Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86

Overview

General Information

Sample Name:x86
Analysis ID:634909
MD5:dd2cc276434817909826bfcae05dbf9c
SHA1:488ac1c5a8a93279418b67e6f51e01afbc6299b1
SHA256:7b1b6a74884932bd6d593f68075b186828729bb9f462a092003059a0761c6fa0
Tags:Mirai
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Sample is packed with UPX
Uses known network protocols on non-standard ports
Connects to many ports of the same IP (likely port scanning)
Sample contains only a LOAD segment without any section mappings
Yara signature match
HTTP GET or POST without a user agent
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:634909
Start date and time: 27/05/202202:07:202022-05-27 02:07:20 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 53s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:x86
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal76.troj.evad.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
Command:/tmp/x86
PID:6229
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Infected
Standard Error:
  • system is lnxubuntu20
  • x86 (PID: 6229, Parent: 6123, MD5: dd2cc276434817909826bfcae05dbf9c) Arguments: /tmp/x86
    • x86 New Fork (PID: 6230, Parent: 6229)
    • x86 New Fork (PID: 6231, Parent: 6229)
    • x86 New Fork (PID: 6232, Parent: 6229)
    • x86 New Fork (PID: 6234, Parent: 6229)
    • x86 New Fork (PID: 6235, Parent: 6229)
    • x86 New Fork (PID: 6236, Parent: 6229)
      • x86 New Fork (PID: 6237, Parent: 6236)
        • x86 New Fork (PID: 6242, Parent: 6237)
          • x86 New Fork (PID: 6243, Parent: 6242)
      • x86 New Fork (PID: 6238, Parent: 6236)
        • x86 New Fork (PID: 6239, Parent: 6238)
  • cleanup
SourceRuleDescriptionAuthorStrings
x86SUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x862d:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x85d9:$s2: $Id: UPX
  • 0x858a:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    Timestamp:192.168.2.23156.250.93.8739206372152835222 05/27/22-02:08:33.177869
    SID:2835222
    Source Port:39206
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.24.6940130528692027339 05/27/22-02:09:00.827653
    SID:2027339
    Source Port:40130
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23197.234.54.1842104528692027339 05/27/22-02:10:32.535224
    SID:2027339
    Source Port:42104
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.247.27.8644956372152835222 05/27/22-02:10:13.396894
    SID:2835222
    Source Port:44956
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.230.16.24141418528692027339 05/27/22-02:11:24.285083
    SID:2027339
    Source Port:41418
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.84.756426528692027339 05/27/22-02:08:22.102752
    SID:2027339
    Source Port:56426
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.53.9946340372152835222 05/27/22-02:10:43.079477
    SID:2835222
    Source Port:46340
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.57.2934364372152835222 05/27/22-02:09:32.396300
    SID:2835222
    Source Port:34364
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.65.737558372152835222 05/27/22-02:11:40.615594
    SID:2835222
    Source Port:37558
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.46.22259016372152835222 05/27/22-02:09:12.267726
    SID:2835222
    Source Port:59016
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.9.1435518372152835222 05/27/22-02:09:37.298229
    SID:2835222
    Source Port:35518
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.237.4.8935620528692027339 05/27/22-02:08:18.022137
    SID:2027339
    Source Port:35620
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23197.244.6.13260688372152835222 05/27/22-02:11:35.486635
    SID:2835222
    Source Port:60688
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.83.23038942528692027339 05/27/22-02:11:00.895084
    SID:2027339
    Source Port:38942
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.57.16249686372152835222 05/27/22-02:11:38.284833
    SID:2835222
    Source Port:49686
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.15.19943960528692027339 05/27/22-02:08:40.142785
    SID:2027339
    Source Port:43960
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.232.95.9540206528692027339 05/27/22-02:09:03.642497
    SID:2027339
    Source Port:40206
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.50.13048170372152835222 05/27/22-02:11:01.224831
    SID:2835222
    Source Port:48170
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.81.25147706528692027339 05/27/22-02:08:21.597378
    SID:2027339
    Source Port:47706
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23197.246.130.19353610372152835222 05/27/22-02:10:23.280523
    SID:2835222
    Source Port:53610
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.14.9145970372152835222 05/27/22-02:09:53.701760
    SID:2835222
    Source Port:45970
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.49.14137104528692027339 05/27/22-02:09:43.731334
    SID:2027339
    Source Port:37104
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.104.21844966528692027339 05/27/22-02:08:57.958817
    SID:2027339
    Source Port:44966
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.83.23846190528692027339 05/27/22-02:10:06.162481
    SID:2027339
    Source Port:46190
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.18.22549052528692027339 05/27/22-02:09:53.684714
    SID:2027339
    Source Port:49052
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.125.6237340528692027339 05/27/22-02:11:33.720909
    SID:2027339
    Source Port:37340
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.124.10938974528692027339 05/27/22-02:11:18.631762
    SID:2027339
