Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86

Overview

General Information

Sample Name:x86
Analysis ID:557498
MD5:1780fa4bcc6aa107d0bbbc7bf00dfd0a
SHA1:9f8a838e4b0f42289cb04c047b4534f4d034e90f
SHA256:0033a14ee6ebda0d95e4b9db23926c1fc0a201c8d51fa3beabd2409a3b5c5d97
Tags:Mirai
Infos:

Detection

Mirai Moobot
Score:96
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Yara detected Moobot
Machine Learning detection for sample
Sets full permissions to files and/or directories
Yara signature match
Sample has stripped symbol table
Executes the "mkdir" command used to create folders
Sample tries to set the executable flag
Executes the "chmod" command used to modify permissions
Executes commands using a shell command-line interpreter
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample listens on a socket
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:557498
Start date:21.01.2022
Start time:08:26:17
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 56s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:x86
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal96.troj.lin@0/0@1/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/x86
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
qazwsxedc
Standard Error:
  • system is lnxubuntu20
  • x86 (PID: 5222, Parent: 5117, MD5: 1780fa4bcc6aa107d0bbbc7bf00dfd0a) Arguments: /tmp/x86
    • x86 New Fork (PID: 5223, Parent: 5222)
    • sh (PID: 5223, Parent: 5222, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "rm -rf bin/systemd && mkdir bin; >bin/systemd && mv /tmp/x86 bin/systemd; chmod 777 bin/systemd"
      • sh New Fork (PID: 5224, Parent: 5223)
      • rm (PID: 5224, Parent: 5223, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -rf bin/systemd
      • sh New Fork (PID: 5225, Parent: 5223)
      • mkdir (PID: 5225, Parent: 5223, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir bin
      • sh New Fork (PID: 5226, Parent: 5223)
      • mv (PID: 5226, Parent: 5223, MD5: 504f0590fa482d4da070a702260e3716) Arguments: mv /tmp/x86 bin/systemd
      • sh New Fork (PID: 5227, Parent: 5223)
      • chmod (PID: 5227, Parent: 5223, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod 777 bin/systemd
    • x86 New Fork (PID: 5228, Parent: 5222)
      • x86 New Fork (PID: 5229, Parent: 5228)
  • cleanup
SourceRuleDescriptionAuthorStrings
x86Mirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
  • 0x104aa:$x1: POST /cdn-cgi/
  • 0xfa63:$x3: /dev/watchdog
  • 0xfb8c:$s1: LCOGQGPTGP
x86JoeSecurity_MoobotYara detected MoobotJoe Security
    x86JoeSecurity_Mirai_9Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
      • 0x104aa:$x1: POST /cdn-cgi/
      • 0xfa63:$x3: /dev/watchdog
      • 0xfb8c:$s1: LCOGQGPTGP
      5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
        5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
          Process Memory Space: x86 PID: 5222JoeSecurity_MoobotYara detected MoobotJoe Security

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: x86Avira: detected
            Source: x86Virustotal: Detection: 36%Perma Link
            Source: x86ReversingLabs: Detection: 53%
            Source: x86Joe Sandbox ML: detected

            Networking

            barindex
            Source: TrafficSnort IDS: 2030489 ET TROJAN ELF/MooBot Mirai DDoS Variant Server Response 95.181.161.40:55005 -> 192.168.2.23:47080
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 68.180.106.57:23 -> 192.168.2.23:44448
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 68.180.106.57:23 -> 192.168.2.23:44448
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:43120 -> 187.248.39.129:23
            Source: TrafficSnort IDS: 716 INFO TELNET access 203.189.152.57:23 -> 192.168.2.23:43418
            Source: TrafficSnort IDS: 716 INFO TELNET access 103.80.112.238:23 -> 192.168.2.23:40044
            Source: TrafficSnort IDS: 716 INFO TELNET access 181.216.85.93:23 -> 192.168.2.23:57536
            Source: TrafficSnort IDS: 716 INFO TELNET access 1.217.228.22:23 -> 192.168.2.23:58760
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 181.216.85.93:23 -> 192.168.2.23:57536
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42260
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42260
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 68.180.106.57:23 -> 192.168.2.23:44502
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 68.180.106.57:23 -> 192.168.2.23:44502
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42270
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42270
            Source: TrafficSnort IDS: 716 INFO TELNET access 181.216.85.93:23 -> 192.168.2.23:57556
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 181.216.85.93:23 -> 192.168.2.23:57556
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42276
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42276
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:43192 -> 187.248.39.129:23
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42284
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42284
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:42296 -> 81.18.201.36:23
            Source: TrafficSnort IDS: 716 INFO TELNET access 181.216.85.93:23 -> 192.168.2.23:57582
            Source: TrafficSnort IDS: 716 INFO TELNET access 203.189.152.57:23 -> 192.168.2.23:43500
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42296
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42296
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:42310 -> 81.18.201.36:23
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 181.216.85.93:23 -> 192.168.2.23:57582
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42310
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42310
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42320
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42320
            Source: TrafficSnort IDS: 716 INFO TELNET access 103.80.112.238:23 -> 192.168.2.23:40130
            Source: TrafficSnort IDS: 716 INFO TELNET access 181.216.85.93:23 -> 192.168.2.23:57614
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:42334 -> 81.18.201.36:23
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:57614 -> 181.216.85.93:23
            Source: TrafficSnort IDS: 716 INFO TELNET access 103.80.112.238:23 -> 192.168.2.23:40138
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 181.216.85.93:23 -> 192.168.2.23:57614
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42334
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42334
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42340
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42340
            Source: TrafficSnort IDS: 716 INFO TELNET access 1.217.228.22:23 -> 192.168.2.23:58856
            Source: TrafficSnort IDS: 716 INFO TELNET access 181.216.85.93:23 -> 192.168.2.23:57656
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 81.18.201.36:23 -> 192.168.2.23:42366
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 81.18.201.36:23 -> 192.168.2.23:42366
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 181.216.85.93:23 -> 192.168.2.23:57656
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 221.178.131.82:23 -> 192.168.2.23:57214
            Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 68.180.106.57:23 -> 192.168.2.23:44618
            Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 68.180.106.57:23 -> 192.168.2.23:44618
            Source: TrafficSnort IDS: 716 INFO TELNET access 181.216.85.93:23 -> 192.168.2.23:57666
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 181.216.85.93:23 -> 192.168.2.23:57666
            Source: TrafficSnort IDS: 716 INFO TELNET access 203.189.152.57:23 -> 192.168.2.23:43582
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:38408 -> 200.60.4.217:23
            Source: TrafficSnort IDS: 716 INFO TELNET access 181.216.85.93:23 -> 192.168.2.23:57674
            Source: TrafficSnort IDS: 492 INFO TELNET login failed 181.216.85.93:23 -> 192.168.2.23:57674
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:38420 -> 200.60.4.217:23
            Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:57236 -> 221.178.131.82:23
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.231.212.83:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 38.21.102.127:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 61.62.75.59:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 181.120.56.201:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 54.218.103.54:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 94.105.51.120:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 170.66.243.166:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 183.145.45.199:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 126.76.186.241:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 87.236.91.17:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 156.235.158.35:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 23.196.171.59:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 50.246.185.165:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 173.126.88.248:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 12.19.69.182:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 164.208.223.104:2323
            Source: global trafficTCP traffic: 192.168.2.23:47080 -> 95.181.161.40:55005
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 140.95.2.164:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 155.65.71.80:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 59.169.238.71:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 48.59.19.216:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 62.126.231.126:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 171.85.9.238:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 37.128.7.218:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 160.152.135.139:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 190.51.99.64:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 63.226.28.16:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 196.11.123.85:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 198.3.7.63:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 97.146.228.213:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 74.117.53.8:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 40.253.40.126:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 217.140.97.255:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 111.112.217.93:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 48.63.117.174:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 108.12.41.195:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 24.185.130.11:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 40.238.199.160:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 57.252.5.78:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 145.107.241.235:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 53.197.71.250:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 96.55.100.186:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 81.151.113.175:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 125.159.241.2:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.65.162.101:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 43.169.177.248:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 27.102.181.223:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 219.61.68.3:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 92.58.188.73:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 187.180.66.23:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 57.174.90.60:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 25.185.189.231:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 135.226.140.229:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 87.38.234.4:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 41.62.229.239:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 40.46.216.45:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 17.77.228.81:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 147.197.139.32:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 41.191.39.130:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 104.148.21.146:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 120.205.210.203:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 45.195.231.109:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 154.27.219.90:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 58.30.154.241:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 221.109.127.8:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 137.93.125.255:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 25.57.7.238:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 86.219.133.69:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 161.196.21.90:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 59.65.221.42:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 24.175.101.102:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 60.31.107.227:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 123.139.7.64:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 112.230.231.189:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 152.155.99.233:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 216.70.44.236:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 204.113.112.254:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 184.153.159.222:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 96.122.127.113:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 207.185.81.204:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 85.244.144.46:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 153.192.39.116:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 188.224.120.3:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.41.204.127:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 106.64.53.38:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 109.201.235.219:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 191.188.145.102:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 198.96.182.210:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 60.10.112.8:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 104.213.88.165:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 23.209.151.7:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 96.131.76.255:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 123.211.31.7:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 74.166.158.94:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 166.143.12.167:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 120.184.118.35:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 220.248.196.75:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 168.224.212.60:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 111.206.104.55:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 200.115.250.56:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 202.221.255.159:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 41.105.17.120:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 178.81.239.156:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 82.54.60.116:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 128.151.158.87:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 156.23.236.104:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 185.234.228.177:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 118.18.125.180:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 101.154.127.41:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 201.175.105.251:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 123.7.6.76:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 196.190.1.47:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 209.211.229.215:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 96.130.75.186:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 27.157.200.145:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 220.137.124.113:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 113.74.85.202:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 114.34.103.25:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 219.160.155.238:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 173.218.224.211:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 89.90.145.136:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 118.250.32.209:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 141.167.194.245:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 131.200.228.238:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 75.255.24.15:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 173.167.132.52:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 96.232.235.75:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 167.220.161.15:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 24.100.40.124:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 223.235.181.97:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 185.8.36.54:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 166.185.19.13:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 61.11.218.34:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 212.234.137.187:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 108.36.122.23:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 135.153.224.51:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 116.82.118.44:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 163.146.221.169:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 25.38.99.71:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 155.162.203.28:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 183.212.101.134:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 