Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
N0hjaP1acV

Overview

General Information

Sample Name:N0hjaP1acV
Analysis ID:634910
MD5:ee14dc420ebe8fe314e596360fc6e382
SHA1:8b3d7ca9d831a9ecd543ea5d344b30b525c267c2
SHA256:30f9ae9beb37d5a8f1858b947be85c8fbcbd4c094f3c8cd5b8e6d2886d6e08b9
Tags:32elfmipsmirai
Infos:

Detection

Mirai
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Sample is packed with UPX
Uses known network protocols on non-standard ports
Connects to many ports of the same IP (likely port scanning)
Sample contains only a LOAD segment without any section mappings
Yara signature match
HTTP GET or POST without a user agent
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:634910
Start date and time: 27/05/202202:11:472022-05-27 02:11:47 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 59s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:N0hjaP1acV
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal84.troj.evad.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/N0hjaP1acV
PID:6229
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Infected
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
N0hjaP1acVSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0xad78:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0xade7:$s2: $Id: UPX
  • 0xad98:$s3: $Info: This file is packed with the UPX executable packer
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    6256.1.0000000046947e86.000000002687ffb5.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6248.1.0000000046947e86.000000002687ffb5.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6241.1.0000000046947e86.000000002687ffb5.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6229.1.0000000046947e86.000000002687ffb5.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
            6245.1.0000000046947e86.000000002687ffb5.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              Timestamp:192.168.2.23156.224.14.7950618528692027339 05/27/22-02:13:58.105252
              SID:2027339
              Source Port:50618
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.61.6557204528692027339 05/27/22-02:16:04.924108
              SID:2027339
              Source Port:57204
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.98.20249046528692027339 05/27/22-02:14:35.444891
              SID:2027339
              Source Port:49046
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.74.22046262528692027339 05/27/22-02:14:36.677860
              SID:2027339
              Source Port:46262
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.84.11541430528692027339 05/27/22-02:13:56.668282
              SID:2027339
              Source Port:41430
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.227.240.9754036528692027339 05/27/22-02:13:49.289658
              SID:2027339
              Source Port:54036
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.224.22.3855960528692027339 05/27/22-02:14:36.626878
              SID:2027339
              Source Port:55960
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.138.9042848372152835222 05/27/22-02:15:11.674046
              SID:2835222
              Source Port:42848
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.71.1035844528692027339 05/27/22-02:12:54.856801
              SID:2027339
              Source Port:35844
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.14.2143682528692027339 05/27/22-02:15:25.586143
              SID:2027339
              Source Port:43682
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.224.9.16347384528692027339 05/27/22-02:14:57.144519
              SID:2027339
              Source Port:47384
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.48.2654720372152835222 05/27/22-02:13:39.144497
              SID:2835222
              Source Port:54720
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.46.15837544528692027339 05/27/22-02:15:35.761225
              SID:2027339
              Source Port:37544
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.60.15545062528692027339 05/27/22-02:14:40.059383
              SID:2027339
              Source Port:45062
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.49.15951956528692027339 05/27/22-02:14:00.916205
              SID:2027339
              Source Port:51956
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.143.18546852528692027339 05/27/22-02:15:44.829670
              SID:2027339
              Source Port:46852
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.116.8035674528692027339 05/27/22-02:14:37.094245
              SID:2027339
              Source Port:35674
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.82.14242758528692027339 05/27/22-02:12:55.926001
              SID:2027339
              Source Port:42758
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.96.22646198528692027339 05/27/22-02:13:10.956619
              SID:2027339
              Source Port:46198
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.71.3647022372152835222 05/27/22-02:13:23.331351
              SID:2835222
              Source Port:47022
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.123.935674528692027339 05/27/22-02:14:50.971307
              SID:2027339
              Source Port:35674
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.105.8957578528692027339 05/27/22-02:15:32.707694
              SID:2027339
              Source Port:57578
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.59.9749196528692027339 05/27/22-02:12:56.166673
              SID:2027339
              Source Port:49196
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.240.106.14755106372152835222 05/27/22-02:14:29.271383
              SID:2835222
              Source Port:55106
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.87.22641980528692027339 05/27/22-02:14:29.289410
              SID:2027339
              Source Port:41980
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.159.9053200528692027339 05/27/22-02:15:26.120158
              SID:2027339
              Source Port:53200
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.247.27.25357938528692027339 05/27/22-02:13:53.102906
              SID:2027339
              Source Port:57938
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.61.2542128372152835222 05/27/22-02:14:49.510258
              SID:2835222
              Source Port:42128
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.91.2855614528692027339 05/27/22-02:14:18.676105
              SID:2027339
              Source Port:55614