    Source Port:38974
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.66.1860368528692027339 05/27/22-02:08:52.410969
    SID:2027339
    Source Port:60368
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.59.14052754528692027339 05/27/22-02:09:57.822412
    SID:2027339
    Source Port:52754
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.245.61.3048640372152835222 05/27/22-02:10:17.308980
    SID:2835222
    Source Port:48640
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.156.9551950528692027339 05/27/22-02:09:28.759032
    SID:2027339
    Source Port:51950
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.83.957132528692027339 05/27/22-02:09:29.972143
    SID:2027339
    Source Port:57132
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.76.10743068372152835222 05/27/22-02:11:21.094478
    SID:2835222
    Source Port:43068
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.48.24657230372152835222 05/27/22-02:09:58.042780
    SID:2835222
    Source Port:57230
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.232.91.17258270528692027339 05/27/22-02:10:30.263985
    SID:2027339
    Source Port:58270
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.12.25238678528692027339 05/27/22-02:11:09.420455
    SID:2027339
    Source Port:38678
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.100.17052070528692027339 05/27/22-02:08:50.822129
    SID:2027339
    Source Port:52070
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.71.17636978372152835222 05/27/22-02:10:06.822295
    SID:2835222
    Source Port:36978
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.83.11836290528692027339 05/27/22-02:10:30.670300
    SID:2027339
    Source Port:36290
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.245.52.18539754372152835222 05/27/22-02:09:58.350586
    SID:2835222
    Source Port:39754
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.124.5350918372152835222 05/27/22-02:10:25.902125
    SID:2835222
    Source Port:50918
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.55.15933966528692027339 05/27/22-02:09:18.155424
    SID:2027339
    Source Port:33966
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.230.29.15354968372152835222 05/27/22-02:08:26.153652
    SID:2835222
    Source Port:54968
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.114.1555964528692027339 05/27/22-02:09:34.521201
    SID:2027339
    Source Port:55964
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.110.4135590372152835222 05/27/22-02:08:28.884045
    SID:2835222
    Source Port:35590
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.61.4946618528692027339 05/27/22-02:11:37.374060
    SID:2027339
    Source Port:46618
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.105.19141054372152835222 05/27/22-02:08:35.767046
    SID:2835222
    Source Port:41054
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.111.5143178528692027339 05/27/22-02:09:09.317807
    SID:2027339
    Source Port:43178
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.106.4336000372152835222 05/27/22-02:08:29.297365
    SID:2835222
    Source Port:36000
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.235.100.5836954372152835222 05/27/22-02:09:15.931366
    SID:2835222
    Source Port:36954
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.75.6750076372152835222 05/27/22-02:10:08.340696
    SID:2835222
    Source Port:50076
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.91.22143548528692027339 05/27/22-02:09:55.382680
    SID:2027339
    Source Port:43548
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.227.247.2751180528692027339 05/27/22-02:10:43.763059
    SID:2027339
    Source Port:51180
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.60.10438956528692027339 05/27/22-02:10:48.266273
    SID:2027339
    Source Port:38956
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.157.18759464372152835222 05/27/22-02:08:53.696489
    SID:2835222
    Source Port:59464
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.237.4.6736916372152835222 05/27/22-02:11:17.791572
    SID:2835222
    Source Port:36916
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.84.16440172372152835222 05/27/22-02:10:51.345888
    SID:2835222
    Source Port:40172
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.32.15060216372152835222 05/27/22-02:09:40.857295
    SID:2835222
    Source Port:60216
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.45.24846018528692027339 05/27/22-02:11:20.133049
    SID:2027339
    Source Port:46018
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.105.1741684372152835222 05/27/22-02:09:12.291544
    SID:2835222
    Source Port:41684
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.99.4237202528692027339 05/27/22-02:09:02.324425
    SID:2027339
    Source Port:37202
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.48.16057224372152835222 05/27/22-02:10:51.813172
    SID:2835222
    Source Port:57224
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.115.13256142528692027339 05/27/22-02:11:13.871917
    SID:2027339
    Source Port:56142
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.53.21360200528692027339 05/27/22-02:08:14.394908
    SID:2027339
    Source Port:60200
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.235.101.16839478372152835222 05/27/22-02:10:53.778904
    SID:2835222
    Source Port:39478
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.134.11352950528692027339 05/27/22-02:08:36.519508
    SID:2027339
    Source Port:52950
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.83.24250786528692027339 05/27/22-02:09:18.812829
    SID:2027339
    Source Port:50786
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.240.109.21449218372152835222 05/27/22-02:08:14.477325