36.118.160.93:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 152.147.125.64:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 52.29.168.22:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 62.43.45.203:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 113.245.84.250:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 107.0.63.100:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 167.186.232.152:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 177.29.151.73:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 164.94.56.231:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 201.64.123.137:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 39.102.161.47:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 32.21.208.24:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 83.200.17.199:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 179.131.52.86:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 80.144.232.33:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.126.43.62:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 47.116.125.69:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 218.9.11.84:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 79.220.191.102:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 39.236.144.201:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 59.21.9.251:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 39.204.25.249:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 148.59.226.246:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 91.194.19.157:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 207.56.251.50:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 166.61.56.230:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 44.159.31.52:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 78.187.167.106:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 153.148.60.160:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 209.242.93.45:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 32.199.166.125:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 5.65.195.76:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 75.76.98.72:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 8.206.129.110:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 145.103.63.225:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 20.61.60.90:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 58.8.85.128:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 117.46.182.9:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 203.47.167.69:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 111.248.238.185:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 193.253.239.212:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 43.29.124.207:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 79.5.30.93:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 203.4.135.116:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 124.118.65.110:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 197.9.247.229:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 210.165.141.230:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 154.78.187.11:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 58.134.12.14:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 74.218.11.170:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 40.39.15.128:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.138.133.248:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 65.20.86.245:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 73.50.17.185:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 100.247.20.164:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 74.212.179.123:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 183.17.134.82:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 168.149.20.89:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 210.77.208.99:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 48.161.198.60:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 160.203.51.206:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 92.194.231.229:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 32.230.63.92:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 66.6.54.195:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 87.154.48.241:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 143.50.246.26:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 92.161.193.212:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 176.99.135.166:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 193.100.197.226:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 53.89.49.10:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 221.87.90.126:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 79.26.243.233:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 139.163.212.55:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 203.23.85.2:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 67.194.175.20:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 223.50.249.23:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 17.211.123.99:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 115.21.68.74:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 205.11.122.11:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 107.83.176.187:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 157.56.59.33:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 97.202.92.0:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 12.44.48.121:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 34.235.16.233:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 138.173.89.159:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 153.55.235.201:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 197.6.252.203:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 76.47.89.56:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 5.22.214.1:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 201.21.34.213:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 161.16.109.56:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 124.59.248.154:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 116.19.152.54:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 81.193.114.233:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 163.216.173.86:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 122.139.0.115:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 194.119.155.221:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 217.169.8.178:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 118.244.133.224:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 13.57.69.255:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 204.159.111.29:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 73.149.56.129:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 163.194.41.7:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 79.47.81.228:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 221.200.208.73:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 76.133.164.163:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 45.142.98.219:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 71.138.3.197:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 58.49.44.204:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 147.219.190.148:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 218.164.116.22:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 204.151.111.240:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 161.113.25.155:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 182.89.12.88:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 125.76.130.26:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 87.28.250.178:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 32.130.203.86:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 97.126.143.142:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 211.252.240.1:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 4.220.25.80:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 205.69.50.13:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 23.86.69.221:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 86.42.155.12:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 48.130.204.6:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 128.12.28.181:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 1.156.181.103:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 164.243.242.60:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 67.74.222.214:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 8.120.54.83:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 72.75.96.21:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 14.130.224.15:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 75.212.91.141:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 121.92.171.22:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 148.188.147.170:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 167.54.192.161:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 13.63.74.236:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 143.187.114.82:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 86.178.5.146:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 186.155.9.255:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 50.249.202.5:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.149.10.104:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 60.119.37.85:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 125.24.102.92:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 207.82.93.56:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 100.187.38.74:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 46.73.180.209:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 144.29.208.73:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 222.237.242.205:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 202.88.190.130:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 34.126.231.201:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 217.50.233.230:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 195.27.16.109:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 54.99.95.39:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 52.204.142.52:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 167.200.146.121:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 14.235.170.40:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 131.42.106.12:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 213.179.186.42:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 51.181.104.76:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 120.53.142.207:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 1.92.131.122:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 94.177.120.169:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 158.15.139.125:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 175.74.140.252:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 188.98.115.137:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 208.201.54.37:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 24.118.54.214:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 102.2.77.198:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 173.105.196.87:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 20.49.40.194:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.168.3.115:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 157.146.141.120:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 207.134.135.165:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 112.50.62.63:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 98.165.174.90:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 140.172.197.152:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 129.128.187.251:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 108.172.79.114:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 130.150.118.128:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 68.245.234.27:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 170.6.131.111:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 9.28.91.254:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 84.49.28.26:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 221.135.167.114:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 97.19.22.180:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 148.73.12.238:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 40.70.8.20:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 195.62.113.89:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 92.11.207.219:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 154.115.210.13:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 161.124.50.1:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 9.112.76.235:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 27.241.218.247:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 62.191.172.130:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 83.61.140.171:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 46.5.220.59:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 1.145.198.149:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 50.238.58.144:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 106.224.162.162:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.83.197.47:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 221.215.242.90:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 186.121.120.22:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 70.106.168.199:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 129.149.185.215:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 162.66.135.87:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.5.78.37:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 47.104.46.174:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 123.96.91.29:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 206.23.70.185:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 209.81.175.251:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 180.4.30.216:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 19.43.152.120:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 91.36.183.68:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 120.120.165.210:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 121.184.153.12:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 18.153.89.132:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 23.19.147.252:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 51.223.134.244:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 158.212.48.199:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 169.229.72.75:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 194.233.186.125:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 169.222.38.203:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 47.43.163.136:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.176.42.64:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 18.185.13.209:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 20.73.51.54:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 218.104.143.93:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 130.8.89.45:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 17.255.145.248:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 202.63.81.152:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 100.160.201.16:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 173.2.58.76:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 48.43.16.213:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 148.73.45.225:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 27.102.240.137:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 155.17.123.39:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 151.159.168.174:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 169.184.36.44:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 154.98.186.231:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 163.66.174.202:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 86.210.31.163:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 49.216.127.189:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 116.200.61.74:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 162.55.116.8:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 74.206.140.146:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 104.101.202.148:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 93.108.148.108:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 133.242.226.85:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 59.153.126.53:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 166.238.240.66:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 213.132.14.85:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 150.123.201.87:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 179.5.230.40:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 113.151.179.65:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 8.132.217.124:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 135.239.120.102:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 164.64.200.187:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.79.15.68:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 25.252.219.16:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.67.163.208:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 92.175.114.192:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 70.66.170.138:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 133.204.177.171:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 189.133.23.91:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 8.95.171.251:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 135.244.53.225:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 66.128.3.86:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 47.77.115.79:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 147.70.71.210:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 4.43.219.184:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 88.184.233.226:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 198.221.212.94:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 101.138.245.241:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 85.90.71.126:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 206.3.218.51:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 145.18.82.137:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 177.72.245.83:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 166.157.52.60:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 112.4.71.37:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 163.109.157.85:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 13.69.205.109:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 123.101.86.147:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 163.22.185.152:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 196.62.1.143:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 150.25.236.34:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 207.54.224.190:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 128.218.16.44:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 107.167.36.208:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 144.121.161.1:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 159.200.239.99:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 137.16.214.207:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 209.36.206.194:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 98.48.128.153:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 178.102.169.26:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 76.154.182.179:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.142.152.90:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 142.249.55.246:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 210.42.93.1:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 96.122.138.152:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 211.247.36.101:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 98.243.76.112:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 41.47.46.69:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 179.86.157.161:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 141.69.251.145:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 126.35.234.124:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 138.181.175.20:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 97.3.131.142:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 2.4.222.24:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 181.93.150.126:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 86.136.28.5:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 157.150.82.225:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 181.172.124.138:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 49.118.230.243:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 168.92.10.110:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 118.141.139.85:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 37.60.29.35:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 31.62.177.79:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 163.253.191.0:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 129.3.88.182:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 13.104.58.220:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 95.34.145.194:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 170.51.237.110:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.124.167.209:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 159.217.158.173:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 222.66.13.237:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 112.165.223.18:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 105.150.238.50:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 72.21.65.204:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 176.249.3.208:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 64.57.71.216:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 217.188.94.83:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 128.158.145.204:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 41.233.218.137:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 145.149.13.165:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 222.27.53.111:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 98.60.80.7:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 218.159.26.167:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 87.49.47.35:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 106.226.93.162:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 25.91.216.29:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 166.204.61.27:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 125.180.161.18:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 194.85.109.14:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 89.166.77.232:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 25.150.133.106:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 196.26.132.109:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 115.229.246.25:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 217.210.84.40:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 173.237.168.121:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 8.137.134.241:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 44.89.237.114:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 126.121.36.125:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 147.223.234.121:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 18.212.144.40:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 160.45.183.189:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 95.43.75.216:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 61.224.11.38:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 196.5.193.148:2323
            Source: global trafficTCP traffic: 192.168.2.23:49014 -> 123.5.56.31:2323
            Source: /tmp/x86 (PID: 5222)Socket: 127.0.0.1::1124
            Source: unknownDNS traffic detected: queries for: arcticboatz.cz
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
            Source: unknownTCP traffic detected without corresponding DNS query: 219.220.101.68
            Source: unknownTCP traffic detected without corresponding DNS query: 84.119.230.83
            Source: unknownTCP traffic detected without corresponding DNS query: 142.231.212.83
            Source: unknownTCP traffic detected without corresponding DNS query: 174.9.182.198
            Source: unknownTCP traffic detected without corresponding DNS query: 140.142.157.105
            Source: unknownTCP traffic detected without corresponding DNS query: 217.156.178.192
            Source: unknownTCP traffic detected without corresponding DNS query: 203.124.80.26
            Source: unknownTCP traffic detected without corresponding DNS query: 38.21.102.127
            Source: unknownTCP traffic detected without corresponding DNS query: 75.188.46.204
            Source: unknownTCP traffic detected without corresponding DNS query: 1.6.194.75
            Source: unknownTCP traffic detected without corresponding DNS query: 148.73.149.41
            Source: unknownTCP traffic detected without corresponding DNS query: 137.142.255.180
            Source: unknownTCP traffic detected without corresponding DNS query: 140.239.1.218
            Source: unknownTCP traffic detected without corresponding DNS query: 167.31.164.83
            Source: unknownTCP traffic detected without corresponding DNS query: 54.142.138.125
            Source: unknownTCP traffic detected without corresponding DNS query: 35.92.121.43
            Source: unknownTCP traffic detected without corresponding DNS query: 196.91.90.25
            Source: unknownTCP traffic detected without corresponding DNS query: 45.235.16.89
            Source: unknownTCP traffic detected without corresponding DNS query: 130.224.198.17
            Source: unknownTCP traffic detected without corresponding DNS query: 90.15.39.230
            Source: unknownTCP traffic detected without corresponding DNS query: 61.62.75.59
            Source: unknownTCP traffic detected without corresponding DNS query: 190.143.236.145
            Source: unknownTCP traffic detected without corresponding DNS query: 221.250.41.134
            Source: unknownTCP traffic detected without corresponding DNS query: 27.185.1.94
            Source: unknownTCP traffic detected without corresponding DNS query: 23.44.64.44
            Source: unknownTCP traffic detected without corresponding DNS query: 152.128.19.125
            Source: unknownTCP traffic detected without corresponding DNS query: 181.120.56.201
            Source: unknownTCP traffic detected without corresponding DNS query: 40.124.152.92
            Source: unknownTCP traffic detected without corresponding DNS query: 4.94.220.105
            Source: unknownTCP traffic detected without corresponding DNS query: 189.64.42.171
            Source: unknownTCP traffic detected without corresponding DNS query: 20.200.55.75
            Source: unknownTCP traffic detected without corresponding DNS query: 129.153.102.24
            Source: unknownTCP traffic detected without corresponding DNS query: 92.169.178.66
            Source: unknownTCP traffic detected without corresponding DNS query: 155.245.169.255
            Source: unknownTCP traffic detected without corresponding DNS query: 25.136.157.196
            Source: unknownTCP traffic detected without corresponding DNS query: 113.192.88.80
            Source: unknownTCP traffic detected without corresponding DNS query: 218.244.141.186
            Source: unknownTCP traffic detected without corresponding DNS query: 31.183.125.132
            Source: unknownTCP traffic detected without corresponding DNS query: 146.98.33.96
            Source: unknownTCP traffic detected without corresponding DNS query: 203.150.88.240
            Source: unknownTCP traffic detected without corresponding DNS query: 221.137.163.178
            Source: unknownTCP traffic detected without corresponding DNS query: 54.218.103.54
            Source: unknownTCP traffic detected without corresponding DNS query: 5.44.129.65
            Source: unknownTCP traffic detected without corresponding DNS query: 94.105.51.120
            Source: unknownTCP traffic detected without corresponding DNS query: 31.225.15.191
            Source: unknownTCP traffic detected without corresponding DNS query: 187.199.202.28
            Source: unknownTCP traffic detected without corresponding DNS query: 64.61.239.13
            Source: unknownTCP traffic detected without corresponding DNS query: 57.247.68.221
            Source: unknownTCP traffic detected without corresponding DNS query: 162.17.96.184
            Source: unknownTCP traffic detected without corresponding DNS query: 200.121.41.161

            System Summary

            barindex
            Source: x86, type: SAMPLEMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
            Source: 5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
            Source: x86, type: SAMPLEMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
            Source: 5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: Initial sampleString containing 'busybox' found: /bin/busybox
            Source: Initial sampleString containing 'busybox' found: fx86_64webserv%s:%darm7ppcm68k/bin/busybox/bin/watchdog/bin/systemd
            Source: classification engineClassification label: mal96.troj.lin@0/0@1/0

            Persistence and Installation Behavior

            barindex
            Source: /bin/sh (PID: 5227)Chmod executable with 777: /usr/bin/chmod -> chmod 777 bin/systemd
            Source: /bin/sh (PID: 5225)Mkdir executable: /usr/bin/mkdir -> mkdir bin
            Source: /usr/bin/chmod (PID: 5227)File: /tmp/bin/systemd (bits: - usr: rwx grp: rwx all: rwx)Jump to behavior
            Source: /bin/sh (PID: 5227)Chmod executable: /usr/bin/chmod -> chmod 777 bin/systemd
            Source: /tmp/x86 (PID: 5223)Shell command executed: sh -c "rm -rf bin/systemd && mkdir bin; >bin/systemd && mv /tmp/x86 bin/systemd; chmod 777 bin/systemd"
            Source: /bin/sh (PID: 5224)Rm executable: /usr/bin/rm -> rm -rf bin/systemd

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: x86, type: SAMPLE
            Source: Yara matchFile source: 5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: x86, type: SAMPLE
            Source: Yara matchFile source: 5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: x86 PID: 5222, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: x86, type: SAMPLE
            Source: Yara matchFile source: 5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: x86, type: SAMPLE
            Source: Yara matchFile source: 5222.1.00000000a0bbd638.00000000b1c13d1a.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: x86 PID: 5222, type: MEMORYSTR
            Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
            Valid Accounts1
            Scripting
            Path InterceptionPath Interception2
            File and Directory Permissions Modification
            OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
            Encrypted Channel
            Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
            Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
            Scripting
            LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
            Non-Standard Port
            Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
            Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
            File Deletion
            Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
            Non-Application Layer Protocol
            Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
            Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer2
            Application Layer Protocol
            SIM Card SwapCarrier Billing Fraud
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 557498 Sample: x86 Startdate: 21/01/2022 Architecture: LINUX Score: 96 25 arcticboatz.cz 2->25 27 205.124.31.118, 23 WEST-NET-WESTUS United States 2->27 29 99 other IPs or domains 2->29 31 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->31 33 Malicious sample detected (through community Yara rule) 2->33 35 Antivirus / Scanner detection for submitted sample 2->35 37 4 other signatures 2->37 8 x86 2->8         started        signatures3 process4 process5 10 x86 sh 8->10         started        12 x86 8->12         started        process6 14 sh chmod 10->14         started        17 sh rm 10->17         started        19 sh mkdir 10->19         started        21 sh mv 10->21         started        23 x86 12->23         started        signatures7 39 Sets full permissions to files and/or directories 14->39
            SourceDetectionScannerLabelLink
            x8636%VirustotalBrowse
            x8653%ReversingLabsLinux.Trojan.Gafgyt
            x86100%AviraLINUX/Gafgyt.vka
            x86100%Joe Sandbox ML
            No Antivirus matches
            SourceDetectionScannerLabelLink
            arcticboatz.cz4%VirustotalBrowse
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            arcticboatz.cz
            95.181.161.40
            truetrueunknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            93.159.75.28
            unknownCroatia (LOCAL Name: Hrvatska)
            5391T-HTCroatianTelecomIncHRfalse
            221.207.171.0
            unknownChina
            4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
            114.156.106.5
            unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
            106.87.226.13
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            72.80.164.124
            unknownUnited States
            701UUNETUSfalse
            157.95.204.143
            unknownUnited States
            29700CYPRESS-SEMICONDUCTORUSfalse
            51.127.189.197
            unknownUnited Kingdom
            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            168.193.156.82
            unknownUnited States
            27435OPSOURCE-INCUSfalse
            2.173.32.247
            unknownGermany
            3320DTAGInternetserviceprovideroperationsDEfalse
            203.86.142.26
            unknownHong Kong
            4760HKTIMS-APHKTLimitedHKfalse
            133.111.13.207
            unknownJapan2497IIJInternetInitiativeJapanIncJPfalse
            188.30.226.8
            unknownUnited Kingdom
            206067H3GUKGBfalse
            77.251.26.232
            unknownNetherlands
            6830LIBERTYGLOBALLibertyGlobalformerlyUPCBroadbandHoldingfalse
            77.11.152.161
            unknownGermany
            6805TDDE-ASN1DEfalse
            221.246.233.161
            unknownJapan17506UCOMARTERIANetworksCorporationJPfalse
            157.146.114.253
            unknownUnited States
            719ELISA-ASHelsinkiFinlandEUfalse
            58.120.90.66
            unknownKorea Republic of
            9318SKB-ASSKBroadbandCoLtdKRfalse
            19.215.98.92
            unknownUnited States
            3MIT-GATEWAYSUSfalse
            24.181.167.141
            unknownUnited States
            20115CHARTER-20115USfalse
            72.22.196.243
            unknownUnited States
            62648CMB-ASNUSfalse
            150.192.43.49
            unknownUnited States
            1479DNIC-ASBLK-01478-01479USfalse
            131.40.166.4
            unknownUnited States
            452AFCONC-BLOCK1-ASUSfalse
            95.104.118.215
            unknownGeorgia
            16010MAGTICOMASCaucasus-OnlineGEfalse
            178.252.213.17
            unknownRussian Federation
            24689ROSINTEL-ASRUfalse
            210.222.91.114
            unknownKorea Republic of
            4766KIXS-AS-KRKoreaTelecomKRfalse
            118.250.121.168
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            133.107.241.23
            unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
            27.153.37.134
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            205.124.31.118
            unknownUnited States
            210WEST-NET-WESTUSfalse
            165.68.7.86
            unknownUnited States
            29885UCHHS-ASUSfalse
            147.51.71.88
            unknownUnited States
            1491DNIC-AS-01491USfalse
            186.1.227.220
            unknownArgentina
            52251NORTECHARfalse
            176.153.184.104
            unknownFrance
            5410BOUYGTEL-ISPFRfalse
            206.246.3.148
            unknownUnited States
            27258KAMOPOWERUSfalse
            125.6.109.58
            unknownJapan17707DATAHOTEL-JPASforDATAHOTELwhichisoneofiDCinJapanfalse
            45.25.135.219
            unknownUnited States
            7018ATT-INTERNET4USfalse
            174.156.87.240
            unknownUnited States
            10507SPCSUSfalse
            166.119.39.139
            unknownJapan131790SANOFI-SG6RafflesQuay18-00SGfalse
            13.66.19.93
            unknownUnited States
            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
            71.82.198.43
            unknownUnited States
            20115CHARTER-20115USfalse
            218.158.83.43
            unknownKorea Republic of
            4766KIXS-AS-KRKoreaTelecomKRfalse
            222.35.64.191
            unknownChina
            24138CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
            61.111.155.62
            unknownKorea Republic of
            4670HYUNDAI-KRShinbiroKRfalse
            139.189.85.92
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            197.39.112.164
            unknownEgypt
            8452TE-ASTE-ASEGfalse
            24.118.54.214
            unknownUnited States
            7922COMCAST-7922USfalse
            159.38.88.62
            unknownSweden
            19399SLLNETEUfalse
            20.138.253.203
            unknownUnited States
            22562CSC-IGN-EMEAUSfalse
            166.157.52.60
            unknownUnited States
            22394CELLCOUSfalse
            118.142.173.236
            unknownHong Kong
            9304HUTCHISON-AS-APHGCGlobalCommunicationsLimitedHKfalse
            170.109.110.70
            unknownUnited States
            7018ATT-INTERNET4USfalse
            118.182.191.81
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            157.111.35.111
            unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
            48.158.241.178
            unknownUnited States
            2686ATGS-MMD-ASUSfalse
            45.228.1.204
            unknownBrazil
            267054LINKWAYTELECOMBRfalse
            42.70.155.245
            unknownTaiwan; Republic of China (ROC)
            17421EMOME-NETMobileBusinessGroupTWfalse
            135.91.191.89
            unknownUnited States
            10455LUCENT-CIOUSfalse
            103.159.15.26
            unknownunknown
            134687TWIDC-AS-APTWIDCLimitedHKfalse
            43.139.190.48
            unknownJapan4249LILLY-ASUSfalse
            69.68.215.177
            unknownUnited States
            18494CENTURYLINK-LEGACY-EMBARQ-WRBGUSfalse
            121.88.133.138
            unknownKorea Republic of
            10036CNM-AS-KRDLIVEKRfalse
            27.92.184.219
            unknownJapan2516KDDIKDDICORPORATIONJPfalse
            103.17.68.226
            unknownBangladesh
            58814BANKASIALIMITED-AS-APBankAsiaLimitedBDfalse
            102.212.38.252
            unknownunknown
            36926CKL1-ASNKEfalse
            64.61.239.13
            unknownUnited States
            32946RPU-1892USfalse
            169.196.167.204
            unknownUnited States
            20249AS20249USfalse
            134.59.211.185
            unknownFrance
            2200FR-RENATERReseauNationaldetelecommunicationspourlaTecfalse
            18.227.222.44
            unknownUnited States
            16509AMAZON-02USfalse
            24.119.81.142
            unknownUnited States
            11492CABLEONEUSfalse
            165.91.25.157
            unknownUnited States
            3794TAMUUSfalse
            164.53.91.16
            unknownAustralia
            10235NAB-AS-APNationalAustraliaBankLimitedAUfalse
            5.40.77.248
            unknownSpain
            207412JUSTOESfalse
            43.199.125.167
            unknownJapan4249LILLY-ASUSfalse
            187.212.87.3
            unknownMexico
            8151UninetSAdeCVMXfalse
            121.92.171.22
            unknownJapan2510INFOWEBFUJITSULIMITEDJPfalse
            31.225.15.191
            unknownGermany
            3320DTAGInternetserviceprovideroperationsDEfalse
            83.27.125.187
            unknownPoland
            5617TPNETPLfalse
            169.105.87.50
            unknownUnited States
            37611AfrihostZAfalse
            208.145.68.220
            unknownUnited States
            3561CENTURYLINK-LEGACY-SAVVISUSfalse
            76.166.83.90
            unknownUnited States
            20001TWC-20001-PACWESTUSfalse
            84.58.245.7
            unknownGermany
            3209VODANETInternationalIP-BackboneofVodafoneDEfalse
            165.122.99.65
            unknownUnited States
            3376MCI-ASNUSfalse
            121.57.253.53
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            101.235.253.19
            unknownKorea Republic of
            10036CNM-AS-KRDLIVEKRfalse
            149.123.223.163
            unknownUnited States
            174COGENT-174USfalse
            192.215.186.199
            unknownUnited States
            4266CERNET-ASN-BLOCKUSfalse
            142.142.45.130
            unknownCanada
            808GONET-ASN-1CAfalse
            79.81.192.121
            unknownFrance
            15557LDCOMNETFRfalse
            84.123.88.75
            unknownSpain
            12357COMUNITELSPAINESfalse
            150.30.62.61
            unknownJapan7516TOHKNETTohokuIntelligentTelecommunicationCoIncJPfalse
            219.50.108.55
            unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
            78.180.254.88
            unknownTurkey
            9121TTNETTRfalse
            1.63.17.173
            unknownChina
            4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
            141.25.92.54
            unknownGermany
            680DFNVereinzurFoerderungeinesDeutschenForschungsnetzesefalse
            94.157.167.179
            unknownNetherlands
            50266TMOBILE-THUISNLfalse
            133.116.140.222
            unknownJapan2522PPP-EXPJapanNetworkInformationCenterJPfalse
            60.87.24.58
            unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
            91.159.84.100
            unknownFinland
            719ELISA-ASHelsinkiFinlandEUfalse
            140.65.179.96
            unknownUnited States
            23700FASTNET-AS-IDLinknet-FastnetASNIDfalse
            211.175.192.49
            unknownKorea Republic of
            9457DREAMX-ASDREAMLINECOKRfalse
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
            Entropy (8bit):6.341796052094503
            TrID:
            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
            File name:x86
            File size:74656
            MD5:1780fa4bcc6aa107d0bbbc7bf00dfd0a
            SHA1:9f8a838e4b0f42289cb04c047b4534f4d034e90f
            SHA256:0033a14ee6ebda0d95e4b9db23926c1fc0a201c8d51fa3beabd2409a3b5c5d97
            SHA512:14252ac161a4a741e0a8e9a0111c15950a901710b8c027489389543f891f4de8e8e2fd0a6b6f0597b6d27a5cc6f8ca0f50c5e863a836b449b17551ed49f41851
            SSDEEP:1536:9DbhNzyVTW72M0p6jI2n4ms0QpRm8yfjChkgUDQHQzeTBnk9:9RNzgoRY6jbn9sl48GChklQHQzeTBnk9
            File Content Preview:.ELF..............>.......@.....@....... !..........@.8...@.......................@.......@.....p.......p.......................x.......x.Q.....x.Q.....h........1..............Q.td....................................................H...._........H........

            ELF header

            Class:ELF64
            Data:2's complement, little endian
            Version:1 (current)
            Machine:Advanced Micro Devices X86-64
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - System V
            ABI Version:0
            Entry Point Address:0x400194
            Flags:0x0
            ELF Header Size:64
            Program Header Offset:64
            Program Header Size:56
            Number of Program Headers:3
            Section Header Offset:74016
            Section Header Size:64
            Number of Section Headers:10
            Header String Table Index:9
            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
            NULL0x00x00x00x00x0000
            .initPROGBITS0x4000e80xe80x130x00x6AX001
            .textPROGBITS0x4001000x1000xf8160x00x6AX0016
            .finiPROGBITS0x40f9160xf9160xe0x00x6AX001
            .rodataPROGBITS0x40f9400xf9400x23300x00x2A0032
            .ctorsPROGBITS0x511c780x11c780x100x00x3WA008
            .dtorsPROGBITS0x511c880x11c880x100x00x3WA008
            .dataPROGBITS0x511ca00x11ca00x4400x00x3WA0032
            .bssNOBITS0x5120e00x120e00x2ca80x00x3WA0032
            .shstrtabSTRTAB0x00x120e00x3e0x00x0001
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00x4000000x4000000x11c700x11c703.75700x5R E0x100000.init .text .fini .rodata
            LOAD0x11c780x511c780x511c780x4680x31101.42400x6RW 0x100000.ctors .dtors .data .bss
            GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
            TimestampSource PortDest PortSource IPDest IP
            Jan 21, 2022 08:26:57.663871050 CET4901423192.168.2.23219.220.101.68
            Jan 21, 2022 08:26:57.663883924 CET4901423192.168.2.2384.119.230.83
            Jan 21, 2022 08:26:57.663909912 CET490142323192.168.2.23142.231.212.83
            Jan 21, 2022 08:26:57.663922071 CET4901423192.168.2.23174.9.182.198
            Jan 21, 2022 08:26:57.663932085 CET4901423192.168.2.23140.142.157.105
            Jan 21, 2022 08:26:57.663935900 CET4901423192.168.2.23217.156.178.192
            Jan 21, 2022 08:26:57.663940907 CET4901423192.168.2.23203.124.80.26
            Jan 21, 2022 08:26:57.663942099 CET490142323192.168.2.2338.21.102.127
            Jan 21, 2022 08:26:57.663947105 CET4901423192.168.2.2375.188.46.204
            Jan 21, 2022 08:26:57.663952112 CET4901423192.168.2.231.6.194.75
            Jan 21, 2022 08:26:57.663958073 CET4901423192.168.2.23148.73.149.41
            Jan 21, 2022 08:26:57.663954973 CET4901423192.168.2.23137.142.255.180
            Jan 21, 2022 08:26:57.663953066 CET4901423192.168.2.23140.239.1.218
            Jan 21, 2022 08:26:57.663964033 CET4901423192.168.2.23167.31.164.83
            Jan 21, 2022 08:26:57.663969040 CET4901423192.168.2.2354.142.138.125
            Jan 21, 2022 08:26:57.663970947 CET4901423192.168.2.2335.92.121.43
            Jan 21, 2022 08:26:57.663974047 CET4901423192.168.2.23196.91.90.25
            Jan 21, 2022 08:26:57.663980961 CET4901423192.168.2.2345.235.16.89
            Jan 21, 2022 08:26:57.663985968 CET4901423192.168.2.23130.224.198.17
            Jan 21, 2022 08:26:57.663989067 CET4901423192.168.2.2390.15.39.230
            Jan 21, 2022 08:26:57.663991928 CET490142323192.168.2.2361.62.75.59
            Jan 21, 2022 08:26:57.663995981 CET4901423192.168.2.23190.143.236.145
            Jan 21, 2022 08:26:57.663997889 CET4901423192.168.2.23221.250.41.134
            Jan 21, 2022 08:26:57.664005995 CET4901423192.168.2.2327.185.1.94
            Jan 21, 2022 08:26:57.664012909 CET4901423192.168.2.2323.44.64.44
            Jan 21, 2022 08:26:57.664016008 CET4901423192.168.2.23152.128.19.125
            Jan 21, 2022 08:26:57.664020061 CET490142323192.168.2.23181.120.56.201
            Jan 21, 2022 08:26:57.664022923 CET4901423192.168.2.2340.124.152.92
            Jan 21, 2022 08:26:57.664027929 CET4901423192.168.2.234.94.220.105
            Jan 21, 2022 08:26:57.664035082 CET4901423192.168.2.23189.64.42.171
            Jan 21, 2022 08:26:57.664037943 CET4901423192.168.2.2320.200.55.75
            Jan 21, 2022 08:26:57.664040089 CET4901423192.168.2.23129.153.102.24
            Jan 21, 2022 08:26:57.664045095 CET4901423192.168.2.2392.169.178.66
            Jan 21, 2022 08:26:57.664048910 CET4901423192.168.2.23155.245.169.255
            Jan 21, 2022 08:26:57.665641069 CET4901423192.168.2.2325.136.157.196
            Jan 21, 2022 08:26:57.665677071 CET4901423192.168.2.23113.192.88.80
            Jan 21, 2022 08:26:57.665695906 CET4901423192.168.2.23218.244.141.186
            Jan 21, 2022 08:26:57.665707111 CET4901423192.168.2.2331.183.125.132
            Jan 21, 2022 08:26:57.665709972 CET4901423192.168.2.23146.98.33.96
            Jan 21, 2022 08:26:57.665710926 CET4901423192.168.2.23203.150.88.240
            Jan 21, 2022 08:26:57.665715933 CET4901423192.168.2.23221.137.163.178
            Jan 21, 2022 08:26:57.665728092 CET490142323192.168.2.2354.218.103.54
            Jan 21, 2022 08:26:57.665741920 CET4901423192.168.2.235.44.129.65
            Jan 21, 2022 08:26:57.665745020 CET490142323192.168.2.2394.105.51.120
            Jan 21, 2022 08:26:57.665750980 CET4901423192.168.2.2331.225.15.191
            Jan 21, 2022 08:26:57.665754080 CET4901423192.168.2.23187.199.202.28
            Jan 21, 2022 08:26:57.665756941 CET4901423192.168.2.2364.61.239.13
            Jan 21, 2022 08:26:57.665756941 CET4901423192.168.2.2357.247.68.221
            Jan 21, 2022 08:26:57.665757895 CET4901423192.168.2.23162.17.96.184
            Jan 21, 2022 08:26:57.665760994 CET4901423192.168.2.23200.121.41.161
            Jan 21, 2022 08:26:57.665766001 CET4901423192.168.2.2396.24.95.245
            Jan 21, 2022 08:26:57.665771961 CET4901423192.168.2.23166.254.220.116
            Jan 21, 2022 08:26:57.665775061 CET4901423192.168.2.2382.232.93.98
            Jan 21, 2022 08:26:57.665779114 CET4901423192.168.2.23186.96.207.198
            Jan 21, 2022 08:26:57.665783882 CET4901423192.168.2.23158.37.53.244
            Jan 21, 2022 08:26:57.665785074 CET4901423192.168.2.23209.8.83.238
            Jan 21, 2022 08:26:57.665786028 CET4901423192.168.2.23114.71.235.203
            Jan 21, 2022 08:26:57.665787935 CET4901423192.168.2.23145.100.65.102
            Jan 21, 2022 08:26:57.665793896 CET4901423192.168.2.2338.57.185.204
            Jan 21, 2022 08:26:57.665796995 CET4901423192.168.2.2394.164.163.3
            Jan 21, 2022 08:26:57.665800095 CET4901423192.168.2.23136.187.160.177
            Jan 21, 2022 08:26:57.665802956 CET4901423192.168.2.23155.61.135.174
            Jan 21, 2022 08:26:57.665803909 CET4901423192.168.2.23172.198.3.225
            Jan 21, 2022 08:26:57.665810108 CET4901423192.168.2.23161.154.190.104
            Jan 21, 2022 08:26:57.665812969 CET4901423192.168.2.23109.134.70.233
            Jan 21, 2022 08:26:57.665812969 CET490142323192.168.2.23170.66.243.166
            Jan 21, 2022 08:26:57.665819883 CET4901423192.168.2.23122.177.155.216
            Jan 21, 2022 08:26:57.665831089 CET4901423192.168.2.23223.39.249.103
            Jan 21, 2022 08:26:57.665834904 CET4901423192.168.2.2345.50.163.26
            Jan 21, 2022 08:26:57.665846109 CET4901423192.168.2.23163.46.208.131
            Jan 21, 2022 08:26:57.665848970 CET4901423192.168.2.2320.142.16.35
            Jan 21, 2022 08:26:57.665851116 CET4901423192.168.2.23100.224.207.209
            Jan 21, 2022 08:26:57.665854931 CET4901423192.168.2.23104.178.105.237
            Jan 21, 2022 08:26:57.665858030 CET4901423192.168.2.23188.124.233.55
            Jan 21, 2022 08:26:57.665859938 CET4901423192.168.2.23181.118.6.21
            Jan 21, 2022 08:26:57.665875912 CET4901423192.168.2.2335.201.25.179
            Jan 21, 2022 08:26:57.665894985 CET490142323192.168.2.23183.145.45.199
            Jan 21, 2022 08:26:57.665904999 CET4901423192.168.2.231.244.47.176
            Jan 21, 2022 08:26:57.665904045 CET4901423192.168.2.2389.49.84.211
            Jan 21, 2022 08:26:57.665915012 CET4901423192.168.2.23136.29.252.171
            Jan 21, 2022 08:26:57.665915966 CET4901423192.168.2.2354.47.170.226
            Jan 21, 2022 08:26:57.665915966 CET4901423192.168.2.23189.62.14.115
            Jan 21, 2022 08:26:57.665920019 CET4901423192.168.2.2335.243.37.190
            Jan 21, 2022 08:26:57.665920973 CET4901423192.168.2.23122.174.108.173
            Jan 21, 2022 08:26:57.665925980 CET4901423192.168.2.23118.249.151.85
            Jan 21, 2022 08:26:57.665927887 CET4901423192.168.2.2365.78.192.175
            Jan 21, 2022 08:26:57.665934086 CET4901423192.168.2.23222.239.196.121
            Jan 21, 2022 08:26:57.665941954 CET490142323192.168.2.23126.76.186.241
            Jan 21, 2022 08:26:57.665949106 CET4901423192.168.2.2325.197.223.197
            Jan 21, 2022 08:26:57.665951014 CET4901423192.168.2.23176.192.132.185
            Jan 21, 2022 08:26:57.665958881 CET4901423192.168.2.23202.193.62.212
            Jan 21, 2022 08:26:57.665960073 CET4901423192.168.2.23144.0.14.9
            Jan 21, 2022 08:26:57.665967941 CET4901423192.168.2.23113.228.173.202
            Jan 21, 2022 08:26:57.665970087 CET4901423192.168.2.23168.25.135.197
            Jan 21, 2022 08:26:57.665977955 CET4901423192.168.2.23135.31.63.152
            Jan 21, 2022 08:26:57.665978909 CET4901423192.168.2.2385.242.80.9
            Jan 21, 2022 08:26:57.665992022 CET490142323192.168.2.2387.236.91.17
            Jan 21, 2022 08:26:57.665994883 CET4901423192.168.2.23192.67.19.59
            Jan 21, 2022 08:26:57.665999889 CET4901423192.168.2.23130.169.128.7
            Jan 21, 2022 08:26:57.666001081 CET4901423192.168.2.23200.90.143.78
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
            Jan 21, 2022 08:26:57.663700104 CET192.168.2.238.8.8.80xbae5Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
            Jan 21, 2022 08:26:57.679620981 CET8.8.8.8192.168.2.230xbae5No error (0)arcticboatz.cz95.181.161.40A (IP address)IN (0x0001)

            System Behavior

            Start time:08:26:56
            Start date:21/01/2022
            Path:/tmp/x86
            Arguments:/tmp/x86
            File size:74656 bytes
            MD5 hash:1780fa4bcc6aa107d0bbbc7bf00dfd0a
            Start time:08:26:56
            Start date:21/01/2022
            Path:/tmp/x86
            Arguments:n/a
            File size:74656 bytes
            MD5 hash:1780fa4bcc6aa107d0bbbc7bf00dfd0a
            Start time:08:26:56
            Start date:21/01/2022
            Path:/bin/sh
            Arguments:sh -c "rm -rf bin/systemd && mkdir bin; >bin/systemd && mv /tmp/x86 bin/systemd; chmod 777 bin/systemd"
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
            Start time:08:26:56
            Start date:21/01/2022
            Path:/bin/sh
            Arguments:n/a
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
            Start time:08:26:56
            Start date:21/01/2022
            Path:/usr/bin/rm
            Arguments:rm -rf bin/systemd
            File size:72056 bytes
            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b
            Start time:08:26:56
            Start date:21/01/2022
            Path:/bin/sh
            Arguments:n/a
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
            Start time:08:26:56
            Start date:21/01/2022
            Path:/usr/bin/mkdir
            Arguments:mkdir bin
            File size:88408 bytes
            MD5 hash:088c9d1df5a28ed16c726eca15964cb7
            Start time:08:26:56
            Start date:21/01/2022
            Path:/bin/sh
            Arguments:n/a
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
            Start time:08:26:56
            Start date:21/01/2022
            Path:/usr/bin/mv
            Arguments:mv /tmp/x86 bin/systemd
            File size:149888 bytes
            MD5 hash:504f0590fa482d4da070a702260e3716
            Start time:08:26:56
            Start date:21/01/2022
            Path:/bin/sh
            Arguments:n/a
            File size:129816 bytes
            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
            Start time:08:26:56
            Start date:21/01/2022
            Path:/usr/bin/chmod
            Arguments:chmod 777 bin/systemd
            File size:63864 bytes
            MD5 hash:739483b900c045ae1374d6f53a86a279
            Start time:08:26:56
            Start date:21/01/2022
            Path:/tmp/x86
            Arguments:n/a
            File size:74656 bytes
            MD5 hash:1780fa4bcc6aa107d0bbbc7bf00dfd0a
            Start time:08:26:56
            Start date:21/01/2022
            Path:/tmp/x86
            Arguments:n/a
            File size:74656 bytes
            MD5 hash:1780fa4bcc6aa107d0bbbc7bf00dfd0a