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.224.10.8242746372152835222 05/27/22-02:13:33.105779
              SID:2835222
              Source Port:42746
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.84.16260258372152835222 05/27/22-02:15:47.741844
              SID:2835222
              Source Port:60258
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.2341.78.123.148548528692027339 05/27/22-02:13:21.096567
              SID:2027339
              Source Port:48548
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.239.155.15857160372152835222 05/27/22-02:14:46.840933
              SID:2835222
              Source Port:57160
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.77.18754816372152835222 05/27/22-02:15:44.742124
              SID:2835222
              Source Port:54816
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.108.9943718528692027339 05/27/22-02:12:43.189218
              SID:2027339
              Source Port:43718
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.52.19033086528692027339 05/27/22-02:13:35.255592
              SID:2027339
              Source Port:33086
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.86.12138606372152835222 05/27/22-02:14:39.009848
              SID:2835222
              Source Port:38606
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.126.23844746528692027339 05/27/22-02:15:02.150467
              SID:2027339
              Source Port:44746
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.81.6340236372152835222 05/27/22-02:15:19.372629
              SID:2835222
              Source Port:40236
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.56.1052602372152835222 05/27/22-02:12:54.824351
              SID:2835222
              Source Port:52602
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23197.234.54.14351348372152835222 05/27/22-02:16:02.763420
              SID:2835222
              Source Port:51348
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.46.4234500528692027339 05/27/22-02:15:27.951216
              SID:2027339
              Source Port:34500
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.91.15335422528692027339 05/27/22-02:12:57.071160
              SID:2027339
              Source Port:35422
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.112.8149114528692027339 05/27/22-02:14:02.928791
              SID:2027339
              Source Port:49114
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.78.10032836528692027339 05/27/22-02:14:14.336004
              SID:2027339
              Source Port:32836
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.97.10846336372152835222 05/27/22-02:15:58.248205
              SID:2835222
              Source Port:46336
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.230.29.6445174372152835222 05/27/22-02:13:57.768233
              SID:2835222
              Source Port:45174
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.110.1256560528692027339 05/27/22-02:15:46.756882
              SID:2027339
              Source Port:56560
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.75.035466528692027339 05/27/22-02:13:10.915908
              SID:2027339
              Source Port:35466
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.92.22957968528692027339 05/27/22-02:14:25.235370
              SID:2027339
              Source Port:57968
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.74.11139380372152835222 05/27/22-02:14:17.492006
              SID:2835222
              Source Port:39380
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.79.4638264528692027339 05/27/22-02:12:53.354886
              SID:2027339
              Source Port:38264
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.115.13956778372152835222 05/27/22-02:13:45.586935
              SID:2835222
              Source Port:56778
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.247.27.7743950528692027339 05/27/22-02:14:48.265097
              SID:2027339
              Source Port:43950
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.53.439590528692027339 05/27/22-02:14:50.766924
              SID:2027339
              Source Port:39590
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.133.3557720528692027339 05/27/22-02:15:41.275652
              SID:2027339
              Source Port:57720
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.76.13138880372152835222 05/27/22-02:13:29.292236
              SID:2835222
              Source Port:38880
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.80.5734018528692027339 05/27/22-02:13:52.173426
              SID:2027339
              Source Port:34018
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.232.94.19548476372152835222 05/27/22-02:15:58.177549
              SID:2835222
              Source Port:48476
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.54.15656814528692027339 05/27/22-02:13:52.850974
              SID:2027339
              Source Port:56814
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.239.152.11950524528692027339 05/27/22-02:15:30.191969
              SID:2027339
              Source Port:50524
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.66.20950904372152835222 05/27/22-02:15:47.269657
              SID:2835222
              Source Port:50904
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.111.13948572372152835222 05/27/22-02:15:58.658252
              SID:2835222
              Source Port:48572
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.227.240.12943716528692027339 05/27/22-02:13:38.769973
              SID:2027339
              Source Port:43716
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.139.6345370528692027339 05/27/22-02:13:01.828686
              SID:2027339
              Source Port:45370
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.115.17658628528692027339 05/27/22-02:15:29.598619
              SID:2027339
              Source Port:58628
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.60.15346750372152835222 05/27/22-02:13:24.130514
              SID:2835222
              Source Port:46750
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.239.152.24145346528692027339 05/27/22-02:13:27.364885
              SID:2027339
              Source Port:45346
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.82.21942842528692027339 05/27/22-02:13:59.432040
              SID:2027339
              Source Port:42842
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.159.7533144528692027339 05/27/22-02:16:02.376255
              SID:2027339
              Source Port:33144
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.49.10155184528692027339 05/27/22-02:13:23.358713
              SID:2027339
              Source Port:55184
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.103.9948840528692027339 05/27/22-02:13:52.855377
              SID:2027339
              Source Port:48840
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.79.23948044372152835222 05/27/22-02:14:15.506746
              SID:2835222
              Source Port:48044
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.155.21634766528692027339 05/27/22-02:14:09.609403
              SID:2027339
              Source Port:34766
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.98.15754100372152835222 05/27/22-02:14:50.692622
              SID:2835222
              Source Port:54100
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.102.8256764372152835222 05/27/22-02:12:48.708918
              SID:2835222
              Source Port:56764
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.75.3760012372152835222 05/27/22-02:13:33.140390
              SID:2835222
              Source Port:60012
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.108.1634146528692027339 05/27/22-02:15:33.429510
              SID:2027339
              Source Port:34146
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.99.11246524372152835222 05/27/22-02:14:22.250710
              SID:2835222
              Source Port:46524
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.113.21339116528692027339 05/27/22-02:13:04.328886
              SID:2027339
              Source Port:39116
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.78.14639698372152835222 05/27/22-02:13:36.843203
              SID:2835222
              Source Port:39698
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.227.245.16853588528692027339 05/27/22-02:15:23.400250
              SID:2027339
              Source Port:53588
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.89.15641022372152835222 05/27/22-02:13:15.717127
              SID:2835222
              Source Port:41022
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.63.8542466528692027339 05/27/22-02:13:38.710756
              SID:2027339
              Source Port:42466
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.102.11344524372152835222 05/27/22-02:15:36.796853
              SID:2835222
              Source Port:44524
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.60.16839394528692027339 05/27/22-02:13:19.454012
              SID:2027339
              Source Port:39394
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.60.3440268372152835222 05/27/22-02:13:22.309987
              SID:2835222
              Source Port:40268
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.61.11047844528692027339 05/27/22-02:13:31.890200
              SID:2027339
              Source Port:47844
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.230.26.23059828528692027339 05/27/22-02:15:29.650636
              SID:2027339
              Source Port:59828
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.95.13541928372152835222 05/27/22-02:15:55.855853
              SID:2835222
              Source Port:41928
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.103.20155744372152835222 05/27/22-02:13:30.822378
              SID:2835222
              Source Port:55744
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.232.89.11239742528692027339 05/27/22-02:16:03.547915
              SID:2027339
              Source Port:39742
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.52.21637384372152835222 05/27/22-02:13:57.603579
              SID:2835222
              Source Port:37384
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.124.11133152372152835222 05/27/22-02:14:34.749820
              SID:2835222
              Source Port:33152
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.34.17034528528692027339 05/27/22-02:14:56.885248
              SID:2027339
              Source Port:34528
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.54.14049164372152835222 05/27/22-02:13:24.836193
              SID:2835222
              Source Port:49164
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.32.3845886372152835222 05/27/22-02:14:00.364163
              SID:2835222
              Source Port:45886
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.95.8757264372152835222 05/27/22-02:15:19.224623
              SID:2835222
              Source Port:57264
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.107.9559450528692027339 05/27/22-02:12:46.370080
              SID:2027339
              Source Port:59450
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.230.24.13137042372152835222 05/27/22-02:16:06.079051
              SID:2835222
              Source Port:37042
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.104.14141364372152835222 05/27/22-02:14:07.440368
              SID:2835222
              Source Port:41364
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23197.246.193.4154768372152835222 05/27/22-02:14:18.135266
              SID:2835222
              Source Port:54768
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.230.30.19348628372152835222 05/27/22-02:13:14.410059
              SID:2835222
              Source Port:48628
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.91.7440776372152835222 05/27/22-02:12:44.206867
              SID:2835222
              Source Port:40776
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.60.858916372152835222 05/27/22-02:13:06.892359
              SID:2835222
              Source Port:58916
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.74.23548190528692027339 05/27/22-02:13:26.081860
              SID:2027339
              Source Port:48190
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.99.23254506528692027339 05/27/22-02:14:08.659215
              SID:2027339
              Source Port:54506
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.48.14135426528692027339 05/27/22-02:12:50.304313
              SID:2027339
              Source Port:35426
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.97.3437308528692027339 05/27/22-02:12:59.940810
              SID:2027339
              Source Port:37308
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.88.17641590372152835222 05/27/22-02:15:56.186019
              SID:2835222
              Source Port:41590
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.15.2547450528692027339 05/27/22-02:13:49.655052
              SID:2027339
              Source Port:47450
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.224.29.18044182528692027339 05/27/22-02:14:53.146841
              SID:2027339
              Source Port:44182
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.85.2660200528692027339 05/27/22-02:12:57.635007
              SID:2027339
              Source Port:60200
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.132.19453538372152835222 05/27/22-02:14:15.265038
              SID:2835222
              Source Port:53538
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.88.12440016372152835222 05/27/22-02:12:51.593923
              SID:2835222
              Source Port:40016
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.97.23148260372152835222 05/27/22-02:14:22.025068
              SID:2835222
              Source Port:48260
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.14.1233270528692027339 05/27/22-02:14:00.689986
              SID:2027339
              Source Port:33270
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.2341.0.84.7736524528692027339 05/27/22-02:14:50.212272
              SID:2027339
              Source Port:36524
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.61.22551084528692027339 05/27/22-02:14:54.636072
              SID:2027339
              Source Port:51084
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.106.9537216372152835222 05/27/22-02:13:44.364053
              SID:2835222
              Source Port:37216
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.132.20852444528692027339 05/27/22-02:14:02.725896
              SID:2027339
              Source Port:52444
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.51.4044368528692027339 05/27/22-02:15:28.190347
              SID:2027339
              Source Port:44368
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.73.2647476372152835222 05/27/22-02:15:29.455772
              SID:2835222
              Source Port:47476
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.70.21457858528692027339 05/27/22-02:15:25.590511
              SID:2027339
              Source Port:57858
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.10.4050578372152835222 05/27/22-02:13:29.590300
              SID:2835222
              Source Port:50578
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.224.29.17353380372152835222 05/27/22-02:13:45.539483
              SID:2835222
              Source Port:53380
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.224.23.9258526372152835222 05/27/22-02:13:24.790368
              SID:2835222
              Source Port:58526
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.94.8759650372152835222 05/27/22-02:14:18.028243
              SID:2835222
              Source Port:59650
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.136.12443902372152835222 05/27/22-02:15:26.194360
              SID:2835222
              Source Port:43902
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.54.16845118372152835222 05/27/22-02:14:18.028002
              SID:2835222
              Source Port:45118
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.69.4648562372152835222 05/27/22-02:13:04.054928
              SID:2835222
              Source Port:48562
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.68.4039378372152835222 05/27/22-02:13:23.904907
              SID:2835222
              Source Port:39378
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.123.21541922528692027339 05/27/22-02:13:00.537684
              SID:2027339
              Source Port:41922
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.51.7551070372152835222 05/27/22-02:13:49.473187
              SID:2835222
              Source Port:51070
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.71.25145106372152835222 05/27/22-02:15:24.727191
              SID:2835222
              Source Port:45106
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.232.90.7048948528692027339 05/27/22-02:16:03.715684
              SID:2027339
              Source Port:48948
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.98.6352232528692027339 05/27/22-02:14:31.680197
              SID:2027339
              Source Port:52232
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.71.8852088528692027339 05/27/22-02:15:08.130201
              SID:2027339
              Source Port:52088
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.54.19744280372152835222 05/27/22-02:14:52.946969
              SID:2835222
              Source Port:44280
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.12.036632372152835222 05/27/22-02:13:03.624342
              SID:2835222
              Source Port:36632
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.8.5546794528692027339 05/27/22-02:16:01.823422
              SID:2027339
              Source Port:46794
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.70.5951892528692027339 05/27/22-02:12:43.767721
              SID:2027339
              Source Port:51892
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.125.5538080528692027339 05/27/22-02:13:56.593665
              SID:2027339
              Source Port:38080
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.96.8544686528692027339 05/27/22-02:14:39.577991
              SID:2027339
              Source Port:44686
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.79.20055110372152835222 05/27/22-02:13:33.332911
              SID:2835222
              Source Port:55110
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.227.247.3046224528692027339 05/27/22-02:15:17.885570
              SID:2027339
              Source Port:46224
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.116.4956468528692027339 05/27/22-02:15:59.528866
              SID:2027339
              Source Port:56468
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.67.6038562528692027339 05/27/22-02:15:49.696382
              SID:2027339
              Source Port:38562
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.240.109.20643920372152835222 05/27/22-02:12:42.296506
              SID:2835222
              Source Port:43920
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.125.22534114528692027339 05/27/22-02:13:00.075937
              SID:2027339
              Source Port:34114
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.111.22336972372152835222 05/27/22-02:14:51.973133
              SID:2835222
              Source Port:36972
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.227.244.16356848372152835222 05/27/22-02:14:51.959326
              SID:2835222
              Source Port:56848
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.91.20635914372152835222 05/27/22-02:14:39.039040
              SID:2835222
              Source Port:35914
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.109.19948556372152835222 05/27/22-02:14:22.555051
              SID:2835222
              Source Port:48556
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.100.15653238528692027339 05/27/22-02:14:06.366393
              SID:2027339
              Source Port:53238
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.49.16350578372152835222 05/27/22-02:15:29.431320
              SID:2835222
              Source Port:50578
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.97.17148168372152835222 05/27/22-02:15:39.488038
              SID:2835222
              Source Port:48168
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.106.16754500528692027339 05/27/22-02:15:20.331149
              SID:2027339
              Source Port:54500
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.79.13455592372152835222 05/27/22-02:13:17.995176
              SID:2835222
              Source Port:55592
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.75.4648516528692027339 05/27/22-02:14:01.198799
              SID:2027339
              Source Port:48516
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.141.19958162528692027339 05/27/22-02:13:05.395964
              SID:2027339
              Source Port:58162
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.58.23755430372152835222 05/27/22-02:14:57.299845
              SID:2835222
              Source Port:55430
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.85.12849114528692027339 05/27/22-02:14:32.261733
              SID:2027339
              Source Port:49114
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.230.16.454496528692027339 05/27/22-02:15:51.760200
              SID:2027339
              Source Port:54496
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.138.11251752372152835222 05/27/22-02:13:57.830736
              SID:2835222
              Source Port:51752
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.106.7147258372152835222 05/27/22-02:15:03.890871
              SID:2835222
              Source Port:47258
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.250.15.23946968528692027339 05/27/22-02:15:47.192692
              SID:2027339
              Source Port:46968
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.58.4448610372152835222 05/27/22-02:13:46.898085
              SID:2835222
              Source Port:48610
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.247.25.15648536528692027339 05/27/22-02:12:46.612785
              SID:2027339
              Source Port:48536
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.133.24056286372152835222 05/27/22-02:13:39.348628
              SID:2835222
              Source Port:56286
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.230.28.7345884528692027339 05/27/22-02:15:39.186764
              SID:2027339
              Source Port:45884
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.56.24144482528692027339 05/27/22-02:14:31.741771
              SID:2027339
              Source Port:44482
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.235.97.16654848528692027339 05/27/22-02:13:34.854493
              SID:2027339
              Source Port:54848
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.132.20736434372152835222 05/27/22-02:12:42.088150
              SID:2835222
              Source Port:36434
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.247.20.10237006528692027339 05/27/22-02:12:57.512512
              SID:2027339
              Source Port:37006
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.127.19738718528692027339 05/27/22-02:12:53.360210
              SID:2027339
              Source Port:38718
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.224.31.5834264372152835222 05/27/22-02:14:00.300631
              SID:2835222
              Source Port:34264
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.62.6141094528692027339 05/27/22-02:15:44.833472
              SID:2027339
              Source Port:41094
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.238.61.19838604372152835222 05/27/22-02:12:42.098117
              SID:2835222
              Source Port:38604
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.225.137.12950458528692027339 05/27/22-02:15:07.743958
              SID:2027339
              Source Port:50458
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.97.19555994528692027339 05/27/22-02:16:00.365402
              SID:2027339
              Source Port:55994
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.107.1652176528692027339 05/27/22-02:16:02.078691
              SID:2027339
              Source Port:52176
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.104.15951580372152835222 05/27/22-02:14:33.327999
              SID:2835222
              Source Port:51580
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.254.39.23552566528692027339 05/27/22-02:15:32.125041
              SID:2027339
              Source Port:52566
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.247.21.7352968528692027339 05/27/22-02:15:49.939246
              SID:2027339
              Source Port:52968
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.241.13.1957972372152835222 05/27/22-02:15:29.464566
              SID:2835222
              Source Port:57972
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.226.15.2155130528692027339 05/27/22-02:13:27.026150
              SID:2027339
              Source Port:55130
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.245.49.3753600528692027339 05/27/22-02:14:26.799092
              SID:2027339
              Source Port:53600
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.240.105.15933672528692027339 05/27/22-02:13:00.042953
              SID:2027339
              Source Port:33672
              Destination Port:52869
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23197.0.78.13843770372152835222 05/27/22-02:15:44.616626
              SID:2835222
              Source Port:43770
              Destination Port:37215
              Protocol:TCP
              Classtype:A Network Trojan was detected
              Timestamp:192.168.2.23156.244.91.16451552372152835222 05/27/22-02:15:48.271631
              SID:2835222
              Source Port:5155