    SID:2835222
    Source Port:49218
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.60.12339346528692027339 05/27/22-02:08:22.605255
    SID:2027339
    Source Port:39346
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.57.7834732528692027339 05/27/22-02:08:43.981312
    SID:2027339
    Source Port:34732
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.232.94.4342736528692027339 05/27/22-02:10:21.505947
    SID:2027339
    Source Port:42736
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.12.24860452528692027339 05/27/22-02:08:27.549152
    SID:2027339
    Source Port:60452
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.159.24341980372152835222 05/27/22-02:10:22.350636
    SID:2835222
    Source Port:41980
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.48.2244644372152835222 05/27/22-02:08:29.535468
    SID:2835222
    Source Port:44644
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.98.141024372152835222 05/27/22-02:09:54.170376
    SID:2835222
    Source Port:41024
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.157.12057534372152835222 05/27/22-02:11:17.707201
    SID:2835222
    Source Port:57534
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.158.11554628528692027339 05/27/22-02:08:26.078418
    SID:2027339
    Source Port:54628
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.46.13051012372152835222 05/27/22-02:08:10.935380
    SID:2835222
    Source Port:51012
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.2341.62.7.22358304372152835222 05/27/22-02:10:35.523318
    SID:2835222
    Source Port:58304
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.235.103.4838150528692027339 05/27/22-02:09:25.534555
    SID:2027339
    Source Port:38150
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.84.13952358372152835222 05/27/22-02:09:41.217219
    SID:2835222
    Source Port:52358
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.85.3937246372152835222 05/27/22-02:11:23.623877
    SID:2835222
    Source Port:37246
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.247.25.3538820372152835222 05/27/22-02:11:20.375770
    SID:2835222
    Source Port:38820
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.77.18151046372152835222 05/27/22-02:09:23.282743
    SID:2835222
    Source Port:51046
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.8.10353864372152835222 05/27/22-02:11:33.449825
    SID:2835222
    Source Port:53864
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.79.3043096372152835222 05/27/22-02:09:09.801782
    SID:2835222
    Source Port:43096
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.55.21659548528692027339 05/27/22-02:08:23.171560
    SID:2027339
    Source Port:59548
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.11.17238258372152835222 05/27/22-02:10:56.310971
    SID:2835222
    Source Port:38258
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.83.23437172372152835222 05/27/22-02:09:32.387384
    SID:2835222
    Source Port:37172
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.56.4441860372152835222 05/27/22-02:10:01.946094
    SID:2835222
    Source Port:41860
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.100.8537612528692027339 05/27/22-02:10:30.635250
    SID:2027339
    Source Port:37612
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.112.4243040528692027339 05/27/22-02:11:14.191934
    SID:2027339
    Source Port:43040
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.100.9660928528692027339 05/27/22-02:08:29.558143
    SID:2027339
    Source Port:60928
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.91.20143670372152835222 05/27/22-02:10:03.247807
    SID:2835222
    Source Port:43670
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.122.14742696528692027339 05/27/22-02:10:00.571062
    SID:2027339
    Source Port:42696
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.146.56.19850788372152835222 05/27/22-02:08:19.953487
    SID:2835222
    Source Port:50788
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.77.2537124528692027339 05/27/22-02:09:45.222920
    SID:2027339
    Source Port:37124
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.66.1634728528692027339 05/27/22-02:08:45.208279
    SID:2027339
    Source Port:34728
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.97.2944914372152835222 05/27/22-02:09:12.248751
    SID:2835222
    Source Port:44914
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.240.110.8150836372152835222 05/27/22-02:11:33.412288
    SID:2835222
    Source Port:50836
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.15.18539824372152835222 05/27/22-02:09:57.802052
    SID:2835222
    Source Port:39824
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.141.10648574528692027339 05/27/22-02:10:30.276060
    SID:2027339
    Source Port:48574
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.83.3747286528692027339 05/27/22-02:10:58.308624
    SID:2027339
    Source Port:47286
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.245.59.18456924528692027339 05/27/22-02:08:15.406066
    SID:2027339
    Source Port:56924
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.110.2840570528692027339 05/27/22-02:10:58.269854
    SID:2027339
    Source Port:40570
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.247.29.4133758372152835222 05/27/22-02:11:18.771854
    SID:2835222
    Source Port:33758
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.110.14560086372152835222 05/27/22-02:08:55.233600
    SID:2835222
    Source Port:60086
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.10.24846788528692027339 05/27/22-02:09:42.672044
    SID:2027339
