Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
kuCwPmEwdM

Overview

General Information

Sample Name:kuCwPmEwdM
Analysis ID:635082
MD5:5503ada6da9fa406b1b76e372b1fcbb0
SHA1:2aee070f638cbf5b49c5257c036118d9ca558f56
SHA256:a909a24a46ef6270ac602102003e78a139e0750c3502a39f6c958896143d5bdb
Tags:32elfmipsmirai
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Uses known network protocols on non-standard ports
Sample tries to kill multiple processes (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Detected TCP or UDP traffic on non-standard ports
Sample tries to kill a process (SIGKILL)
Detected non-DNS traffic on DNS port
Sample has stripped symbol table
HTTP GET or POST without a user agent
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

Some HTTP requests failed (404). It is likely that the sample will exhibit less behavior.
Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:635082
Start date and time: 27/05/202212:46:062022-05-27 12:46:06 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 7m 3s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:kuCwPmEwdM
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.spre.troj.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
Command:/tmp/kuCwPmEwdM
PID:6230
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Infected By Cult
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    Timestamp:192.168.2.2388.147.25.23054608802839471 05/27/22-12:47:34.014385
    SID:2839471
    Source Port:54608
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.215.185.23438844802839471 05/27/22-12:47:51.607040
    SID:2839471
    Source Port:38844
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.67.237.6659082802839471 05/27/22-12:47:15.080363
    SID:2839471
    Source Port:59082
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.112.154.17441676802839471 05/27/22-12:47:15.090627
    SID:2839471
    Source Port:41676
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2341.62.245.11149730372152835222 05/27/22-12:47:53.882683
    SID:2835222
    Source Port:49730
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.2395.179.137.17458194802839471 05/27/22-12:48:14.438208
    SID:2839471
    Source Port:58194
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.150.144.1353878802839471 05/27/22-12:47:10.978190
    SID:2839471
    Source Port:53878
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.130.6.15141382802839471 05/27/22-12:47:15.059849
    SID:2839471
    Source Port:41382
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.221.78.1259134802839471 05/27/22-12:47:49.018701
    SID:2839471
    Source Port:59134
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.214.234.13634152802839471 05/27/22-12:48:04.635268
    SID:2839471
    Source Port:34152
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.112.26.17644764802839471 05/27/22-12:47:49.003840
    SID:2839471
    Source Port:44764
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.100.241.10034392802839471 05/27/22-12:48:03.504850
    SID:2839471
    Source Port:34392
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.216.150.19036108802839471 05/27/22-12:47:15.053671
    SID:2839471
    Source Port:36108
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.159.21.17353860802839471 05/27/22-12:47:59.854206
    SID:2839471
    Source Port:53860
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.56.53.13533488802839471 05/27/22-12:47:49.073357
    SID:2839471
    Source Port:33488
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.255.41.2859640802839471 05/27/22-12:47:13.505289
    SID:2839471
    Source Port:59640
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.223.18.12440804802839471 05/27/22-12:47:13.498434
    SID:2839471
    Source Port:40804
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.247.238.12639848802839471 05/27/22-12:46:57.495420
    SID:2839471
    Source Port:39848
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.146.194.15851092802839471 05/27/22-12:47:33.709741
    SID:2839471
    Source Port:51092
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.100.230.2060114802839471 05/27/22-12:47:31.209429
    SID:2839471
    Source Port:60114
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.167.73.7760578802839471 05/27/22-12:47:07.038688
    SID:2839471
    Source Port:60578
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.122.162.8149276802839471 05/27/22-12:48:07.946255
    SID:2839471
    Source Port:49276
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.100.170.10448188802839471 05/27/22-12:47:07.172463
    SID:2839471
    Source Port:48188
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.100.208.23146568802839471 05/27/22-12:48:16.775027
    SID:2839471
    Source Port:46568
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.215.255.9151586802839471 05/27/22-12:47:42.722816
    SID:2839471
    Source Port:51586
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.198.110.23440074802839471 05/27/22-12:47:46.661375
    SID:2839471
    Source Port:40074
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.136.102.12851928802839471 05/27/22-12:47:38.633741
    SID:2839471
    Source Port:51928
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.136.54.2860044802839471 05/27/22-12:47:27.579938
    SID:2839471
    Source Port:60044
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.156.55.2955906802839471 05/27/22-12:47:36.188256
    SID:2839471
    Source Port:55906
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.221.188.4335412802839471 05/27/22-12:47:29.045100
    SID:2839471
    Source Port:35412
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.255.253.4234062802839471 05/27/22-12:48:16.968700
    SID:2839471
    Source Port:34062
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.214.45.152148802839471 05/27/22-12:47:24.075213
    SID:2839471
    Source Port:52148
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.101.211.16546204802839471 05/27/22-12:47:10.944613
    SID:2839471
    Source Port:46204
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.17.57.16850558802839471 05/27/22-12:47:20.105563
    SID:2839471
    Source Port:50558
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.216.182.20750770802839471 05/27/22-12:47:58.808550
    SID:2839471
    Source Port:50770
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.101.70.4758192802839471 05/27/22-12:47:15.046152
    SID:2839471
    Source Port:58192
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.168.220.9735532802839471 05/27/22-12:46:57.377011
    SID:2839471
    Source Port:35532
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.72.51.7837596802839471 05/27/22-12:48:11.670529
    SID:2839471
    Source Port:37596
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.101.242.23146042802839471 05/27/22-12:47:31.204962
    SID:2839471
    Source Port:46042
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.214.188.14054808802839471 05/27/22-12:47:49.127460
    SID:2839471
    Source Port:54808
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.101.23.23945600802839471 05/27/22-12:47:51.604867
    SID:2839471
    Source Port:45600
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.216.72.7139974802839471 05/27/22-12:48:12.019932
    SID:2839471
    Source Port:39974
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.159.11.3059024802839471 05/27/22-12:48:16.848947
    SID:2839471
    Source Port:59024
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.100.83.1649496802839471 05/27/22-12:47:28.999232
    SID:2839471
    Source Port:49496
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.65.56.13836468802839471 05/27/22-12:48:10.168925
    SID:2839471
    Source Port:36468
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.198.148.23836254802839471 05/27/22-12:47:38.619624
    SID:2839471
    Source Port:36254
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.128.147.22039230802839471 05/27/22-12:48:19.208516
    SID:2839471
    Source Port:39230
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.205.95.4333448802839471 05/27/22-12:48:11.887654
    SID:2839471
    Source Port:33448
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.87.64.25548256802839471 05/27/22-12:48:14.568167
    SID:2839471
    Source Port:48256
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.171.3.21846612802839471 05/27/22-12:47:13.447133
    SID:2839471
    Source Port:46612
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.210.22.22158942802839471 05/27/22-12:47:06.690087
    SID:2839471
    Source Port:58942
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.101.156.14756178802839471 05/27/22-12:47:36.242927
    SID:2839471
    Source Port:56178
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.249.107.25445124802839471 05/27/22-12:47:29.101579
    SID:2839471
    Source Port:45124
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.194.65.25249746802839471 05/27/22-12:47:23.716570
    SID:2839471
    Source Port:49746
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.49.221.10932828802839471 05/27/22-12:47:42.672755
    SID:2839471
    Source Port:32828
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.171.3.21846688802839471 05/27/22-12:47:16.542926
    SID:2839471
    Source Port:46688
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.129.137.24538576802839471 05/27/22-12:47:36.183582
    SID:2839471
    Source Port:38576
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.28.199.25340702802839471 05/27/22-12:47:11.081110
    SID:2839471
    Source Port:40702
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.17.60.4039644802839471 05/27/22-12:47:53.228125
    SID:2839471
    Source Port:39644
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.231.53.22052380802839471 05/27/22-12:48:04.736705
    SID:2839471
    Source Port:52380
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23197.234.61.11341942372152835222 05/27/22-12:48:13.090975
    SID:2835222
    Source Port:41942
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.2395.68.75.9742456802839471 05/27/22-12:46:55.294531
    SID:2839471
    Source Port:42456
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23197.214.98.13255698372152835222 05/27/22-12:47:20.408675
    SID:2835222
    Source Port:55698
    Destination Port:37215
    Protocol:TCP
    Classtype:A Network Trojan was detected
    Timestamp:192.168.2.2395.121.139.12559944802839471 05/27/22-12:47:20.135801
    SID:2839471
    Source Port:59944
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.156.51.10259576802839471 05/27/22-12:48:12.074131
    SID:2839471
    Source Port:59576
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.217.109.1953226802839471 05/27/22-12:46:57.392990
    SID:2839471
    Source Port:53226
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.68.127.12146654802839471 05/27/22-12:48:14.464045
    SID:2839471
    Source Port:46654
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.100.241.10034382802839471 05/27/22-12:48:02.219711
    SID:2839471
    Source Port:34382
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.120.6.6139842802839471 05/27/22-12:48:11.903918
    SID:2839471
    Source Port:39842
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.210.144.12460104802839471 05/27/22-12:47:27.576693
    SID:2839471
    Source Port:60104
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.57.98.20234828802839471 05/27/22-12:47:36.352619
    SID:2839471
    Source Port:34828
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.211.75.2541774802839471 05/27/22-12:48:19.124724
    SID:2839471
    Source Port:41774
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.57.203.25247000802839471 05/27/22-12:48:19.323847
    SID:2839471
    Source Port:47000
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.23112.171.248.10837160802839471 05/27/22-12:47:27.589765
    SID:2839471
    Source Port:37160
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2388.149.185.11848152802839471 05/27/22-12:47:29.046007
    SID:2839471
    Source Port:48152
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.57.207.24558776802839471 05/27/22-12:47:31.306412
    SID:2839471
    Source Port:58776
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.101.222.5660330802839471 05/27/22-12:47:49.004541
    SID:2839471
    Source Port:60330
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack
    Timestamp:192.168.2.2395.100.83.3160434802839471 05/27/22-12:47:51.581498
    SID:2839471
    Source Port:60434
    Destination Port:80
    Protocol:TCP
    Classtype:Web Application Attack

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: kuCwPmEwdMVirustotal: Detection: 53%Perma Link

    Networking

    barindex
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:42456 -> 95.68.75.97:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:35532 -> 95.168.220.97:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:53226 -> 95.217.109.19:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:39848 -> 88.247.238.126:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:58942 -> 88.210.22.221:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:60578 -> 95.167.73.77:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:48188 -> 95.100.170.104:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:46204 -> 95.101.211.165:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:53878 -> 88.150.144.13:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:40702 -> 88.28.199.253:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:46612 -> 112.171.3.218:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:40804 -> 112.223.18.124:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:58192 -> 95.101.70.47:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:36108 -> 95.216.150.190:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:41382 -> 95.130.6.151:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:59082 -> 95.67.237.66:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:41676 -> 88.112.154.174:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:59640 -> 88.255.41.28:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:46688 -> 112.171.3.218:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:59944 -> 95.121.139.125:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:50558 -> 112.17.57.168:80
    Source: TrafficSnort IDS: 2835222 ETPRO EXPLOIT Huawei Remote Command Execution - Outbound (CVE-2017-17215) 192.168.2.23:55698 -> 197.214.98.132:37215
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:49746 -> 112.194.65.252:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:52148 -> 88.214.45.1:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:60044 -> 88.136.54.28:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:37160 -> 112.171.248.108:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:49496 -> 95.100.83.16:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:35412 -> 88.221.188.43:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:48152 -> 88.149.185.118:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:45124 -> 88.249.107.254:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:46042 -> 95.101.242.231:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:60114 -> 95.100.230.20:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:58776 -> 95.57.207.245:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:51092 -> 95.146.194.158:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:54608 -> 88.147.25.230:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:60104 -> 88.210.144.124:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:38576 -> 95.129.137.245:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:55906 -> 95.156.55.29:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:56178 -> 95.101.156.147:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:34828 -> 95.57.98.202:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:36254 -> 88.198.148.238:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:51928 -> 88.136.102.128:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:51586 -> 95.215.255.91:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:32828 -> 95.49.221.109:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:40074 -> 88.198.110.234:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:59134 -> 88.221.78.12:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:44764 -> 95.112.26.176:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:60330 -> 95.101.222.56:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:33488 -> 95.56.53.135:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:54808 -> 88.214.188.140:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:60434 -> 95.100.83.31:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:45600 -> 95.101.23.239:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:38844 -> 95.215.185.234:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:39644 -> 112.17.60.40:80
    Source: TrafficSnort IDS: 2835222 ETPRO EXPLOIT Huawei Remote Command Execution - Outbound (CVE-2017-17215) 192.168.2.23:49730 -> 41.62.245.111:37215
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:50770 -> 95.216.182.207:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:53860 -> 95.159.21.173:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:34152 -> 95.214.234.136:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:52380 -> 95.231.53.220:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:34382 -> 95.100.241.100:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:34392 -> 95.100.241.100:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:49276 -> 95.122.162.81:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:36468 -> 95.65.56.138:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:37596 -> 112.72.51.78:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:39974 -> 95.216.72.71:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:33448 -> 112.205.95.43:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:39842 -> 112.120.6.61:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:59576 -> 95.156.51.102:80
    Source: TrafficSnort IDS: 2835222 ETPRO EXPLOIT Huawei Remote Command Execution - Outbound (CVE-2017-17215) 192.168.2.23:41942 -> 197.234.61.113:37215
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:58194 -> 95.179.137.174:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:48256 -> 95.87.64.255:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:46654 -> 95.68.127.121:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:46568 -> 95.100.208.231:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:34062 -> 88.255.253.42:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:59024 -> 95.159.11.30:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:41774 -> 95.211.75.25:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:39230 -> 95.128.147.220:80
    Source: TrafficSnort IDS: 2839471 ETPRO TROJAN Mirai Variant User-Agent (Outbound) 192.168.2.23:47000 -> 95.57.203.252:80
    Source: unknownNetwork traffic detected: HTTP traffic on port 55698 -> 37215
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55524
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55526
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55610
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55622
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55626
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55654
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55662
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55678
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55724
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 55726
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43074
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43080
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43138
    Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 37215
    Source: unknownNetwork traffic detected: HTTP traffic on port 37215 -> 49730
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43156
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43166
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43168
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43170
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43172
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43176
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43180
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43186
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43198
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43206
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43208
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43208
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43210
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43264
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43326
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43342
    Source: unknownNetwork traffic detected: HTTP traffic on port 41942 -> 37215
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40308
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40314
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40316
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40338
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40342
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40348
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40366
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40368
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40372
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40376
    Source: unknownNetwork traffic detected: HTTP traffic on port 50856 -> 37215
    Source: unknownNetwork traffic detected: HTTP traffic on port 37215 -> 50856
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.180.130.175:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.227.168.94:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.116.102.175:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.246.215.221:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.27.23.175:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.49.38.43:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.69.82.160:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.248.2.238:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.207.185.156:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.16.15.137:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.118.147.237:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.229.188.204:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.167.28.90:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.94.69.60:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.14.237.246:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.189.161.5:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.54.155.68:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.16.211.107:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.112.154.132:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.252.234.6:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.11.2.183:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.202.166.131:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.136.231.90:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.78.195.168:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.99.59.99:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.175.66.217:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.53.165.177:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.157.32.197:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.46.174.67:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.10.198.249:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.119.251.150:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.81.191.35:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.247.214.118:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.220.195.112:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.60.252.66:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.158.16.201:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.170.170.129:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.16.150.35:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.129.25.11:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.135.227.92:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.3.67.242:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.179.132.9:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.244.110.57:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.226.13.23:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.29.239.31:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.231.9.0:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.86.45.83:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.195.8.228:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.226.189.122:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.147.83.240:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.185.252.6:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.254.113.73:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.103.14.255:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.107.28.188:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.134.152.238:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.107.174.7:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.150.188.139:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.23.69.52:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.63.189.38:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.201.107.59:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.192.58.20:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.58.2.239:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.144.107.53:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.162.36.83:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.0.34.53:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.246.238.98:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.43.22.142:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.51.23.136:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.221.208.156:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.37.157.94:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.8.99.211:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.38.13.34:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.133.74.32:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.137.3.78:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.193.194.201:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.204.111.102:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.102.214.10:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.233.207.115:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.77.197.146:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.50.18.225:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.159.118.19:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.20.0.70:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.221.169.251:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.92.173.102:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.79.81.225:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.91.58.13:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.164.176.50:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.84.139.48:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.37.72.195:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.130.176.54:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.82.15.236:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.119.162.243:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.147.75.123:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.199.93.163:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.156.167.238:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.228.222.232:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.170.181.77:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.224.188.234:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.198.97.41:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.80.46.185:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.155.24.88:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.241.198.64:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.46.255.143:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.197.138.47:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.103.187.69:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.73.80.253:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.223.143.118:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.24.79.123:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.210.17.58:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.110.171.171:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.104.187.243:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.236.157.62:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.234.228.194:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.235.67.251:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.173.122.6:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.160.99.24:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.111.125.33:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.209.227.71:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.238.3.24:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.244.66.250:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.224.98.214:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.124.39.68:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.40.126.75:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.147.78.66:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.107.232.205:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.203.21.216:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.159.54.40:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.160.253.124:8080
    Source: global trafficTCP traffic: 192.168.2.23:34376 -> 45.95.55.16:3884
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.69.131.175:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.132.103.175:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.182.113.60:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.31.243.228:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.59.218.169:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.98.167.27:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.231.216.146:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.142.90.76:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.98.231.70:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.132.238.249:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.121.77.67:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.134.178.9:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.85.53.240:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.141.62.67:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.202.195.245:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.196.66.253:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.35.67.137:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.37.214.65:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.134.52.12:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.182.93.127:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.225.194.145:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.199.186.253:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.96.113.194:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.163.90.241:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.230.14.232:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.105.212.155:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.211.135.36:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.215.94.34:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.197.112.214:37215
    Source: global trafficTCP traffic: 192.168.2.23:63767 -> 197.240.45.223:37215
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.175.139.70:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.37.156.186:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.248.237.115:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.234.219.166:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.92.77.154:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.217.64.204:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.143.156.10:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.52.97.10:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.236.109.76:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.199.147.158:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.162.73.125:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.226.228.44:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.243.246.133:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.249.63.83:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.213.183.195:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.202.80.137:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.114.47.29:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.217.254.26:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.68.47.95:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.108.80.165:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.252.225.180:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.255.14.94:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.70.176.56:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.11.14.66:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.95.0.127:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.124.105.153:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.225.5.106:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.207.117.102:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.170.58.224:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.146.62.128:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.158.8.34:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.160.218.224:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.12.135.246:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.151.53.50:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.33.199.82:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.190.61.109:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.248.194.65:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.115.31.246:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.246.185.238:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.10.216.61:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.208.66.168:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.65.169.172:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.181.129.205:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.87.212.138:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.73.204.83:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.77.232.222:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.10.25.148:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.34.199.29:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.4.135.3:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.184.161.195:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.226.138.87:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.4.190.60:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.181.209.191:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.154.98.78:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.49.101.201:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.99.239.24:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.104.89.57:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.72.180.247:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.65.117.156:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.143.122.177:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.73.158.7:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.210.153.41:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.186.140.81:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.153.116.63:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.60.178.119:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.40.79.122:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.160.162.115:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.190.111.206:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.155.56.159:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.235.25.102:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.99.114.14:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.203.170.124:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.75.42.135:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.243.3.237:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.245.169.234:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.223.4.35:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.153.33.13:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.82.75.6:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.182.93.127:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.104.203.250:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.18.8.224:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.124.153.31:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.126.31.212:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.18.135.10:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.2.233.82:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.77.95.40:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.136.34.236:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.215.63.72:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.211.83.84:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.14.162.96:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.191.108.241:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.32.181.161:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.29.227.111:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.168.115.79:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.95.61.231:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.92.54.84:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.248.3.215:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.52.66.159:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.2.111.35:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.215.39.11:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.211.153.210:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.192.56.252:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.6.43.1:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.118.146.191:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.252.248.97:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.222.53.116:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.115.128.46:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.102.161.87:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.52.197.58:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.224.146.96:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.228.28.75:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.54.149.158:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.113.180.190:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.60.138.187:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.43.84.40:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.186.181.25:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.223.66.237:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.128.212.148:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.179.209.148:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.20.114.1:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.138.89.77:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.129.49.188:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.22.11.251:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.150.202.42:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.124.232.227:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.145.28.132:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.242.245.163:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.68.149.197:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.18.73.1:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.169.51.253:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.249.46.167:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.29.111.182:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.65.50.82:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.40.114.226:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.235.64.58:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.38.199.25:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.246.68.21:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.198.112.108:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.179.48.56:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.112.49.172:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.147.24.140:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.123.172.111:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.171.83.99:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.132.10.68:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.244.39.167:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.104.160.217:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.10.239.190:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.27.72.36:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.79.196.183:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.58.125.188:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.206.215.61:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.4.47.34:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.41.180.37:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.31.75.100:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.17.111.124:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.28.0.153:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.243.178.203:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.203.96.13:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.49.142.37:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.115.99.102:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.198.40.107:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.54.203.92:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.248.172.186:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.6.5.200:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.152.107.220:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.157.31.222:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.68.208.225:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.179.69.252:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.246.213.242:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.80.27.127:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.22.182.23:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.231.25.118:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.177.45.122:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.203.133.153:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.147.170.89:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.96.8.30:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.24.195.28:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.180.34.150:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.131.98.183:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.231.14.91:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.102.9.226:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 31.120.125.141:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.113.107.159:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.63.55.123:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.204.17.175:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.84.84.58:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.219.246.217:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 95.19.140.252:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.158.207.74:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.110.110.86:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.41.23.129:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 85.178.164.231:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 62.195.206.173:8080
    Source: global trafficTCP traffic: 192.168.2.23:63785 -> 94.67.235.210:8080
    Source: global trafficTCP traffic: 192.168.2.