.59
          sora.arm7Get hashmaliciousBrowse
          • 221.87.68.14
          sora.armGet hashmaliciousBrowse
          • 126.180.101.68
          OhDPOb1tfBGet hashmaliciousBrowse
          • 126.215.126.182
          b3astmode.arm7Get hashmaliciousBrowse
          • 221.17.155.132
          b3astmode.armGet hashmaliciousBrowse
          • 221.28.251.112
          tPC6yuAhscGet hashmaliciousBrowse
          • 126.98.144.148
          sora.x86Get hashmaliciousBrowse
          • 126.195.188.132
          0VIoO2ovmFGet hashmaliciousBrowse
          • 220.1.225.135
          6Zcc7k2JZyGet hashmaliciousBrowse
          • 60.86.254.14
          nKv4cxjIx6Get hashmaliciousBrowse
          • 219.18.123.200
          apep.arm7Get hashmaliciousBrowse
          • 160.24.170.153
          CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC780426DE24AE46F300FDAF9CBF597C8F2164F7B6C525C.exeGet hashmaliciousBrowse
          • 47.251.42.216
          Kq8hjfiv87.exeGet hashmaliciousBrowse
          • 47.251.42.216
          C7304FF0966068D305DA031F9DA60C5B0EBE32AC43533.exeGet hashmaliciousBrowse
          • 47.251.42.216
          armGet hashmaliciousBrowse
          • 8.208.25.42
          f2Y03RRaRe.exeGet hashmaliciousBrowse
          • 8.209.79.122
          DrC7J6YQnm.exeGet hashmaliciousBrowse
          • 8.209.71.17
          tips-5067550674.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          tips920293137.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          tips920293137.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          156219029342206-107-0_attach.1.payment 264494490.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          NVTNgwAjOKGet hashmaliciousBrowse
          • 8.212.11.154
          RFQ-CIF DT22.docGet hashmaliciousBrowse
          • 47.241.96.113
          order 4544471372.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          order 4544471372.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          SecuriteInfo.com.Heur.31616.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          SecuriteInfo.com.Heur.26641.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          SecuriteInfo.com.Heur.5035.docGet hashmaliciousBrowse
          • 8.209.79.68
          SecuriteInfo.com.Heur.6074.docGet hashmaliciousBrowse
          • 8.209.79.68
          plans_48055147646.xlsGet hashmaliciousBrowse
          • 149.129.254.152
          plans_48055147646.xlsGet hashmaliciousBrowse
          • 149.129.254.152

          JA3 Fingerprints

          No context

          Dropped Files

          No context

          Created / dropped Files

          /proc/5264/oom_score_adj
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):6
          Entropy (8bit):1.7924812503605778
          Encrypted:false
          SSDEEP:3:ptn:Dn
          MD5:CBF282CC55ED0792C33D10003D1F760A
          SHA1:007DD8BD75468E6B7ABA4285E9B267202C7EAEED
          SHA-256:FCDBAB99FCC0F4409E5F9D7D6FC497780288B4C441698126BB62832412774D22
          SHA-512:4643A8675D213C7DA35CC0C2BFB3B6F20324F9C48AEA7BA79F470615698C9A0CEFDA45CAA1957FC29110EE746BC8458AB8AB1E43EB513912A5E1E8858812CC00
          Malicious:false
          Reputation:high, very likely benign file
          Preview: -1000.
          /run/sshd.pid
          Process:/usr/sbin/sshd
          File Type:ASCII text
          Category:dropped
          Size (bytes):5
          Entropy (8bit):2.321928094887362
          Encrypted:false
          SSDEEP:3:Ct:Ct
          MD5:ED62F87F4EC9699FDAD6BAFEFC371E3D
          SHA1:F14CB0851A26C184C7614A62326934CBFDA85155
          SHA-256:EB4EE1B62A4108FE56E980DC18F22FA746F5060A5265EA1E101CB5CBA1F6F43E
          SHA-512:C3111F12F3B9DF49EBC63F082C6B267AE6DB6AC567E258584F5C8883B17DC683CE947F9BBF8E99F706C31ECB1B74EA7D6BCEA9F8F2D0BC668DF14123EF6B246B
          Malicious:false
          Reputation:moderate, very likely benign file
          Preview: 5264.

          Static File Info

          General

          File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
          Entropy (8bit):6.009298823803464
          TrID:
          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
          File name:61KiF94nKN
          File size:66380
          MD5:06d58f655cb40ee644bd74e19483ba8b
          SHA1:84a92f7b7855ef9f1ec12e10ef38b3bc7045d903
          SHA256:e0f8643b2d10593678b16fdaab7bc4a070cdbe4a8a617b0a37bda328f4002235
          SHA512:c1f7006c3f4a845df1b582b2fb6fcdfe83a033b8dd7cb9c7cde7afbcbce3ac57a467feda72f1c77d44843f05ca725ce50d6db93edf61f7680d247ca3258a4bc4
          SSDEEP:1536:0dn1Jb3SdNySlmbWfuPA+CbsyGjoycpbY+WJ:suv1sbWfu4Tsffcp0+WJ
          File Content Preview:.ELF...........................4.........4. ...(....................... ... ...........................|............dt.Q................................@..(....@.<.................#.....a...`.....!..... ...@.....".........`......$ ... ...@...........`....

          Static ELF Info

          ELF header

          Class:ELF32
          Data:2's complement, big endian
          Version:1 (current)
          Machine:Sparc
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - System V
          ABI Version:0
          Entry Point Address:0x101a4
          Flags:0x0
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:3
          Section Header Offset:65980
          Section Header Size:40
          Number of Section Headers:10
          Header String Table Index:9

          Sections

          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
          NULL0x00x00x00x00x0000
          .initPROGBITS0x100940x940x1c0x00x6AX004
          .textPROGBITS0x100b00xb00xf3e80x00x6AX004
          .finiPROGBITS0x1f4980xf4980x140x00x6AX004
          .rodataPROGBITS0x1f4b00xf4b00x8700x00x2A008
          .ctorsPROGBITS0x200000x100000x80x00x3WA004
          .dtorsPROGBITS0x200080x100080x80x00x3WA004
          .dataPROGBITS0x200180x100180x1640x00x3WA008
          .bssNOBITS0x201800x1017c0x3100x00x3WA008
          .shstrtabSTRTAB0x00x1017c0x3e0x00x0001

          Program Segments

          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00x100000x100000xfd200xfd203.31930x5R E0x10000.init .text .fini .rodata
          LOAD0x100000x200000x200000x17c0x4900.43070x6RW 0x10000.ctors .dtors .data .bss
          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

          Network Behavior

          Network Port Distribution

          TCP Packets

          TimestampSource PortDest PortSource IPDest IP
          Dec 4, 2021 22:45:34.410459995 CET478563175192.168.2.23107.189.5.196
          Dec 4, 2021 22:45:34.439884901 CET317547856107.189.5.196192.168.2.23
          Dec 4, 2021 22:45:34.440021992 CET478563175192.168.2.23107.189.5.196
          Dec 4, 2021 22:45:34.440248013 CET478563175192.168.2.23107.189.5.196
          Dec 4, 2021 22:45:34.469099045 CET317547856107.189.5.196192.168.2.23
          Dec 4, 2021 22:45:34.469194889 CET478563175192.168.2.23107.189.5.196
          Dec 4, 2021 22:45:34.488081932 CET2050123192.168.2.23248.193.244.74
          Dec 4, 2021 22:45:34.488213062 CET2050123192.168.2.23182.30.202.74
          Dec 4, 2021 22:45:34.488331079 CET2050123192.168.2.2320.170.254.210
          Dec 4, 2021 22:45:34.488363028 CET2050123192.168.2.23217.222.231.113
          Dec 4, 2021 22:45:34.488392115 CET2050123192.168.2.2342.200.189.153
          Dec 4, 2021 22:45:34.488398075 CET2050123192.168.2.23144.57.51.77
          Dec 4, 2021 22:45:34.488399982 CET2050123192.168.2.23154.26.157.215
          Dec 4, 2021 22:45:34.488399982 CET2050123192.168.2.2378.244.182.235
          Dec 4, 2021 22:45:34.488426924 CET2050123192.168.2.23175.76.251.170
          Dec 4, 2021 22:45:34.488524914 CET2050123192.168.2.23162.167.22.164
          Dec 4, 2021 22:45:34.488684893 CET2050123192.168.2.23147.174.188.3
          Dec 4, 2021 22:45:34.488699913 CET2050123192.168.2.23247.30.146.27
          Dec 4, 2021 22:45:34.488746881 CET2050123192.168.2.2384.163.75.219
          Dec 4, 2021 22:45:34.488754034 CET2050123192.168.2.2386.231.94.30
          Dec 4, 2021 22:45:34.488761902 CET2050123192.168.2.2365.54.249.74
          Dec 4, 2021 22:45:34.488817930 CET2050123192.168.2.23148.124.160.183
          Dec 4, 2021 22:45:34.488969088 CET2050123192.168.2.23219.149.150.55
          Dec 4, 2021 22:45:34.488981009 CET2050123192.168.2.2341.108.222.11
          Dec 4, 2021 22:45:34.489058971 CET2050123192.168.2.23107.112.201.203
          Dec 4, 2021 22:45:34.489156961 CET2050123192.168.2.238.46.29.60
          Dec 4, 2021 22:45:34.489168882 CET2050123192.168.2.2362.3.116.251
          Dec 4, 2021 22:45:34.489172935 CET2050123192.168.2.23177.206.148.136
          Dec 4, 2021 22:45:34.489187956 CET2050123192.168.2.23165.130.187.97
          Dec 4, 2021 22:45:34.489317894 CET2050123192.168.2.23198.52.223.117
          Dec 4, 2021 22:45:34.489336014 CET2050123192.168.2.2379.205.208.191
          Dec 4, 2021 22:45:34.489345074 CET2050123192.168.2.2338.142.35.158
          Dec 4, 2021 22:45:34.489389896 CET2050123192.168.2.23217.16.189.179
          Dec 4, 2021 22:45:34.489413023 CET2050123192.168.2.23194.15.246.151
          Dec 4, 2021 22:45:34.489438057 CET2050123192.168.2.2324.21.13.6
          Dec 4, 2021 22:45:34.489563942 CET2050123192.168.2.23162.2.210.17
          Dec 4, 2021 22:45:34.489590883 CET2050123192.168.2.23219.178.164.254
          Dec 4, 2021 22:45:34.489603043 CET2050123192.168.2.2375.114.192.193
          Dec 4, 2021 22:45:34.489629984 CET2050123192.168.2.2312.184.52.122
          Dec 4, 2021 22:45:34.489639997 CET2050123192.168.2.23219.106.239.212
          Dec 4, 2021 22:45:34.489686012 CET2050123192.168.2.23139.242.243.69
          Dec 4, 2021 22:45:34.489737034 CET2050123192.168.2.23184.59.166.130
          Dec 4, 2021 22:45:34.489785910 CET2050123192.168.2.23205.127.95.157
          Dec 4, 2021 22:45:34.489914894 CET2050123192.168.2.23146.62.124.63
          Dec 4, 2021 22:45:34.489996910 CET2050123192.168.2.2335.56.18.171
          Dec 4, 2021 22:45:34.490010023 CET2050123192.168.2.23211.176.55.53
          Dec 4, 2021 22:45:34.490026951 CET2050123192.168.2.23122.224.69.236
          Dec 4, 2021 22:45:34.490058899 CET2050123192.168.2.23186.80.70.220
          Dec 4, 2021 22:45:34.490073919 CET2050123192.168.2.23255.184.148.169
          Dec 4, 2021 22:45:34.490091085 CET2050123192.168.2.2379.70.199.5
          Dec 4, 2021 22:45:34.490104914 CET2050123192.168.2.23222.165.116.129
          Dec 4, 2021 22:45:34.490117073 CET2050123192.168.2.2394.5.75.117
          Dec 4, 2021 22:45:34.490180016 CET2050123192.168.2.23208.30.158.0
          Dec 4, 2021 22:45:34.490200043 CET2050123192.168.2.23118.37.220.185
          Dec 4, 2021 22:45:34.490255117 CET2050123192.168.2.23221.26.196.176
          Dec 4, 2021 22:45:34.490299940 CET2050123192.168.2.23160.119.26.52
          Dec 4, 2021 22:45:34.490324974 CET2050123192.168.2.23191.148.55.190
          Dec 4, 2021 22:45:34.490372896 CET2050123192.168.2.23197.98.116.127
          Dec 4, 2021 22:45:34.490405083 CET2050123192.168.2.23244.146.147.1
          Dec 4, 2021 22:45:34.490411997 CET2050123192.168.2.2354.11.13.132
          Dec 4, 2021 22:45:34.490427017 CET2050123192.168.2.23147.189.82.55
          Dec 4, 2021 22:45:34.490470886 CET2050123192.168.2.23110.42.16.236
          Dec 4, 2021 22:45:34.490485907 CET2050123192.168.2.2348.1.91.144
          Dec 4, 2021 22:45:34.490489006 CET2050123192.168.2.23190.105.59.8
          Dec 4, 2021 22:45:34.490514040 CET2050123192.168.2.2365.173.100.107
          Dec 4, 2021 22:45:34.490528107 CET2050123192.168.2.23181.147.251.118
          Dec 4, 2021 22:45:34.490782022 CET2050123192.168.2.2367.10.193.232
          Dec 4, 2021 22:45:34.490835905 CET2050123192.168.2.23157.226.68.20
          Dec 4, 2021 22:45:34.490860939 CET2050123192.168.2.23198.81.182.95
          Dec 4, 2021 22:45:34.490869999 CET2050123192.168.2.2377.98.224.151
          Dec 4, 2021 22:45:34.491029024 CET2050123192.168.2.2374.232.6.86
          Dec 4, 2021 22:45:34.491049051 CET2050123192.168.2.23221.238.143.8
          Dec 4, 2021 22:45:34.491050959 CET2050123192.168.2.23217.63.27.189
          Dec 4, 2021 22:45:34.491071939 CET2050123192.168.2.2384.99.94.108
          Dec 4, 2021 22:45:34.491096020 CET2050123192.168.2.2392.13.52.23
          Dec 4, 2021 22:45:34.491103888 CET2050123192.168.2.23108.162.86.130
          Dec 4, 2021 22:45:34.491199017 CET2050123192.168.2.23204.55.70.130
          Dec 4, 2021 22:45:34.491277933 CET2050123192.168.2.23199.119.255.193
          Dec 4, 2021 22:45:34.491390944 CET2050123192.168.2.23104.170.68.59
          Dec 4, 2021 22:45:34.491410971 CET2050123192.168.2.2390.97.94.152
          Dec 4, 2021 22:45:34.491425991 CET2050123192.168.2.23165.174.15.118
          Dec 4, 2021 22:45:34.491439104 CET2050123192.168.2.2361.104.64.148
          Dec 4, 2021 22:45:34.491452932 CET2050123192.168.2.23218.162.113.198
          Dec 4, 2021 22:45:34.491466045 CET2050123192.168.2.2342.200.244.240
          Dec 4, 2021 22:45:34.491481066 CET2050123192.168.2.23111.107.17.158
          Dec 4, 2021 22:45:34.491534948 CET2050123192.168.2.23177.38.223.139
          Dec 4, 2021 22:45:34.491554976 CET2050123192.168.2.2313.2.160.160
          Dec 4, 2021 22:45:34.491584063 CET2050123192.168.2.23204.160.232.196
          Dec 4, 2021 22:45:34.491616011 CET2050123192.168.2.2312.238.221.189
          Dec 4, 2021 22:45:34.491662979 CET2050123192.168.2.23246.54.140.13
          Dec 4, 2021 22:45:34.491723061 CET2050123192.168.2.23164.208.182.69
          Dec 4, 2021 22:45:34.491760015 CET2050123192.168.2.23251.108.61.171
          Dec 4, 2021 22:45:34.491836071 CET2050123192.168.2.2363.37.121.122
          Dec 4, 2021 22:45:34.491846085 CET2050123192.168.2.23110.192.141.151
          Dec 4, 2021 22:45:34.491887093 CET2050123192.168.2.2399.162.195.67
          Dec 4, 2021 22:45:34.491902113 CET2050123192.168.2.2324.224.53.184
          Dec 4, 2021 22:45:34.491949081 CET2050123192.168.2.232.162.30.179
          Dec 4, 2021 22:45:34.492008924 CET2050123192.168.2.23188.69.83.158
          Dec 4, 2021 22:45:34.492062092 CET2050123192.168.2.23180.68.210.119
          Dec 4, 2021 22:45:34.492064953 CET2050123192.168.2.23179.200.223.50

          DNS Queries

          TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
          Dec 4, 2021 22:45:34.386389017 CET192.168.2.238.8.8.80xba5aStandard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:45:42.784358025 CET192.168.2.238.8.8.80xba5aStandard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:45:42.874461889 CET192.168.2.238.8.8.80xba5aStandard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:45:56.854185104 CET192.168.2.238.8.8.80x6ef4Standard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:46:03.318275928 CET192.168.2.238.8.8.80xd2d4Standard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:46:03.596966982 CET192.168.2.238.8.8.80x2b86Standard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:46:09.163847923 CET192.168.2.238.8.8.80xb537Standard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:46:33.807394981 CET192.168.2.238.8.8.80x477cStandard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:46:55.184551001 CET192.168.2.238.8.8.80x57bdStandard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:47:03.980705023 CET192.168.2.238.8.8.80xd143Standard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:47:04.723417997 CET192.168.2.238.8.8.80xf816Standard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:47:05.338871956 CET192.168.2.238.8.8.80x1c2cStandard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)
          Dec 4, 2021 22:47:45.619473934 CET192.168.2.238.8.8.80x203bStandard query (0)xia.ddcch4ckserver.topA (IP address)IN (0x0001)

          DNS Answers

          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
          Dec 4, 2021 22:45:34.409746885 CET8.8.8.8192.168.2.230xba5aNo error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:45:42.890985012 CET8.8.8.8192.168.2.230xba5aNo error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:45:42.895654917 CET8.8.8.8192.168.2.230xba5aNo error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:45:56.872252941 CET8.8.8.8192.168.2.230x6ef4No error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:46:03.609237909 CET8.8.8.8192.168.2.230xd2d4No error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:46:03.615993023 CET8.8.8.8192.168.2.230x2b86No error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:46:09.183428049 CET8.8.8.8192.168.2.230xb537No error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:46:34.152484894 CET8.8.8.8192.168.2.230x477cNo error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:46:55.204437017 CET8.8.8.8192.168.2.230x57bdNo error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:47:04.003648996 CET8.8.8.8192.168.2.230xd143No error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:47:04.741116047 CET8.8.8.8192.168.2.230xf816No error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:47:05.358477116 CET8.8.8.8192.168.2.230x1c2cNo error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)
          Dec 4, 2021 22:47:45.642565966 CET8.8.8.8192.168.2.230x203bNo error (0)xia.ddcch4ckserver.top107.189.5.196A (IP address)IN (0x0001)

          System Behavior

          General

          Start time:22:45:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:/tmp/61KiF94nKN
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:40
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:41
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:41
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:42
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:42
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:46:08
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:41
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:41
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:46:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:47:44
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:33
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:56
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:46:02
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:46:02
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:46:54
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:47:03
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:47:04
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:47:03
          Start date:04/12/2021
          Path:/tmp/61KiF94nKN
          Arguments:n/a
          File size:4379400 bytes
          MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

          General

          Start time:22:45:40
          Start date:04/12/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:22:45:40
          Start date:04/12/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -t
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340

          General

          Start time:22:45:40
          Start date:04/12/2021
          Path:/usr/lib/systemd/systemd
          Arguments:n/a
          File size:1620224 bytes
          MD5 hash:9b2bec7092a40488108543f9334aab75

          General

          Start time:22:45:40
          Start date:04/12/2021
          Path:/usr/sbin/sshd
          Arguments:/usr/sbin/sshd -D
          File size:876328 bytes
          MD5 hash:dbca7a6bbf7bf57fedac243d4b2cb340