    Source Port:46788
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.87.6448366528692027339 05/27/22-02:09:54.137565
    SID:2027339
    Source Port:48366
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.235.97.1139134372152835222 05/27/22-02:09:18.794017
    SID:2835222
    Source Port:39134
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.15.14043438528692027339 05/27/22-02:09:31.466186
    SID:2027339
    Source Port:43438
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.155.24855312372152835222 05/27/22-02:09:32.486282
    SID:2835222
    Source Port:55312
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.100.16339036528692027339 05/27/22-02:11:37.013850
    SID:2027339
    Source Port:39036
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.59.8643368372152835222 05/27/22-02:08:33.801465
    SID:2835222
    Source Port:43368
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.40.11654112528692027339 05/27/22-02:08:37.479153
    SID:2027339
    Source Port:54112
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.152.19157300528692027339 05/27/22-02:10:18.931916
    SID:2027339
    Source Port:57300
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.93.11436020528692027339 05/27/22-02:08:12.881787
    SID:2027339
    Source Port:36020
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.28.038234528692027339 05/27/22-02:10:41.100941
    SID:2027339
    Source Port:38234
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.152.11358802372152835222 05/27/22-02:08:26.353303
    SID:2835222
    Source Port:58802
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.235.100.2535450372152835222 05/27/22-02:10:05.689530
    SID:2835222
    Source Port:35450
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.44.6543656372152835222 05/27/22-02:08:46.975224
    SID:2835222
    Source Port:43656
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.88.14059936528692027339 05/27/22-02:09:34.033957
    SID:2027339
    Source Port:59936
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.107.3258836528692027339 05/27/22-02:09:03.475486
    SID:2027339
    Source Port:58836
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.96.2058270528692027339 05/27/22-02:08:45.518956
    SID:2027339
    Source Port:58270
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.98.14447846528692027339 05/27/22-02:10:16.712080
    SID:2027339
    Source Port:47846
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.117.16059048372152835222 05/27/22-02:08:38.339060
    SID:2835222
    Source Port:59048
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.9.16844810528692027339 05/27/22-02:08:28.023484
    SID:2027339
    Source Port:44810
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.120.17850922372152835222 05/27/22-02:09:36.587948
    SID:2835222
    Source Port:50922
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.2341.193.254.16344864528692027339 05/27/22-02:11:01.724045
    SID:2027339
    Source Port:44864
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.18.14434108372152835222 05/27/22-02:08:23.351272
    SID:2835222
    Source Port:34108
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.62.19644698372152835222 05/27/22-02:08:36.746389
    SID:2835222
    Source Port:44698
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.2341.60.218.12654878372152835222 05/27/22-02:09:52.276348
    SID:2835222
    Source Port:54878
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.65.19242452528692027339 05/27/22-02:09:44.237835
    SID:2027339
    Source Port:42452
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.15.6347676528692027339 05/27/22-02:11:05.344992
    SID:2027339
    Source Port:47676
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.68.12454036372152835222 05/27/22-02:11:07.505431
    SID:2835222
    Source Port:54036
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.133.2149966528692027339 05/27/22-02:11:16.326094
    SID:2027339
    Source Port:49966
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.104.15739982372152835222 05/27/22-02:09:34.486601
    SID:2835222
    Source Port:39982
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.72.7457434372152835222 05/27/22-02:10:59.890550
    SID:2835222
    Source Port:57434
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.75.20653206528692027339 05/27/22-02:08:21.588262
    SID:2027339
    Source Port:53206
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.53.8658920372152835222 05/27/22-02:09:12.249881
    SID:2835222
    Source Port:58920
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23197.246.192.11255418372152835222 05/27/22-02:09:49.376045
    SID:2835222
    Source Port:55418
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.62.25045912528692027339 05/27/22-02:11:23.997793
    SID:2027339
    Source Port:45912
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.230.26.23352248528692027339 05/27/22-02:08:43.670473
    SID:2027339
    Source Port:52248
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.94.19141562528692027339 05/27/22-02:11:30.122687
    SID:2027339
    Source Port:41562
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.111.23836542372152835222 05/27/22-02:11:33.430745
    SID:2835222
    Source Port:36542
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23197.232.9.1046028372152835222 05/27/22-02:09:53.502577
    SID:2835222
    Source Port:46028
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.245.60.14544718372152835222 05/27/22-02:10:31.899703
    SID:2835222
    Source Port:44718
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.30.8360660372152835222 05/27/22-02:08:32.714927
    SID:2835222
    Source Port:60660
