Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm

Overview

General Information

Sample Name:arm
Analysis ID:557442
MD5:c8eac6c41bd5f6ec5a65524142f340e0
SHA1:ae41cee628bdacfe7dd71dd1e4ab90e71a9d0a86
SHA256:b916d6f9d2756f35b510f1e89cf54a3601b3aafdba2a506cd9e5254e0dade88e
Tags:Mirai
Infos:

Detection

Mirai Moobot
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Yara detected Moobot
Sets full permissions to files and/or directories
Yara signature match
Executes the "mkdir" command used to create folders
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "chmod" command used to modify permissions
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample has stripped symbol table
Sample tries to set the executable flag
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
Static ELF header machine description suggests that the sample might not execute correctly on this machine
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:557442
Start date:21.01.2022
Start time:06:00:31
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 0s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:arm
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal100.troj.lin@0/0@1/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/arm
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
qazwsxedc
Standard Error:
  • system is lnxubuntu20
  • arm (PID: 5201, Parent: 5115, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm
    • arm New Fork (PID: 5223, Parent: 5201)
    • sh (PID: 5223, Parent: 5201, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf bin/systemd && mkdir bin; >bin/systemd && mv /tmp/arm bin/systemd; chmod 777 bin/systemd"
      • sh New Fork (PID: 5225, Parent: 5223)
      • rm (PID: 5225, Parent: 5223, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf bin/systemd
      • sh New Fork (PID: 5226, Parent: 5223)
      • mkdir (PID: 5226, Parent: 5223, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir bin
      • sh New Fork (PID: 5227, Parent: 5223)
      • mv (PID: 5227, Parent: 5223, MD5: 504f0590fa482d4da070a702260e3716) Arguments: mv /tmp/arm bin/systemd
      • sh New Fork (PID: 5228, Parent: 5223)
      • chmod (PID: 5228, Parent: 5223, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod 777 bin/systemd
    • arm New Fork (PID: 5229, Parent: 5201)
      • arm New Fork (PID: 5231, Parent: 5229)
  • cleanup
SourceRuleDescriptionAuthorStrings
armMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
  • 0x12be8:$x1: POST /cdn-cgi/
  • 0x12168:$x3: /dev/watchdog
  • 0x122b4:$s1: LCOGQGPTGP
armMAL_ELF_LNX_Mirai_Oct10_2Detects ELF malware Mirai relatedFlorian Roth
  • 0x12be8:$c01: 50 4F 53 54 20 2F 63 64 6E 2D 63 67 69 2F 00 00 20 48 54 54 50 2F 31 2E 31 0D 0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 00 0D 0A 48 6F 73 74 3A
armJoeSecurity_MoobotYara detected MoobotJoe Security
    armJoeSecurity_Mirai_5Yara detected MiraiJoe Security
      armJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        SourceRuleDescriptionAuthorStrings
        5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
        • 0x12be8:$x1: POST /cdn-cgi/
        • 0x12168:$x3: /dev/watchdog
        • 0x122b4:$s1: LCOGQGPTGP
        5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmpMAL_ELF_LNX_Mirai_Oct10_2Detects ELF malware Mirai relatedFlorian Roth
        • 0x12be8:$c01: 50 4F 53 54 20 2F 63 64 6E 2D 63 67 69 2F 00 00 20 48 54 54 50 2F 31 2E 31 0D 0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 00 0D 0A 48 6F 73 74 3A
        5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
          5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmpJoeSecurity_Mirai_5Yara detected MiraiJoe Security
            5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
              Click to see the 1 entries

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: armAvira: detected
              Source: armVirustotal: Detection: 39%Perma Link
              Source: armReversingLabs: Detection: 50%

              Networking

              barindex
              Source: TrafficSnort IDS: 2030489 ET TROJAN ELF/MooBot Mirai DDoS Variant Server Response 95.181.161.40:55005 -> 192.168.2.23:47080
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:38814 -> 220.83.107.132:23
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38814
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38814
              Source: TrafficSnort IDS: 716 INFO TELNET access 175.203.37.237:23 -> 192.168.2.23:36270
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38842
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38842
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 175.203.37.237:23 -> 192.168.2.23:36270
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 175.203.37.237:23 -> 192.168.2.23:36270
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38882
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38882
              Source: TrafficSnort IDS: 716 INFO TELNET access 175.203.37.237:23 -> 192.168.2.23:36320
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 175.203.37.237:23 -> 192.168.2.23:36320
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 175.203.37.237:23 -> 192.168.2.23:36320
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38892
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38892
              Source: TrafficSnort IDS: 716 INFO TELNET access 211.119.241.133:23 -> 192.168.2.23:56018
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47332
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43120
              Source: TrafficSnort IDS: 716 INFO TELNET access 175.203.37.237:23 -> 192.168.2.23:36334
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47332
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38900
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38900
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47342
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43128
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 175.203.37.237:23 -> 192.168.2.23:36334
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 175.203.37.237:23 -> 192.168.2.23:36334
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47342
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43130
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47352
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:47352 -> 200.182.98.209:23
              Source: TrafficSnort IDS: 716 INFO TELNET access 175.203.37.237:23 -> 192.168.2.23:36352
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:36352 -> 175.203.37.237:23
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43150
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47352
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38914
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38914
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47382
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 175.203.37.237:23 -> 192.168.2.23:36352
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 175.203.37.237:23 -> 192.168.2.23:36352
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43168
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47382
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43182
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47402
              Source: TrafficSnort IDS: 716 INFO TELNET access 211.119.241.133:23 -> 192.168.2.23:56092
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:47402 -> 200.182.98.209:23
              Source: TrafficSnort IDS: 716 INFO TELNET access 175.203.37.237:23 -> 192.168.2.23:36404
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43194
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47402
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38966
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38966
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 175.203.37.237:23 -> 192.168.2.23:36404
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 175.203.37.237:23 -> 192.168.2.23:36404
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43196
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47414
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47414
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43204
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47424
              Source: TrafficSnort IDS: 716 INFO TELNET access 175.203.37.237:23 -> 192.168.2.23:36422
              Source: TrafficSnort IDS: 716 INFO TELNET access 14.33.224.31:23 -> 192.168.2.23:43214
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:38988
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:38988
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47424
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 175.203.37.237:23 -> 192.168.2.23:36422
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 175.203.37.237:23 -> 192.168.2.23:36422
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:57684 -> 171.103.146.187:23
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47458
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:47458 -> 200.182.98.209:23
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47458
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:39034 -> 220.83.107.132:23
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47476
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:37442 -> 188.170.132.248:23
              Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 220.83.107.132:23 -> 192.168.2.23:39034
              Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 220.83.107.132:23 -> 192.168.2.23:39034
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47476
              Source: TrafficSnort IDS: 716 INFO TELNET access 211.119.241.133:23 -> 192.168.2.23:56176
              Source: TrafficSnort IDS: 716 INFO TELNET access 200.182.98.209:23 -> 192.168.2.23:47500
              Source: TrafficSnort IDS: 716 INFO TELNET access 175.203.37.237:23 -> 192.168.2.23:36526
              Source: TrafficSnort IDS: 492 INFO TELNET login failed 200.182.98.209:23 -> 192.168.2.23:47500
              Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:36526 -> 175.203.37.237:23
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 119.202.14.199:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 110.66.24.210:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 212.75.120.245:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 195.199.169.97:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 134.186.6.145:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 108.217.29.81:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 73.131.122.187:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 129.244.223.61:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 72.96.34.184:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 66.75.206.83:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 209.227.67.56:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 189.250.33.177:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 89.76.23.231:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 164.209.153.188:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 188.36.29.232:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 94.227.101.144:2323
              Source: global trafficTCP traffic: 192.168.2.23:47080 -> 95.181.161.40:55005
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 13.149.76.24:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 175.209.167.191:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 58.31.160.53:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 14.76.176.203:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 165.2.254.41:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 157.204.78.173:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 132.202.223.186:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 212.97.166.177:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 126.34.6.61:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 211.203.6.56:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 213.211.68.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 211.124.62.148:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 58.196.208.154:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 88.106.34.40:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 41.48.30.55:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 180.202.194.106:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 147.13.67.111:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 78.83.175.148:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 169.68.115.128:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 128.167.53.10:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 61.211.97.49:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 43.88.176.97:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 53.224.170.145:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 8.22.246.96:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 37.223.36.130:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 98.86.114.50:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 161.240.122.163:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 98.246.2.248:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 116.159.170.153:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 35.114.7.220:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 136.206.119.139:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 20.64.64.198:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 186.95.83.155:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 19.200.124.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 50.32.235.243:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 19.216.22.91:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 222.32.132.103:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 73.49.183.128:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 193.222.148.245:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 207.114.19.59:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 79.159.64.234:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 222.217.248.94:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 115.232.226.51:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 25.153.217.202:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 36.59.244.131:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 93.49.241.53:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 100.197.93.137:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 147.163.82.69:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 170.241.229.156:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 41.210.85.93:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 109.48.158.14:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 76.237.210.224:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 198.237.107.242:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 98.232.40.90:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 205.61.9.169:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 23.46.163.17:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 134.188.245.96:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 44.177.140.110:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 222.148.51.62:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 129.111.218.23:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 128.118.247.172:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 191.252.2.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 75.101.231.39:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 221.215.5.223:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 92.54.199.220:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 195.27.43.191:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 39.194.241.65:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 73.29.27.148:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 114.228.180.159:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 98.99.113.184:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 42.25.145.30:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 130.221.223.11:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 202.22.74.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 199.252.94.69:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 71.127.250.103:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 36.92.140.192:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 19.84.98.233:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 32.255.200.203:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 195.66.254.12:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 197.0.65.116:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 59.127.160.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 34.77.15.214:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 45.86.122.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 151.100.99.150:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 159.4.46.109:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 39.35.154.251:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 142.100.7.210:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 202.7.91.161:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 63.12.237.4:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 52.91.245.109:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 135.46.116.225:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 217.8.176.203:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 68.147.36.5:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 211.87.41.238:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 129.208.231.18:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 201.50.185.101:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 193.174.6.233:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 100.203.177.63:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 34.228.253.178:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 50.244.191.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 8.136.129.164:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 17.51.153.128:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 143.42.72.88:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 202.41.76.86:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 36.96.122.33:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 197.91.164.175:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 25.149.5.16:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 135.108.113.12:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 76.241.188.13:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 62.32.77.180:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 81.175.67.43:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 8.8.215.243:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 90.110.71.141:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 176.84.177.235:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 2.114.253.9:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 39.154.169.19:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 209.206.157.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 153.68.49.73:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 163.218.53.125:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 17.185.139.244:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 186.24.162.3:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 137.74.187.88:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 80.103.45.199:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 166.81.131.214:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 143.24.39.35:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 89.140.112.124:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 184.214.3.97:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 115.248.43.218:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 128.130.224.206:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 145.227.0.143:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 32.150.1.226:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 216.254.216.72:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 104.233.227.181:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 183.124.54.111:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 86.28.109.24:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 102.55.168.120:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 125.217.153.52:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 39.12.250.103:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 173.96.7.213:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 135.184.53.54:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 199.131.178.254:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 131.216.75.1:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 99.99.202.68:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 75.12.162.149:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 123.125.89.196:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 162.53.119.1:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 196.9.198.232:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 162.6.235.241:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 184.167.49.255:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 106.98.188.167:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 120.169.16.154:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 46.225.233.40:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 205.1.99.213:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 170.136.31.35:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 167.211.254.114:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 204.145.223.240:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 197.202.44.40:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 216.24.39.152:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 45.199.163.13:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 165.172.14.121:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 168.194.202.59:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 201.45.234.68:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 150.114.169.99:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 69.76.92.207:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 79.110.3.42:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 4.146.235.171:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 213.15.191.233:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 149.205.212.200:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 195.214.8.4:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 88.140.173.153:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 199.144.137.196:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 63.108.150.4:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 125.235.197.27:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 24.73.253.125:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 202.171.29.139:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 113.241.119.42:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 74.255.95.75:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 200.223.159.55:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 147.74.19.61:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 76.51.81.9:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 93.102.25.204:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 156.161.71.71:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 206.206.164.88:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 121.32.93.5:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 138.160.154.208:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 120.28.128.236:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 174.251.233.13:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 210.4.233.229:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 129.209.103.27:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 129.84.88.65:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 42.113.163.3:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 152.253.215.216:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 162.138.45.210:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 53.168.12.59:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 96.179.192.179:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 2.39.74.136:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 179.62.235.163:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 134.179.209.84:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 72.214.57.27:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 166.210.139.76:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 58.109.89.211:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 77.198.88.98:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 88.204.139.162:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 221.191.103.52:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 102.47.172.169:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 52.40.179.84:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 72.49.202.31:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 61.53.84.82:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 139.27.146.243:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 160.232.75.138:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 117.35.61.205:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 81.65.236.75:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 2.60.204.242:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 110.83.219.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 114.221.33.249:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 65.228.166.73:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 179.250.207.208:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 216.31.152.66:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 112.15.62.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 70.0.181.78:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 98.66.224.239:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 40.11.30.98:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 145.156.191.255:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 156.151.143.86:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 105.255.210.87:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 146.122.186.66:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 80.55.227.138:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 113.255.132.240:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 167.202.147.189:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 208.175.165.242:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 31.213.146.166:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 9.235.234.111:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 143.197.102.250:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 18.97.233.43:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 152.13.28.142:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 58.124.17.254:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 114.104.63.231:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 61.24.112.44:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 87.184.68.164:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 177.84.90.19:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 120.138.80.49:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 12.46.252.87:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 111.217.103.154:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 20.240.163.8:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 97.54.78.215:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 125.145.52.140:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 76.95.232.230:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 133.47.162.247:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 187.204.146.97:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 17.78.154.155:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 81.133.87.154:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 171.212.38.252:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 109.172.90.224:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 147.61.203.27:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 185.127.179.254:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 169.201.222.184:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 71.230.137.240:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 201.185.254.204:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 126.230.63.14:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 113.55.28.64:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 116.240.70.34:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 213.127.162.76:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 182.226.119.134:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 185.152.77.247:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 155.199.42.160:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 64.124.139.105:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 51.2.54.197:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 126.36.228.181:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 60.186.132.119:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 1.14.3.132:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 167.187.44.242:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 126.60.68.75:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 42.235.205.60:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 32.104.61.89:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 218.214.128.88:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 85.55.143.205:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 139.201.178.12:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 129.228.140.121:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 209.141.126.252:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 35.163.10.71:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 58.20.169.118:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 13.190.96.48:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 96.148.44.18:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 208.215.19.225:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 135.225.121.9:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 152.106.121.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 48.116.220.12:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 75.86.161.139:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 39.75.47.22:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 143.148.45.177:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 181.136.144.133:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 46.182.216.39:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 53.18.230.36:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 80.207.98.190:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 65.200.114.61:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 193.229.250.66:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 163.199.143.14:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 62.107.187.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 101.178.200.183:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 147.50.137.104:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 54.188.63.251:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 170.25.80.243:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 43.151.160.54:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 158.198.254.58:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 76.62.241.126:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 163.235.151.167:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 133.205.63.98:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 62.35.78.129:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 139.1.209.168:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 152.209.217.51:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 173.5.133.247:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 116.192.166.208:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 38.165.107.100:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 217.52.73.189:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 42.184.77.144:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 167.103.128.210:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 170.249.192.191:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 78.28.57.24:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 157.222.44.234:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 181.210.228.126:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 209.235.49.209:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 118.110.249.86:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 209.61.61.141:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 49.24.166.167:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 63.212.235.58:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 158.76.153.177:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 76.226.124.47:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 85.157.123.174:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 218.191.27.223:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 128.32.4.134:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 120.237.215.141:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 198.115.32.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 166.184.109.59:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 200.5.249.225:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 116.127.177.68:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 37.120.238.8:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 20.73.40.162:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 149.74.47.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 17.67.37.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 221.63.178.245:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 207.130.32.169:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 23.162.198.61:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 170.152.156.155:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 112.84.150.15:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 8.167.74.147:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 136.181.198.156:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 203.254.50.110:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 58.64.120.248:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 148.99.115.238:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 190.157.99.148:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 57.26.251.43:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 102.227.12.2:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 201.7.115.0:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 52.137.139.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 167.111.214.45:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 105.124.209.35:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 186.133.211.183:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 216.50.253.13:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 110.10.57.114:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 109.29.162.241:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 101.18.227.141:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 97.245.151.65:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 47.4.208.36:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 168.41.175.133:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 101.123.60.31:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 118.42.150.4:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 146.126.72.100:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 2.25.193.237:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 126.203.51.174:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 49.159.251.232:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 102.0.233.154:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 130.250.72.106:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 171.14.159.84:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 50.144.143.82:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 54.93.42.34:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 67.165.172.189:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 69.85.15.151:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 220.8.50.154:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 115.168.49.149:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 51.84.199.184:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 12.177.238.163:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 100.22.3.120:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 149.242.36.140:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 19.198.165.79:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 123.50.69.129:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 106.240.91.50:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 88.83.4.213:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 121.157.215.68:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 20.74.19.221:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 161.191.221.85:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 24.106.103.61:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 175.49.54.203:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 79.99.7.92:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 97.110.177.105:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 209.45.55.251:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 23.159.95.127:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 183.139.191.115:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 75.120.117.166:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 140.195.124.12:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 154.118.228.22:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 38.161.104.88:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 17.104.192.48:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 111.49.125.63:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 184.171.37.129:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 180.194.87.159:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 207.228.127.83:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 207.144.62.232:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 14.33.244.118:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 105.38.79.228:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 92.50.58.130:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 129.98.120.3:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 132.87.10.142:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 203.229.114.65:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 78.167.123.17:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 72.151.7.245:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 163.165.91.211:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 117.237.140.100:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 18.37.136.49:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 50.164.39.217:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 212.140.112.111:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 152.108.49.61:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 144.112.44.132:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 94.169.16.215:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 32.206.7.247:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 35.219.208.165:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 93.200.186.8:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 178.148.193.173:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 183.228.146.200:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 99.204.46.215:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 197.166.65.120:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 159.68.225.175:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 84.225.172.88:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 24.213.54.88:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 54.23.141.240:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 102.79.182.253:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 41.78.9.43:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 60.249.108.245:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 84.170.106.249:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 5.217.168.70:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 116.202.0.155:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 126.149.82.51:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 182.83.122.159:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 40.65.120.94:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 168.216.81.181:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 74.202.4.52:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 91.36.141.220:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 153.11.43.10:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 9.179.51.161:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 100.219.204.50:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 206.193.72.71:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 153.247.68.182:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 135.138.178.31:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 162.49.220.215:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 50.17.254.9:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 162.53.213.20:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 118.30.186.5:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 40.106.23.243:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 138.108.12.27:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 164.131.63.12:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 108.105.127.44:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 46.238.220.28:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 46.79.9.173:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 178.183.212.231:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 13.1.141.137:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 147.145.143.234:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 134.222.141.248:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 193.93.241.153:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 120.27.161.188:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 168.72.132.90:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 167.221.90.53:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 92.168.207.204:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 107.12.58.12:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 217.88.61.52:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 96.64.84.154:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 136.224.8.246:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 200.226.96.224:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 66.183.29.82:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 58.163.63.67:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 74.115.57.106:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 147.175.110.252:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 71.75.220.156:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 223.22.144.31:2323
              Source: global trafficTCP traffic: 192.168.2.23:20991 -> 43.160.204.3:2323
              Source: /tmp/arm (PID: 5201)Socket: 127.0.0.1::1124
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
              Source: unknownTCP traffic detected without corresponding DNS query: 119.202.14.199
              Source: unknownTCP traffic detected without corresponding DNS query: 62.89.61.199
              Source: unknownTCP traffic detected without corresponding DNS query: 68.208.84.130
              Source: unknownTCP traffic detected without corresponding DNS query: 12.238.185.199
              Source: unknownTCP traffic detected without corresponding DNS query: 87.238.206.23
              Source: unknownTCP traffic detected without corresponding DNS query: 159.12.107.37
              Source: unknownTCP traffic detected without corresponding DNS query: 126.42.164.2
              Source: unknownTCP traffic detected without corresponding DNS query: 176.100.194.58
              Source: unknownTCP traffic detected without corresponding DNS query: 173.96.128.32
              Source: unknownTCP traffic detected without corresponding DNS query: 121.149.181.139
              Source: unknownTCP traffic detected without corresponding DNS query: 176.146.86.12
              Source: unknownTCP traffic detected without corresponding DNS query: 18.170.35.44
              Source: unknownTCP traffic detected without corresponding DNS query: 203.255.163.57
              Source: unknownTCP traffic detected without corresponding DNS query: 91.54.14.130
              Source: unknownTCP traffic detected without corresponding DNS query: 196.174.115.72
              Source: unknownTCP traffic detected without corresponding DNS query: 2.154.86.190
              Source: unknownTCP traffic detected without corresponding DNS query: 173.198.105.71
              Source: unknownTCP traffic detected without corresponding DNS query: 34.170.119.206
              Source: unknownTCP traffic detected without corresponding DNS query: 77.200.62.159
              Source: unknownTCP traffic detected without corresponding DNS query: 212.75.120.245
              Source: unknownTCP traffic detected without corresponding DNS query: 118.145.141.83
              Source: unknownTCP traffic detected without corresponding DNS query: 80.223.101.140
              Source: unknownTCP traffic detected without corresponding DNS query: 195.35.106.75
              Source: unknownTCP traffic detected without corresponding DNS query: 168.177.16.242
              Source: unknownTCP traffic detected without corresponding DNS query: 41.26.145.4
              Source: unknownTCP traffic detected without corresponding DNS query: 52.234.120.116
              Source: unknownTCP traffic detected without corresponding DNS query: 192.234.176.72
              Source: unknownTCP traffic detected without corresponding DNS query: 69.236.216.77
              Source: unknownTCP traffic detected without corresponding DNS query: 79.50.197.220
              Source: unknownTCP traffic detected without corresponding DNS query: 195.199.169.97
              Source: unknownTCP traffic detected without corresponding DNS query: 53.253.39.1
              Source: unknownTCP traffic detected without corresponding DNS query: 185.170.170.211
              Source: unknownTCP traffic detected without corresponding DNS query: 2.206.71.1
              Source: unknownTCP traffic detected without corresponding DNS query: 35.60.42.186
              Source: unknownTCP traffic detected without corresponding DNS query: 159.174.14.108
              Source: unknownTCP traffic detected without corresponding DNS query: 65.134.223.36
              Source: unknownTCP traffic detected without corresponding DNS query: 17.95.60.243
              Source: unknownTCP traffic detected without corresponding DNS query: 179.41.227.194
              Source: unknownTCP traffic detected without corresponding DNS query: 216.9.117.128
              Source: unknownTCP traffic detected without corresponding DNS query: 134.186.6.145
              Source: unknownTCP traffic detected without corresponding DNS query: 105.74.198.70
              Source: unknownTCP traffic detected without corresponding DNS query: 89.147.57.147
              Source: unknownTCP traffic detected without corresponding DNS query: 59.170.70.45
              Source: unknownTCP traffic detected without corresponding DNS query: 121.211.51.162
              Source: unknownTCP traffic detected without corresponding DNS query: 154.19.175.84
              Source: unknownTCP traffic detected without corresponding DNS query: 108.217.29.81
              Source: unknownTCP traffic detected without corresponding DNS query: 176.34.100.103
              Source: unknownTCP traffic detected without corresponding DNS query: 199.45.164.180
              Source: unknownTCP traffic detected without corresponding DNS query: 12.13.158.41
              Source: unknownTCP traffic detected without corresponding DNS query: 179.92.96.232
              Source: unknownDNS traffic detected: queries for: arcticboatz.cz

              System Summary

              barindex
              Source: arm, type: SAMPLEMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: arm, type: SAMPLEMatched rule: Detects ELF malware Mirai related Author: Florian Roth
              Source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
              Source: arm, type: SAMPLEMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: arm, type: SAMPLEMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
              Source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: Initial sampleString containing 'busybox' found: bin/busybox
              Source: Initial sampleString containing 'busybox' found: /bin/busybox
              Source: Initial sampleString containing 'busybox' found: f%s:%dwebservarm7x86_64ppcm68kbin/busyboxbin/watchdogbin/systemd/bin/busybox/bin/watchdog/bin/systemd\
              Source: classification engineClassification label: mal100.troj.lin@0/0@1/0

              Persistence and Installation Behavior

              barindex
              Source: /bin/sh (PID: 5228)Chmod executable with 777: /usr/bin/chmod -> chmod 777 bin/systemd
              Source: /bin/sh (PID: 5226)Mkdir executable: /usr/bin/mkdir -> mkdir bin
              Source: /bin/sh (PID: 5228)Chmod executable: /usr/bin/chmod -> chmod 777 bin/systemd
              Source: /usr/bin/chmod (PID: 5228)File: /tmp/bin/systemd (bits: - usr: rwx grp: rwx all: rwx)Jump to behavior
              Source: /tmp/arm (PID: 5223)Shell command executed: sh -c "rm -rf bin/systemd && mkdir bin; >bin/systemd && mv /tmp/arm bin/systemd; chmod 777 bin/systemd"
              Source: /bin/sh (PID: 5225)Rm executable: /usr/bin/rm -> rm -rf bin/systemd
              Source: /tmp/arm (PID: 5201)Queries kernel information via 'uname':
              Source: arm, 5201.1.00000000b2f7bc77.000000009a69674a.rw-.sdmpBinary or memory string: `kU!/etc/qemu-binfmt/arm
              Source: arm, 5201.1.0000000039e6831f.00000000db2ee247.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/armSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm
              Source: arm, 5201.1.00000000b2f7bc77.000000009a69674a.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
              Source: arm, 5201.1.0000000039e6831f.00000000db2ee247.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: arm, type: SAMPLE
              Source: Yara matchFile source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: arm, type: SAMPLE
              Source: Yara matchFile source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: arm PID: 5201, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: arm, type: SAMPLE
              Source: Yara matchFile source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: arm, type: SAMPLE
              Source: Yara matchFile source: 5201.1.000000002e6ad643.0000000062dfdce7.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: arm PID: 5201, type: MEMORYSTR
              Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
              Valid Accounts1
              Scripting
              Path InterceptionPath Interception2
              File and Directory Permissions Modification
              OS Credential Dumping11
              Security Software Discovery
              Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
              Encrypted Channel
              Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
              Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
              Scripting
              LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
              Non-Standard Port
              Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
              Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
              File Deletion
              Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
              Non-Application Layer Protocol
              Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
              Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer2
              Application Layer Protocol
              SIM Card SwapCarrier Billing Fraud
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 557442 Sample: arm Startdate: 21/01/2022 Architecture: LINUX Score: 100 25 arcticboatz.cz 2->25 27 64.196.203.67 WINDSTREAMUS United States 2->27 29 99 other IPs or domains 2->29 31 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->31 33 Malicious sample detected (through community Yara rule) 2->33 35 Antivirus / Scanner detection for submitted sample 2->35 37 3 other signatures 2->37 8 arm 2->8         started        signatures3 process4 process5 10 arm sh 8->10         started        12 arm 8->12         started        process6 14 sh chmod 10->14         started        17 sh rm 10->17         started        19 sh mkdir 10->19         started        21 sh mv 10->21         started        23 arm 12->23         started        signatures7 39 Sets full permissions to files and/or directories 14->39
              SourceDetectionScannerLabelLink
              arm39%VirustotalBrowse
              arm50%ReversingLabsLinux.Trojan.Mirai
              arm100%AviraLINUX/Mirai.bonb
              No Antivirus matches
              SourceDetectionScannerLabelLink
              arcticboatz.cz4%VirustotalBrowse
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              arcticboatz.cz
              95.181.161.40
              truetrueunknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              90.21.87.76
              unknownFrance
              3215FranceTelecom-OrangeFRfalse
              39.70.211.12
              unknownChina
              4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
              191.151.188.107
              unknownColombia
              26611COMCELSACOfalse
              158.248.198.227
              unknownNorway
              29695ALTIBOX_ASNorwayNOfalse
              152.55.146.223
              unknownUnited States
              81NCRENUSfalse
              72.235.23.15
              unknownUnited States
              36149HAWAIIAN-TELCOMUSfalse
              97.39.187.32
              unknownUnited States
              6167CELLCO-PARTUSfalse
              153.247.68.182
              unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
              80.208.170.47
              unknownSwitzerland
              15600FINECOMQuicklineAGCHfalse
              181.126.230.132
              unknownParaguay
              23201TelecelSAPYfalse
              74.169.133.116
              unknownUnited States
              7018ATT-INTERNET4USfalse
              82.117.30.106
              unknownLiechtenstein
              35223HOI-ASLIfalse
              88.253.17.216
              unknownTurkey
              9121TTNETTRfalse
              187.95.178.164
              unknownBrazil
              53090VianetTelecomunicacoeseInternetBRfalse
              138.142.32.215
              unknownUnited States
              721DNIC-ASBLK-00721-00726USfalse
              58.210.29.106
              unknownChina
              4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
              46.138.231.194
              unknownRussian Federation
              25513ASN-MGTS-USPDRUfalse
              91.53.126.192
              unknownGermany
              3320DTAGInternetserviceprovideroperationsDEfalse
              23.49.42.170
              unknownUnited States
              16625AKAMAI-ASUSfalse
              200.179.36.152
              unknownBrazil
              4230CLAROSABRfalse
              80.166.163.211
              unknownDenmark
              3292TDCTDCASDKfalse
              133.150.17.100
              unknownJapan10021KVHKVHCoLtdJPfalse
              176.224.147.61
              unknownSaudi Arabia
              35819MOBILY-ASEtihadEtisalatCompanyMobilySAfalse
              1.69.204.55
              unknownChina
              4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
              216.37.77.119
              unknownUnited States
              21922WEBNETUSfalse
              217.129.155.32
              unknownPortugal
              13156AS13156PalmelaPTfalse
              163.218.53.125
              unknownJapan7502IP-KYOTOAdvancedSoftwareTechnologyManagementResearchfalse
              141.21.45.141
              unknownGermany
              205046FZI-AS-1DEfalse
              173.112.71.235
              unknownUnited States
              10507SPCSUSfalse
              4.105.216.207
              unknownUnited States
              3356LEVEL3USfalse
              165.52.21.238
              unknownSouth Africa
              37053RSAWEB-ASZAfalse
              190.125.166.121
              unknownColombia
              26611COMCELSACOfalse
              162.107.199.176
              unknownUnited States
              17162DONALDSONUSfalse
              191.223.166.113
              unknownBrazil
              8167BrasilTelecomSA-FilialDistritoFederalBRfalse
              81.133.225.89
              unknownUnited Kingdom
              2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
              114.23.5.71
              unknownNew Zealand
              56030VOYAGERNET-AS-APVoyagerInternetLtdNZfalse
              111.17.173.192
              unknownChina
              24444CMNET-V4SHANDONG-AS-APShandongMobileCommunicationCompanyfalse
              136.161.34.86
              unknownUnited States
              174COGENT-174USfalse
              45.83.121.194
              unknownNetherlands
              200313INTERNET-ITNLfalse
              153.193.162.150
              unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
              1.104.172.183
              unknownKorea Republic of
              4766KIXS-AS-KRKoreaTelecomKRfalse
              200.151.155.13
              unknownBrazil
              7738TelemarNorteLesteSABRfalse
              213.36.152.232
              unknownFrance
              12322PROXADFRfalse
              61.15.226.39
              unknownHong Kong
              9908HKCABLE2-HK-APHKCableTVLtdHKfalse
              61.185.7.40
              unknownChina
              4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
              190.145.21.183
              unknownColombia
              14080TelmexColombiaSACOfalse
              201.176.134.4
              unknownArgentina
              22927TelefonicadeArgentinaARfalse
              125.82.123.197
              unknownChina
              4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
              74.33.205.71
              unknownUnited States
              7011FRONTIER-AND-CITIZENSUSfalse
              132.97.141.117
              unknownUnited States
              306DNIC-ASBLK-00306-00371USfalse
              154.197.40.201
              unknownSeychelles
              137443ANCHGLOBAL-AS-APAnchnetAsiaLimitedHKfalse
              151.141.190.160
              unknownUnited States
              29842ETSU-NETUSfalse
              59.65.228.14
              unknownChina
              4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
              99.105.83.245
              unknownUnited States
              7018ATT-INTERNET4USfalse
              152.250.150.236
              unknownBrazil
              27699TELEFONICABRASILSABRfalse
              27.201.102.121
              unknownChina
              4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
              189.71.43.234
              unknownBrazil
              7738TelemarNorteLesteSABRfalse
              136.109.100.212
              unknownUnited States
              60311ONEFMCHfalse
              82.45.153.218
              unknownUnited Kingdom
              5089NTLGBfalse
              144.67.166.155
              unknownUnited States
              3243MEO-RESIDENCIALPTfalse
              207.34.108.176
              unknownCanada
              15247RADIANT-VANCOUVERCAfalse
              191.49.3.3
              unknownBrazil
              26615TIMSABRfalse
              40.99.144.217
              unknownUnited States
              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
              86.7.59.119
              unknownUnited Kingdom
              5089NTLGBfalse
              12.47.81.13
              unknownUnited States
              7018ATT-INTERNET4USfalse
              200.45.30.120
              unknownArgentina
              7303TelecomArgentinaSAARfalse
              48.171.205.123
              unknownUnited States
              2686ATGS-MMD-ASUSfalse
              34.205.37.162
              unknownUnited States
              14618AMAZON-AESUSfalse
              61.17.124.120
              unknownIndia
              17908TCISLTataCommunicationsINfalse
              4.19.212.157
              unknownUnited States
              3356LEVEL3USfalse
              190.227.23.147
              unknownArgentina
              7303TelecomArgentinaSAARfalse
              60.0.108.189
              unknownChina
              4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
              153.12.215.116
              unknownUnited States
              4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
              54.17.208.21
              unknownUnited States
              14618AMAZON-AESUSfalse
              84.208.212.180
              unknownNorway
              41164GET-NOGETNorwayNOfalse
              117.54.211.86
              unknownIndonesia
              9340INDONET-AS-APINDOInternetPTIDfalse
              135.71.50.102
              unknownUnited States
              18676AVAYAUSfalse
              152.241.175.204
              unknownBrazil
              26599TELEFONICABRASILSABRfalse
              212.189.180.251
              unknownItaly
              137ASGARRConsortiumGARREUfalse
              158.178.182.15
              unknownUnited Kingdom
              15830EQUINIX-CONNECT-EMEAGBfalse
              173.28.235.234
              unknownUnited States
              30036MEDIACOM-ENTERPRISE-BUSINESSUSfalse
              9.179.51.161
              unknownUnited States
              3356LEVEL3USfalse
              151.250.30.253
              unknownTurkey
              34984TELLCOM-ASTRfalse
              98.144.53.110
              unknownUnited States
              10796TWC-10796-MIDWESTUSfalse
              134.235.160.137
              unknownUnited States
              1586DNIC-ASBLK-01550-01601USfalse
              42.55.187.255
              unknownChina
              4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
              78.144.25.71
              unknownUnited Kingdom
              13285OPALTELECOM-ASTalkTalkCommunicationsLimitedGBfalse
              126.117.92.254
              unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
              37.20.211.92
              unknownRussian Federation
              12389ROSTELECOM-ASRUfalse
              148.184.114.2
              unknownUnited States
              3423ATTIS-ASN3423USfalse
              201.222.187.82
              unknownChile
              7418TELEFONICACHILESACLfalse
              223.37.56.169
              unknownKorea Republic of
              9644SKTELECOM-NET-ASSKTelecomKRfalse
              209.58.18.6
              unknownUnited States
              6453AS6453USfalse
              44.138.49.166
              unknownUnited States
              7377UCSDUSfalse
              64.196.203.67
              unknownUnited States
              7029WINDSTREAMUSfalse
              143.201.46.60
              unknownunknown
              3128BRUWS-AS3128USfalse
              151.171.248.30
              unknownUnited States
              3257GTT-BACKBONEGTTDEfalse
              76.168.35.52
              unknownUnited States
              20001TWC-20001-PACWESTUSfalse
              19.255.230.120
              unknownUnited States
              3MIT-GATEWAYSUSfalse
              65.56.241.202
              unknownUnited States
              3356LEVEL3USfalse
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
              Entropy (8bit):6.105130846651577
              TrID:
              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
              File name:arm
              File size:83264
              MD5:c8eac6c41bd5f6ec5a65524142f340e0
              SHA1:ae41cee628bdacfe7dd71dd1e4ab90e71a9d0a86
              SHA256:b916d6f9d2756f35b510f1e89cf54a3601b3aafdba2a506cd9e5254e0dade88e
              SHA512:4903b1f5a4a5e87704dbdd6caff2a496ca3de1fec833cfbdfdbf566f4f3ee2eef1eb8ab1e9347eee35bdcf623bd13a70d83e2aeb3611c2bc0dd8f722375235cd
              SSDEEP:1536:0DS1KyEi7hinozX7mgbmvKbvlTuWrYn4XqbMyHFrzLv6aevo0YwbZnFA:YZi9zLmvvKuwYNoyHFTcKwbZnFA
              File Content Preview:.ELF...a..........(.........4....C......4. ...(.....................D=..D=...............@...@...@..p....&..........Q.td..................................-...L."....G..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

              ELF header

              Class:ELF32
              Data:2's complement, little endian
              Version:1 (current)
              Machine:ARM
              Version Number:0x1
              Type:EXEC (Executable file)
              OS/ABI:ARM - ABI
              ABI Version:0
              Entry Point Address:0x8190
              Flags:0x202
              ELF Header Size:52
              Program Header Offset:52
              Program Header Size:32
              Number of Program Headers:3
              Section Header Offset:82864
              Section Header Size:40
              Number of Section Headers:10
              Header String Table Index:9
              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
              NULL0x00x00x00x00x0000
              .initPROGBITS0x80940x940x180x00x6AX004
              .textPROGBITS0x80b00xb00x11f3c0x00x6AX0016
              .finiPROGBITS0x19fec0x11fec0x140x00x6AX004
              .rodataPROGBITS0x1a0000x120000x1d440x00x2A004
              .ctorsPROGBITS0x240000x140000x80x00x3WA004
              .dtorsPROGBITS0x240080x140080x80x00x3WA004
              .dataPROGBITS0x240140x140140x35c0x00x3WA004
              .bssNOBITS0x243700x143700x237c0x00x3WA004
              .shstrtabSTRTAB0x00x143700x3e0x00x0001
              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
              LOAD0x00x80000x80000x13d440x13d443.44850x5R E0x8000.init .text .fini .rodata
              LOAD0x140000x240000x240000x3700x26ec1.67570x6RW 0x8000.ctors .dtors .data .bss
              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
              TimestampSource PortDest PortSource IPDest IP
              Jan 21, 2022 06:01:11.455588102 CET209912323192.168.2.23119.202.14.199
              Jan 21, 2022 06:01:11.455666065 CET2099123192.168.2.2362.89.61.199
              Jan 21, 2022 06:01:11.455688953 CET2099123192.168.2.2368.208.84.130
              Jan 21, 2022 06:01:11.455697060 CET2099123192.168.2.2312.238.185.199
              Jan 21, 2022 06:01:11.455715895 CET2099123192.168.2.2387.238.206.23
              Jan 21, 2022 06:01:11.455739975 CET2099123192.168.2.23159.12.107.37
              Jan 21, 2022 06:01:11.455749989 CET2099123192.168.2.23126.42.164.2
              Jan 21, 2022 06:01:11.455770016 CET2099123192.168.2.23176.100.194.58
              Jan 21, 2022 06:01:11.455790997 CET2099123192.168.2.23173.96.128.32
              Jan 21, 2022 06:01:11.455795050 CET2099123192.168.2.23121.149.181.139
              Jan 21, 2022 06:01:11.455799103 CET209912323192.168.2.23110.66.24.210
              Jan 21, 2022 06:01:11.456011057 CET2099123192.168.2.23176.146.86.12
              Jan 21, 2022 06:01:11.456028938 CET2099123192.168.2.2318.170.35.44
              Jan 21, 2022 06:01:11.456047058 CET2099123192.168.2.23203.255.163.57
              Jan 21, 2022 06:01:11.456075907 CET2099123192.168.2.2391.54.14.130
              Jan 21, 2022 06:01:11.456083059 CET2099123192.168.2.23196.174.115.72
              Jan 21, 2022 06:01:11.456100941 CET2099123192.168.2.232.154.86.190
              Jan 21, 2022 06:01:11.456118107 CET2099123192.168.2.23173.198.105.71
              Jan 21, 2022 06:01:11.456137896 CET2099123192.168.2.2334.170.119.206
              Jan 21, 2022 06:01:11.456151009 CET2099123192.168.2.2377.200.62.159
              Jan 21, 2022 06:01:11.456172943 CET209912323192.168.2.23212.75.120.245
              Jan 21, 2022 06:01:11.456177950 CET2099123192.168.2.23118.145.141.83
              Jan 21, 2022 06:01:11.456199884 CET2099123192.168.2.2380.223.101.140
              Jan 21, 2022 06:01:11.456222057 CET2099123192.168.2.23195.35.106.75
              Jan 21, 2022 06:01:11.456228971 CET2099123192.168.2.23168.177.16.242
              Jan 21, 2022 06:01:11.456273079 CET2099123192.168.2.2341.26.145.4
              Jan 21, 2022 06:01:11.456284046 CET2099123192.168.2.2352.234.120.116
              Jan 21, 2022 06:01:11.456288099 CET2099123192.168.2.23192.234.176.72
              Jan 21, 2022 06:01:11.456293106 CET2099123192.168.2.2369.236.216.77
              Jan 21, 2022 06:01:11.456315994 CET2099123192.168.2.2379.50.197.220
              Jan 21, 2022 06:01:11.456325054 CET209912323192.168.2.23195.199.169.97
              Jan 21, 2022 06:01:11.456335068 CET2099123192.168.2.2353.253.39.1
              Jan 21, 2022 06:01:11.456345081 CET2099123192.168.2.23185.170.170.211
              Jan 21, 2022 06:01:11.456366062 CET2099123192.168.2.232.206.71.1
              Jan 21, 2022 06:01:11.456394911 CET2099123192.168.2.2335.60.42.186
              Jan 21, 2022 06:01:11.456543922 CET2099123192.168.2.23159.174.14.108
              Jan 21, 2022 06:01:11.456551075 CET2099123192.168.2.2365.134.223.36
              Jan 21, 2022 06:01:11.456552982 CET2099123192.168.2.2317.95.60.243
              Jan 21, 2022 06:01:11.456552982 CET2099123192.168.2.23179.41.227.194
              Jan 21, 2022 06:01:11.456554890 CET2099123192.168.2.23216.9.117.128
              Jan 21, 2022 06:01:11.456566095 CET209912323192.168.2.23134.186.6.145
              Jan 21, 2022 06:01:11.456576109 CET2099123192.168.2.23105.74.198.70
              Jan 21, 2022 06:01:11.456577063 CET2099123192.168.2.2389.147.57.147
              Jan 21, 2022 06:01:11.456585884 CET2099123192.168.2.2359.170.70.45
              Jan 21, 2022 06:01:11.456587076 CET2099123192.168.2.23121.211.51.162
              Jan 21, 2022 06:01:11.456619978 CET2099123192.168.2.23154.19.175.84
              Jan 21, 2022 06:01:11.456633091 CET209912323192.168.2.23108.217.29.81
              Jan 21, 2022 06:01:11.456666946 CET2099123192.168.2.23176.34.100.103
              Jan 21, 2022 06:01:11.456670046 CET2099123192.168.2.23199.45.164.180
              Jan 21, 2022 06:01:11.456671000 CET2099123192.168.2.2312.13.158.41
              Jan 21, 2022 06:01:11.456672907 CET2099123192.168.2.23210.93.11.223
              Jan 21, 2022 06:01:11.456684113 CET2099123192.168.2.23179.92.96.232
              Jan 21, 2022 06:01:11.456685066 CET2099123192.168.2.2354.110.176.154
              Jan 21, 2022 06:01:11.456687927 CET2099123192.168.2.2318.167.17.213
              Jan 21, 2022 06:01:11.456701994 CET2099123192.168.2.23109.146.76.49
              Jan 21, 2022 06:01:11.456711054 CET2099123192.168.2.232.236.179.167
              Jan 21, 2022 06:01:11.456723928 CET2099123192.168.2.2381.87.27.47
              Jan 21, 2022 06:01:11.456724882 CET2099123192.168.2.23223.78.145.74
              Jan 21, 2022 06:01:11.456734896 CET2099123192.168.2.23115.8.180.203
              Jan 21, 2022 06:01:11.456743956 CET2099123192.168.2.23173.191.75.43
              Jan 21, 2022 06:01:11.456749916 CET209912323192.168.2.2373.131.122.187
              Jan 21, 2022 06:01:11.456806898 CET2099123192.168.2.23136.47.54.249
              Jan 21, 2022 06:01:11.456809044 CET2099123192.168.2.2390.123.156.218
              Jan 21, 2022 06:01:11.456809998 CET2099123192.168.2.23152.7.148.235
              Jan 21, 2022 06:01:11.456821918 CET2099123192.168.2.238.189.36.140
              Jan 21, 2022 06:01:11.456837893 CET2099123192.168.2.23132.246.187.244
              Jan 21, 2022 06:01:11.456837893 CET2099123192.168.2.23151.243.130.45
              Jan 21, 2022 06:01:11.456837893 CET2099123192.168.2.2336.35.170.173
              Jan 21, 2022 06:01:11.456841946 CET2099123192.168.2.2393.95.148.164
              Jan 21, 2022 06:01:11.456851959 CET209912323192.168.2.23129.244.223.61
              Jan 21, 2022 06:01:11.456852913 CET2099123192.168.2.239.41.200.188
              Jan 21, 2022 06:01:11.456861973 CET2099123192.168.2.23156.32.171.48
              Jan 21, 2022 06:01:11.456865072 CET2099123192.168.2.23114.146.119.112
              Jan 21, 2022 06:01:11.456887007 CET2099123192.168.2.23165.78.222.98
              Jan 21, 2022 06:01:11.456906080 CET2099123192.168.2.23114.215.224.108
              Jan 21, 2022 06:01:11.456923962 CET2099123192.168.2.23129.239.13.54
              Jan 21, 2022 06:01:11.456931114 CET2099123192.168.2.23114.242.61.189
              Jan 21, 2022 06:01:11.456954002 CET2099123192.168.2.23116.242.128.243
              Jan 21, 2022 06:01:11.456976891 CET2099123192.168.2.235.69.101.17
              Jan 21, 2022 06:01:11.456993103 CET2099123192.168.2.2320.114.73.12
              Jan 21, 2022 06:01:11.457005978 CET209912323192.168.2.2372.96.34.184
              Jan 21, 2022 06:01:11.457037926 CET2099123192.168.2.23149.161.250.118
              Jan 21, 2022 06:01:11.457050085 CET2099123192.168.2.23137.115.134.252
              Jan 21, 2022 06:01:11.457067013 CET2099123192.168.2.23188.221.192.75
              Jan 21, 2022 06:01:11.457075119 CET2099123192.168.2.23104.147.193.249
              Jan 21, 2022 06:01:11.457098961 CET2099123192.168.2.23120.118.97.8
              Jan 21, 2022 06:01:11.457115889 CET2099123192.168.2.23109.48.199.39
              Jan 21, 2022 06:01:11.457129955 CET2099123192.168.2.23121.16.233.156
              Jan 21, 2022 06:01:11.457138062 CET2099123192.168.2.23205.77.176.157
              Jan 21, 2022 06:01:11.457174063 CET2099123192.168.2.23178.128.181.157
              Jan 21, 2022 06:01:11.457175016 CET209912323192.168.2.2366.75.206.83
              Jan 21, 2022 06:01:11.457176924 CET2099123192.168.2.2380.17.80.21
              Jan 21, 2022 06:01:11.457191944 CET2099123192.168.2.23169.149.141.114
              Jan 21, 2022 06:01:11.457196951 CET2099123192.168.2.23198.12.214.141
              Jan 21, 2022 06:01:11.457202911 CET2099123192.168.2.23170.129.135.235
              Jan 21, 2022 06:01:11.457222939 CET2099123192.168.2.23197.39.12.215
              Jan 21, 2022 06:01:11.457227945 CET2099123192.168.2.23128.122.40.2
              Jan 21, 2022 06:01:11.457240105 CET2099123192.168.2.23118.69.97.134
              Jan 21, 2022 06:01:11.457243919 CET2099123192.168.2.23200.174.208.43
              Jan 21, 2022 06:01:11.457243919 CET2099123192.168.2.23175.77.82.47
              TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
              Jan 21, 2022 06:01:11.452682972 CET192.168.2.238.8.8.80xd01cStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
              Jan 21, 2022 06:01:11.471282959 CET8.8.8.8192.168.2.230xd01cNo error (0)arcticboatz.cz95.181.161.40A (IP address)IN (0x0001)

              System Behavior

              Start time:06:01:10
              Start date:21/01/2022
              Path:/tmp/arm
              Arguments:/tmp/arm
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
              Start time:06:01:10
              Start date:21/01/2022
              Path:/tmp/arm
              Arguments:n/a
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
              Start time:06:01:10
              Start date:21/01/2022
              Path:/bin/sh
              Arguments:sh -c "rm -rf bin/systemd && mkdir bin; >bin/systemd && mv /tmp/arm bin/systemd; chmod 777 bin/systemd"
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
              Start time:06:01:10
              Start date:21/01/2022
              Path:/bin/sh
              Arguments:n/a
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
              Start time:06:01:10
              Start date:21/01/2022
              Path:/usr/bin/rm
              Arguments:rm -rf bin/systemd
              File size:72056 bytes
              MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b
              Start time:06:01:10
              Start date:21/01/2022
              Path:/bin/sh
              Arguments:n/a
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
              Start time:06:01:10
              Start date:21/01/2022
              Path:/usr/bin/mkdir
              Arguments:mkdir bin
              File size:88408 bytes
              MD5 hash:088c9d1df5a28ed16c726eca15964cb7
              Start time:06:01:10
              Start date:21/01/2022
              Path:/bin/sh
              Arguments:n/a
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
              Start time:06:01:10
              Start date:21/01/2022
              Path:/usr/bin/mv
              Arguments:mv /tmp/arm bin/systemd
              File size:149888 bytes
              MD5 hash:504f0590fa482d4da070a702260e3716
              Start time:06:01:10
              Start date:21/01/2022
              Path:/bin/sh
              Arguments:n/a
              File size:129816 bytes
              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
              Start time:06:01:10
              Start date:21/01/2022
              Path:/usr/bin/chmod
              Arguments:chmod 777 bin/systemd
              File size:63864 bytes
              MD5 hash:739483b900c045ae1374d6f53a86a279
              Start time:06:01:11
              Start date:21/01/2022
              Path:/tmp/arm
              Arguments:n/a
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
              Start time:06:01:11
              Start date:21/01/2022
              Path:/tmp/arm
              Arguments:n/a
              File size:4956856 bytes
              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1