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.252.26.9647192528692027339 05/27/22-02:10:43.687993
    SID:2027339
    Source Port:47192
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.12.12059912528692027339 05/27/22-02:08:16.894106
    SID:2027339
    Source Port:59912
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.84.14348674372152835222 05/27/22-02:10:05.522165
    SID:2835222
    Source Port:48674
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.13.11242014528692027339 05/27/22-02:10:40.122553
    SID:2027339
    Source Port:42014
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.92.11955838372152835222 05/27/22-02:09:00.309825
    SID:2835222
    Source Port:55838
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.61.24751746372152835222 05/27/22-02:10:17.856761
    SID:2835222
    Source Port:51746
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.91.22452316372152835222 05/27/22-02:11:38.032751
    SID:2835222
    Source Port:52316
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.95.16739962372152835222 05/27/22-02:11:40.115430
    SID:2835222
    Source Port:39962
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.87.3850482372152835222 05/27/22-02:08:29.088177
    SID:2835222
    Source Port:50482
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.85.11335474372152835222 05/27/22-02:09:13.488702
    SID:2835222
    Source Port:35474
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.125.20139836372152835222 05/27/22-02:09:02.291712
    SID:2835222
    Source Port:39836
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.247.31.22756570372152835222 05/27/22-02:08:28.829988
    SID:2835222
    Source Port:56570
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.95.25337454372152835222 05/27/22-02:08:59.758700
    SID:2835222
    Source Port:37454
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.102.23940644372152835222 05/27/22-02:11:15.319562
    SID:2835222
    Source Port:40644
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.250.123.9944756372152835222 05/27/22-02:11:12.087553
    SID:2835222
    Source Port:44756
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.58.10655554372152835222 05/27/22-02:09:20.657002
    SID:2835222
    Source Port:55554
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.143.3136562372152835222 05/27/22-02:09:34.769933
    SID:2835222
    Source Port:36562
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.60.8541244372152835222 05/27/22-02:11:10.217859
    SID:2835222
    Source Port:41244
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.107.5449678528692027339 05/27/22-02:11:24.050672
    SID:2027339
    Source Port:49678
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.227.242.16034736372152835222 05/27/22-02:11:26.113784
    SID:2835222
    Source Port:34736
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.70.24541604528692027339 05/27/22-02:10:16.619895
    SID:2027339
    Source Port:41604
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.30.5951560528692027339 05/27/22-02:08:17.072473
    SID:2027339
    Source Port:51560
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.225.156.18043558372152835222 05/27/22-02:09:54.233400
    SID:2835222
    Source Port:43558
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.19.21552722528692027339 05/27/22-02:08:15.302388
    SID:2027339
    Source Port:52722
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.31.548714528692027339 05/27/22-02:10:19.160760
    SID:2027339
    Source Port:48714
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.2391.121.146.4737406232404346 05/27/22-02:09:54.846625
    SID:2404346
    Source Port:37406
    Destination Port:23
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.62.9647338372152835222 05/27/22-02:08:38.316282
    SID:2835222
    Source Port:47338
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.235.107.14646320372152835222 05/27/22-02:11:12.263631
    SID:2835222
    Source Port:46320
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.230.18.2833444372152835222 05/27/22-02:08:51.127626
    SID:2835222
    Source Port:33444
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.244.73.18839326372152835222 05/27/22-02:10:36.370653
    SID:2835222
    Source Port:39326
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.226.103.15633998372152835222 05/27/22-02:09:54.237333
    SID:2835222
    Source Port:33998
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.238.45.12750478372152835222 05/27/22-02:08:23.521688
    SID:2835222
    Source Port:50478
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.224.18.22838774372152835222 05/27/22-02:11:33.028143
    SID:2835222
    Source Port:38774
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.126.18758598528692027339 05/27/22-02:10:00.584459
    SID:2027339
    Source Port:58598
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.79.23335036528692027339 05/27/22-02:10:43.521148
    SID:2027339
    Source Port:35036
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.89.12933818372152835222 05/27/22-02:11:20.389888
    SID:2835222
    Source Port:33818
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.240.107.4433148372152835222 05/27/22-02:09:02.282673
    SID:2835222
    Source Port:33148
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.245.57.1734070528692027339 05/27/22-02:09:58.023985
    SID:2027339
    Source Port:34070
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.241.15.21259254528692027339 05/27/22-02:10:06.137449
    SID:2027339
    Source Port:59254
    Destination Port:52869
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.23156.254.86.14033450528692027339 05/27/22-02:11:40.535210
    SID:2027339
    Source Port:33450
    Destination Port: