Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
VefqQeU0Xt

Overview

General Information

Sample Name:VefqQeU0Xt
Analysis ID:679266
MD5:b8ec31b1eff948abc9e797eb796d10cb
SHA1:5590da71a98232aa873143780f4f9e36e1a8359a
SHA256:f67ac47d33f3681cd957585c4338c43e939eb5fc0d8da4ac84aa33ccf52fcb1e
Tags:32armelfmirai
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected Mirai
Multi AV Scanner detection for submitted file
Searches for CPU information (likely indicative for DDoS capability)
Uses known network protocols on non-standard ports
Executes the "grep" command used to find patterns in files or piped streams
Executes the "wget" command typically used for HTTP/S downloading
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "uname" command used to read OS and architecture name
Detected TCP or UDP traffic on non-standard ports
Executes the "mktemp" command used to create a temporary unique file name
Sample listens on a socket
Sample has stripped symbol table
Reads CPU information from /proc indicative of miner or evasive malware
Executes the "rm" command used to delete files or directories

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox Version:35.0.0 Citrine
Analysis ID:679266
Start date and time: 05/08/202213:55:022022-08-05 13:55:02 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 15s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:VefqQeU0Xt
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.troj.mine.lin@0/4@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/VefqQeU0Xt
PID:6253
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
your device just got infected to a bootnoot
Standard Error:
  • system is lnxubuntu20
  • systemd New Fork (PID: 6200, Parent: 1)
  • 50-motd-news (PID: 6200, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/update-motd.d/50-motd-news --force
    • mktemp (PID: 6221, Parent: 6200, MD5: e117ed1c2172d436fa31cc9d263131e8) Arguments: mktemp
    • mktemp (PID: 6222, Parent: 6200, MD5: e117ed1c2172d436fa31cc9d263131e8) Arguments: mktemp
    • mktemp (PID: 6223, Parent: 6200, MD5: e117ed1c2172d436fa31cc9d263131e8) Arguments: mktemp
    • 50-motd-news New Fork (PID: 6224, Parent: 6200)
      • dpkg (PID: 6225, Parent: 6224, MD5: 5e18156b434fc45062eec2f28b9147be) Arguments: dpkg -l wget
      • dpkg-query (PID: 6225, Parent: 6224, MD5: bf81745ea62201f11bc674cc7c1935fc) Arguments: dpkg-query --list -- wget
      • awk (PID: 6226, Parent: 6224, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "$1 == \"ii\" { print($3); exit(0); }"
    • 50-motd-news New Fork (PID: 6228, Parent: 6200)
      • sed (PID: 6230, Parent: 6228, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -e "s/ /\\//g"
    • uname (PID: 6231, Parent: 6200, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -o
    • uname (PID: 6232, Parent: 6200, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -r
    • uname (PID: 6233, Parent: 6200, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -m
    • uname (PID: 6234, Parent: 6200, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -m
    • 50-motd-news New Fork (PID: 6235, Parent: 6200)
      • grep (PID: 6236, Parent: 6235, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -m1 "^model name" /proc/cpuinfo
      • sed (PID: 6237, Parent: 6235, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -e "s/.*: //" -e s:\\s\\+:/:g
    • cloud-id (PID: 6238, Parent: 6200, MD5: 69f442c3e33b5f9a66b722c29ad89435) Arguments: /usr/bin/cloud-id
      • cloud-id New Fork (PID: 6243, Parent: 6238)
      • uname (PID: 6243, Parent: 6238, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -p
    • 50-motd-news New Fork (PID: 6244, Parent: 6200)
      • cut (PID: 6245, Parent: 6244, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -40 /tmp/tmp.ZtXsY8H9DY
      • tr (PID: 6246, Parent: 6244, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -c -d [:alnum:]
    • wget (PID: 6247, Parent: 6200, MD5: 996940118df7bb2aaa718589d4e95c08) Arguments: wget --timeout 60 -U "wget/1.20.3-1ubuntu1 Ubuntu/20.04.2/LTS GNU/Linux/5.4.0-72-generic/x86_64 Intel(R)/Xeon(R)/Silver/4210/CPU/@/2.20GHz cloud_id/none" -O- --content-on-error https://motd.ubuntu.com
    • cat (PID: 6259, Parent: 6200, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.EQLgjCNBFD
    • head (PID: 6260, Parent: 6200, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
    • tr (PID: 6261, Parent: 6200, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
    • cut (PID: 6262, Parent: 6200, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
    • cat (PID: 6263, Parent: 6200, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.EQLgjCNBFD
    • head (PID: 6264, Parent: 6200, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
    • tr (PID: 6265, Parent: 6200, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
    • cut (PID: 6266, Parent: 6200, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
    • rm (PID: 6269, Parent: 6200, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.EQLgjCNBFD /tmp/tmp.ONisxp5pqw /tmp/tmp.ZtXsY8H9DY
  • VefqQeU0Xt (PID: 6253, Parent: 6122, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/VefqQeU0Xt
  • cleanup
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: VefqQeU0XtAvira: detected
    Source: VefqQeU0XtVirustotal: Detection: 50%Perma Link
    Source: VefqQeU0XtMetadefender: Detection: 52%Perma Link
    Source: VefqQeU0XtReversingLabs: Detection: 47%

    Bitcoin Miner

    barindex
    Source: /etc/update-motd.d/50-motd-news (PID: 6236)Executable: /usr/bin/grep -> grep -m1 "^model name" /proc/cpuinfo
    Source: /usr/bin/grep (PID: 6236)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

    Networking

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58912
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58916
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58924
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58926
    Source: /etc/update-motd.d/50-motd-news (PID: 6247)Wget executable: /usr/bin/wget -> wget --timeout 60 -U "wget/1.20.3-1ubuntu1 Ubuntu/20.04.2/LTS GNU/Linux/5.4.0-72-generic/x86_64 Intel(R)/Xeon(R)/Silver/4210/CPU/@/2.20GHz cloud_id/none" -O- --content-on-error https://motd.ubuntu.com
    Source: global trafficTCP traffic: 192.168.2.23:38184 -> 31.7.58.162:5556
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 191.30.223.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 100.149.208.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 37.123.5.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 161.65.22.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 216.169.15.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 58.18.79.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 95.153.125.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 58.93.74.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 216.144.63.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 52.189.88.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 97.127.204.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 69.23.92.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 75.182.97.253:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 161.162.119.248:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 138.126.202.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 93.22.3.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 248.91.165.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 137.79.23.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 40.74.62.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 165.71.70.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 60.27.61.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 252.58.4.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 156.37.82.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 255.28.159.96:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 249.86.240.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 166.123.185.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 222.141.118.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 177.57.137.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 93.58.244.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 159.68.99.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 1.38.50.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 60.2.238.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 97.187.77.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 201.240.124.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 16.220.124.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 84.198.238.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 115.32.190.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 66.228.208.79:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 80.103.20.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 183.142.183.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 142.138.102.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 114.243.122.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 212.112.223.78:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 93.86.25.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 61.189.246.187:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 249.116.14.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 120.48.145.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 70.181.229.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 45.113.181.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 139.221.25.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 100.73.90.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 112.11.227.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 219.59.141.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 146.44.141.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 95.121.14.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 183.25.166.145:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 1.48.96.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 47.49.80.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 196.118.125.46:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 63.113.204.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 99.10.49.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 205.184.0.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 41.16.212.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 149.156.21.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 151.224.168.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 16.157.212.231:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 181.122.156.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 140.209.235.206:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 52.135.34.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 9.117.77.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 49.72.218.46:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 244.23.77.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 155.63.137.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 249.192.85.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 169.36.16.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 122.150.227.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 72.122.10.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 216.109.192.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 166.76.115.64:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 145.181.147.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 32.24.211.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 154.102.33.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 129.160.183.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 70.28.86.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 130.228.129.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 98.241.154.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 28.112.170.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 93.223.64.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 211.91.188.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 26.148.44.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 92.34.51.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 128.97.49.243:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 30.201.175.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 252.73.111.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 188.252.161.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 128.161.117.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 32.137.121.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 211.40.87.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 118.22.255.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 43.127.4.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 243.244.81.251:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 158.53.46.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 64.83.127.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 90.25.243.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.86.127.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 18.20.18.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 215.235.7.93:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 74.181.104.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 50.181.82.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 72.156.68.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 241.67.238.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 152.1.205.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.201.76.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 130.124.97.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 96.255.174.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 100.30.224.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 176.238.226.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 93.250.8.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 156.169.194.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 94.29.93.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 242.252.94.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 133.114.241.69:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 170.119.172.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 47.1.150.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 20.26.146.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 223.92.152.66:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 134.127.129.137:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 206.36.23.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 38.255.93.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 207.209.34.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 160.11.84.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 193.43.189.75:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 105.251.60.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 37.141.66.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 164.160.233.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 18.15.186.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 166.241.251.156:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 146.171.20.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 169.121.12.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 115.139.50.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 144.119.86.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 175.7.240.248:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 163.31.52.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 223.2.238.1:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 30.217.21.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 48.247.235.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 219.19.11.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 184.129.91.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 135.145.85.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.168.1.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 129.88.103.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 7.73.51.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 41.21.27.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 179.140.118.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 50.185.18.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 94.16.244.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 81.106.195.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 6.220.203.46:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 39.5.130.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.86.83.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 104.200.255.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 141.177.33.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 184.190.19.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 88.207.77.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 95.249.70.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 223.210.128.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 132.43.136.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 241.86.79.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 104.115.1.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 108.25.162.64:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 63.6.103.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 113.104.178.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 139.67.69.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 155.112.183.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 96.208.137.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 149.195.210.156:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 186.101.78.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 240.250.193.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 186.50.185.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 211.177.156.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 49.169.234.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 157.127.84.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 253.235.101.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 15.211.101.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 75.11.100.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 202.53.170.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 4.61.228.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 198.182.125.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 128.45.178.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 19.42.217.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 147.216.18.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 83.157.61.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 43.237.133.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 32.92.24.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 169.35.143.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 63.67.82.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 182.223.30.243:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 34.179.43.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 89.239.124.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 120.12.207.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 41.25.74.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 143.116.120.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 11.71.52.187:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 201.118.201.87:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 206.115.85.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 41.234.155.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 106.137.252.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 12.201.207.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 124.254.36.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 162.22.183.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 204.206.6.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 41.163.78.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 221.106.236.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 183.142.37.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 77.33.41.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 71.223.52.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 96.241.7.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 139.10.236.195:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 160.5.220.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 129.206.122.93:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 94.155.231.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 200.60.35.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 101.18.194.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.62.119.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 62.33.227.170:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 43.98.101.252:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 253.54.235.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 92.50.123.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 198.165.45.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 93.48.104.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 200.56.163.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 68.39.141.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 125.209.18.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 176.254.111.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 102.147.217.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 50.143.75.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 116.157.97.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 19.228.156.106:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 69.50.35.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 250.84.226.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 195.202.188.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 161.100.159.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 160.215.59.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 45.128.28.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 107.92.239.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 52.209.48.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 112.48.63.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 22.182.247.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 70.115.154.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 151.177.75.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 51.174.11.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 159.164.163.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 80.224.241.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 220.35.159.152:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 152.233.14.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 115.231.166.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 121.120.85.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 149.178.33.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 173.35.213.93:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 125.123.249.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 151.27.64.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.118.164.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 180.195.193.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 43.143.52.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 133.122.50.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 22.109.132.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 115.104.128.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 23.112.166.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 213.183.166.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 52.249.189.145:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 165.241.96.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 7.27.150.252:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 149.96.205.109:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 54.86.218.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 204.158.213.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 29.200.225.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 173.47.108.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 11.152.152.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 21.40.108.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 29.119.31.146:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 215.164.51.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 246.248.193.53:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 152.15.24.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 209.97.66.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 34.192.104.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 241.254.158.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 51.5.188.83:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 216.224.200.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 116.52.78.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 6.72.235.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 166.145.18.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 122.213.104.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 23.57.167.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.122.27.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 107.156.86.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 21.162.102.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 203.19.203.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 50.255.87.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 73.129.106.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 66.48.146.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 246.219.167.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 195.182.42.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 42.225.72.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 71.67.244.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 166.224.69.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 9.140.146.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 32.86.189.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 101.116.41.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 53.3.3.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 165.95.230.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 143.0.146.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 194.237.52.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 37.191.102.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 203.241.101.152:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 48.184.111.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 74.199.218.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 13.151.143.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 73.19.147.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 214.192.208.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 195.115.109.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 216.210.167.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 61.46.132.145:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 69.229.227.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 141.86.247.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 9.132.137.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 29.84.77.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 158.53.106.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 117.140.100.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 222.207.255.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 148.177.27.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 59.43.101.106:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 137.49.86.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 206.28.114.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 194.131.160.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 84.91.223.38:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 181.21.84.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 83.10.113.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 99.6.118.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 252.72.52.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 118.145.25.170:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 190.141.63.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 94.229.20.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 83.4.199.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 164.213.255.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 218.60.2.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 92.87.236.155:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 147.14.134.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 52.188.22.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 175.87.158.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 217.165.197.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 43.73.112.73:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 35.228.2.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 218.115.126.233:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 187.121.27.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 125.91.58.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 36.236.209.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 186.66.235.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 87.205.234.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 38.163.154.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 99.71.17.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 214.106.121.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 71.157.150.46:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 14.184.169.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 75.111.66.28:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 200.242.41.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 104.159.245.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 22.91.239.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 146.169.70.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 164.92.82.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 26.180.145.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 214.249.140.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 201.96.143.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 142.244.255.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 193.86.69.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 91.49.155.118:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 206.18.246.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 198.249.190.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 208.116.93.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 208.194.237.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 202.253.113.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 94.73.103.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 129.13.251.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 49.117.62.243:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 95.211.103.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 65.188.108.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 112.191.120.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 180.77.41.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 37.72.139.13:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 43.33.38.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 250.204.91.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 110.236.25.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 102.38.174.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 72.97.54.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 118.11.31.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 253.195.76.213:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 105.3.186.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 240.20.165.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 13.60.25.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 131.12.79.41:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 81.113.166.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 183.55.11.213:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 171.88.53.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 85.148.58.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 137.182.56.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 113.76.239.253:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 126.221.197.47:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 194.12.9.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 80.222.133.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 70.54.141.79:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 140.40.99.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 106.106.247.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 106.246.88.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 18.62.37.187:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 134.141.188.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 118.225.182.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 247.13.244.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 118.10.159.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 136.129.83.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 65.29.70.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 37.37.80.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 92.17.78.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 87.114.248.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 46.57.209.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 94.14.122.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 43.253.223.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 38.244.205.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 55.141.67.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 198.102.103.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 1.225.247.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 70.140.233.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 73.177.200.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 69.172.1.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 26.19.36.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 164.104.171.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 118.8.184.38:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 129.77.119.231:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 188.59.111.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 54.209.90.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 155.221.62.166:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 100.159.228.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 242.19.119.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 109.75.247.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 135.79.28.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 12.169.248.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 222.225.171.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 250.109.130.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 112.119.162.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 181.225.220.252:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 184.12.228.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 95.152.251.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 25.230.132.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 110.13.106.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 188.203.130.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 142.208.85.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 162.223.103.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 95.118.253.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 59.29.195.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 140.188.100.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 138.49.30.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 47.155.194.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 157.157.59.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 153.93.84.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 154.209.219.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 60.32.17.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 152.88.254.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 191.32.75.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 63.30.194.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 91.135.35.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 15.176.207.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 133.86.31.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 143.83.204.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 93.49.121.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 206.232.39.41:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 6.202.183.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 113.44.219.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 61.15.33.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 169.88.69.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 132.103.51.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 144.74.85.38:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 207.167.228.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 67.239.39.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 151.228.9.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 251.6.97.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 133.84.12.147:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 157.146.136.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 176.24.165.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 207.0.37.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 129.39.29.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 175.35.140.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 222.69.67.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 3.40.241.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 128.90.179.38:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 147.247.120.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 222.185.82.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 129.57.14.228:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 97.168.175.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 169.71.207.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 165.207.123.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:27127 -> 170.145.209.235:2323
    Source: /tmp/VefqQeU0Xt (PID: 6253)Socket: 127.0.0.1::4668
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33616
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33616 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 31.7.58.162
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
    Source: unknownTCP traffic detected without corresponding DNS query: 92.240.212.111
    Source: unknownTCP traffic detected without corresponding DNS query: 191.30.223.111
    Source: unknownTCP traffic detected without corresponding DNS query: 192.59.80.156
    Source: unknownTCP traffic detected without corresponding DNS query: 47.184.111.104
    Source: unknownTCP traffic detected without corresponding DNS query: 191.102.53.236
    Source: unknownTCP traffic detected without corresponding DNS query: 220.216.99.136
    Source: unknownTCP traffic detected without corresponding DNS query: 215.99.232.174
    Source: unknownTCP traffic detected without corresponding DNS query: 97.141.194.17
    Source: unknownTCP traffic detected without corresponding DNS query: 26.238.62.70
    Source: unknownTCP traffic detected without corresponding DNS query: 194.213.28.114
    Source: unknownTCP traffic detected without corresponding DNS query: 100.149.208.9
    Source: unknownTCP traffic detected without corresponding DNS query: 78.55.226.3
    Source: unknownTCP traffic detected without corresponding DNS query: 118.134.191.213
    Source: unknownTCP traffic detected without corresponding DNS query: 111.69.31.143
    Source: unknownTCP traffic detected without corresponding DNS query: 174.29.179.151
    Source: unknownTCP traffic detected without corresponding DNS query: 140.127.145.26
    Source: unknownTCP traffic detected without corresponding DNS query: 49.4.192.238
    Source: unknownTCP traffic detected without corresponding DNS query: 89.135.24.152
    Source: unknownTCP traffic detected without corresponding DNS query: 63.182.68.30
    Source: unknownTCP traffic detected without corresponding DNS query: 37.123.5.229
    Source: unknownTCP traffic detected without corresponding DNS query: 22.47.147.217
    Source: unknownTCP traffic detected without corresponding DNS query: 76.20.22.151
    Source: unknownTCP traffic detected without corresponding DNS query: 221.79.225.118
    Source: unknownTCP traffic detected without corresponding DNS query: 183.143.197.44
    Source: unknownTCP traffic detected without corresponding DNS query: 77.23.199.142
    Source: unknownTCP traffic detected without corresponding DNS query: 104.46.191.149
    Source: unknownTCP traffic detected without corresponding DNS query: 113.208.229.47
    Source: unknownTCP traffic detected without corresponding DNS query: 161.65.22.168
    Source: unknownTCP traffic detected without corresponding DNS query: 159.106.12.96
    Source: unknownTCP traffic detected without corresponding DNS query: 144.114.107.235
    Source: unknownTCP traffic detected without corresponding DNS query: 93.116.19.127
    Source: unknownTCP traffic detected without corresponding DNS query: 189.176.215.111
    Source: unknownTCP traffic detected without corresponding DNS query: 203.66.11.88
    Source: unknownTCP traffic detected without corresponding DNS query: 199.38.203.72
    Source: unknownTCP traffic detected without corresponding DNS query: 186.98.116.215
    Source: unknownTCP traffic detected without corresponding DNS query: 1.78.235.5
    Source: unknownTCP traffic detected without corresponding DNS query: 216.169.15.177
    Source: unknownTCP traffic detected without corresponding DNS query: 3.123.192.200
    Source: tmp.ONisxp5pqw.48.drString found in binary or memory: https://motd.ubuntu.com/
    Source: motd-news.70.dr, tmp.EQLgjCNBFD.48.drString found in binary or memory: https://ubuntu.com/blog/microk8s-memory-optimisation

    DDoS

    barindex
    Source: /etc/update-motd.d/50-motd-news (PID: 6236)Executable: /usr/bin/grep -> grep -m1 "^model name" /proc/cpuinfo
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal72.troj.mine.lin@0/4@0/0
    Source: /etc/update-motd.d/50-motd-news (PID: 6236)Grep executable: /usr/bin/grep -> grep -m1 "^model name" /proc/cpuinfo
    Source: /etc/update-motd.d/50-motd-news (PID: 6247)Wget executable: /usr/bin/wget -> wget --timeout 60 -U "wget/1.20.3-1ubuntu1 Ubuntu/20.04.2/LTS GNU/Linux/5.4.0-72-generic/x86_64 Intel(R)/Xeon(R)/Silver/4210/CPU/@/2.20GHz cloud_id/none" -O- --content-on-error https://motd.ubuntu.com
    Source: /usr/bin/grep (PID: 6236)Reads from proc file: /proc/cpuinfoJump to behavior
    Source: /etc/update-motd.d/50-motd-news (PID: 6221)Mktemp executable: /usr/bin/mktemp -> mktemp
    Source: /etc/update-motd.d/50-motd-news (PID: 6222)Mktemp executable: /usr/bin/mktemp -> mktemp
    Source: /etc/update-motd.d/50-motd-news (PID: 6223)Mktemp executable: /usr/bin/mktemp -> mktemp
    Source: /etc/update-motd.d/50-motd-news (PID: 6269)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.EQLgjCNBFD /tmp/tmp.ONisxp5pqw /tmp/tmp.ZtXsY8H9DY
    Source: /etc/update-motd.d/50-motd-news (PID: 6226)Awk executable: /usr/bin/awk -> awk "$1 == \"ii\" { print($3); exit(0); }"
    Source: /etc/update-motd.d/50-motd-news (PID: 6230)Sed executable: /usr/bin/sed -> sed -e "s/ /\\//g"
    Source: /etc/update-motd.d/50-motd-news (PID: 6237)Sed executable: /usr/bin/sed -> sed -e "s/.*: //" -e s:\\s\\+:/:g

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58912
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58916
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58924
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58926
    Source: /usr/bin/uname (PID: 6232)Queries kernel information via 'uname':
    Source: /usr/bin/uname (PID: 6233)Queries kernel information via 'uname':
    Source: /usr/bin/uname (PID: 6234)Queries kernel information via 'uname':
    Source: /usr/bin/cloud-id (PID: 6238)Queries kernel information via 'uname':
    Source: /usr/bin/uname (PID: 6243)Queries kernel information via 'uname':
    Source: /usr/bin/wget (PID: 6247)Queries kernel information via 'uname':
    Source: /tmp/VefqQeU0Xt (PID: 6253)Queries kernel information via 'uname':
    Source: /usr/bin/grep (PID: 6236)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
    Source: VefqQeU0Xt, 6253.1.000055a0d3ae5000.000055a0d3c13000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
    Source: VefqQeU0Xt, 6253.1.000055a0d3ae5000.000055a0d3c13000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
    Source: VefqQeU0Xt, 6253.1.00007ffd83793000.00007ffd837b4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
    Source: VefqQeU0Xt, 6253.1.00007ffd83793000.00007ffd837b4000.rw-.sdmpBinary or memory string: Qx86_64/usr/bin/qemu-arm/tmp/VefqQeU0XtSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/VefqQeU0Xt

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Source: /etc/update-motd.d/50-motd-news (PID: 6231)Uname executable: /usr/bin/uname -> uname -o
    Source: /etc/update-motd.d/50-motd-news (PID: 6232)Uname executable: /usr/bin/uname -> uname -r
    Source: /etc/update-motd.d/50-motd-news (PID: 6233)Uname executable: /usr/bin/uname -> uname -m
    Source: /etc/update-motd.d/50-motd-news (PID: 6234)Uname executable: /usr/bin/uname -> uname -m
    Source: /usr/bin/cloud-id (PID: 6243)Uname executable: /usr/bin/uname -> uname -p

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid Accounts2
    Command and Scripting Interpreter
    Path InterceptionPath Interception1
    Hide Artifacts
    OS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    1
    Jamming or Denial of Service
    Remotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    File Deletion
    LSASS Memory3
    System Information Discovery
    Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration11
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 679266 Sample: VefqQeU0Xt Startdate: 05/08/2022 Architecture: LINUX Score: 72 37 209.31.34.220 XO-AS15US United States 2->37 39 169.205.233.129 WA-K20US United States 2->39 41 98 other IPs or domains 2->41 45 Antivirus / Scanner detection for submitted sample 2->45 47 Multi AV Scanner detection for submitted file 2->47 49 Yara detected Mirai 2->49 51 Uses known network protocols on non-standard ports 2->51 8 systemd 50-motd-news VefqQeU0Xt 2->8         started        signatures3 process4 process5 10 50-motd-news 8->10         started        12 50-motd-news 8->12         started        14 50-motd-news 8->14         started        16 20 other processes 8->16 process6 18 50-motd-news grep 10->18         started        21 50-motd-news sed 10->21         started        23 50-motd-news dpkg dpkg-query 12->23         started        25 50-motd-news awk 12->25         started        27 50-motd-news cut 14->27         started        29 50-motd-news tr 14->29         started        31 cloud-id uname 16->31         started        33 50-motd-news sed 16->33         started        35 2 other processes 16->35 signatures7 43 Searches for CPU information (likely indicative for DDoS capability) 18->43
    SourceDetectionScannerLabelLink
    VefqQeU0Xt50%VirustotalBrowse
    VefqQeU0Xt52%MetadefenderBrowse
    VefqQeU0Xt48%ReversingLabsLinux.Trojan.Mirai
    VefqQeU0Xt100%AviraLINUX/Mirai.evuay
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    https://motd.ubuntu.com/tmp.ONisxp5pqw.48.drfalse
      high
      https://ubuntu.com/blog/microk8s-memory-optimisationmotd-news.70.dr, tmp.EQLgjCNBFD.48.drfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        98.205.175.119
        unknownUnited States
        7922COMCAST-7922USfalse
        74.105.231.151
        unknownUnited States
        701UUNETUSfalse
        15.142.60.68
        unknownUnited States
        5073HPESUSfalse
        56.101.167.101
        unknownUnited States
        2686ATGS-MMD-ASUSfalse
        21.86.198.60
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        126.47.246.73
        unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
        128.5.96.104
        unknownUnited States
        3389FORDSRL-ASUSfalse
        92.210.207.233
        unknownGermany
        3209VODANETInternationalIP-BackboneofVodafoneDEfalse
        251.38.253.40
        unknownReserved
        unknownunknownfalse
        209.31.34.220
        unknownUnited States
        2828XO-AS15USfalse
        189.138.184.246
        unknownMexico
        8151UninetSAdeCVMXfalse
        79.115.120.145
        unknownRomania
        8708RCS-RDS73-75DrStaicoviciROfalse
        115.35.234.224
        unknownChina
        4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
        179.52.79.6
        unknownDominican Republic
        6400CompaniaDominicanadeTelefonosSADOfalse
        44.60.239.46
        unknownUnited States
        7377UCSDUSfalse
        175.36.15.194
        unknownAustralia
        4804MPX-ASMicroplexPTYLTDAUfalse
        217.151.153.64
        unknownGermany
        9022TWL-KOM-ASDonnersbergweg4DEfalse
        47.190.69.170
        unknownUnited States
        5650FRONTIER-FRTRUSfalse
        242.80.21.17
        unknownReserved
        unknownunknownfalse
        1.45.73.121
        unknownChina
        45083CHEERYZONEBeijingCheeryZoneScitechCoLtdCNfalse
        43.106.254.183
        unknownJapan4249LILLY-ASUSfalse
        188.54.137.99
        unknownSaudi Arabia
        25019SAUDINETSTC-ASSAfalse
        89.164.32.20
        unknownCroatia (LOCAL Name: Hrvatska)
        13046ASN-ISKONHEPHRfalse
        251.176.62.50
        unknownReserved
        unknownunknownfalse
        169.205.233.129
        unknownUnited States
        10430WA-K20USfalse
        199.241.205.94
        unknownUnited States
        36529AXXA-RACKCOUSfalse
        107.72.240.241
        unknownUnited States
        7018ATT-INTERNET4USfalse
        180.63.191.8
        unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
        15.196.180.215
        unknownUnited States
        7430TANDEMUSfalse
        152.120.53.132
        unknownUnited States
        2576DOT-ASUSfalse
        66.186.165.62
        unknownUnited States
        21547OXNETUSfalse
        188.194.118.74
        unknownGermany
        31334KABELDEUTSCHLAND-ASDEfalse
        146.189.60.206
        unknownUnited States
        1968UMASSP-DOMUSfalse
        15.152.172.29
        unknownUnited States
        71HP-INTERNET-ASUSfalse
        61.235.174.146
        unknownChina
        9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
        12.245.37.186
        unknownUnited States
        7018ATT-INTERNET4USfalse
        151.65.106.122
        unknownItaly
        1267ASN-WINDTREIUNETEUfalse
        106.162.29.233
        unknownJapan2516KDDIKDDICORPORATIONJPfalse
        66.1.102.108
        unknownUnited States
        3651SPRINT-BB6USfalse
        220.249.23.189
        unknownChina
        4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
        167.8.217.28
        unknownUnited States
        3816COLOMBIATELECOMUNICACIONESSAESPCOfalse
        48.184.111.104
        unknownUnited States
        2686ATGS-MMD-ASUSfalse
        197.132.217.115
        unknownEgypt
        24835RAYA-ASEGfalse
        169.202.199.165
        unknownSouth Africa
        37611AfrihostZAfalse
        182.82.174.104
        unknownChina
        23771SXBCTV-APSXBCTVInternetServiceProviderCNfalse
        134.18.244.239
        unknownAustralia
        385AFCONC-BLOCK1-ASUSfalse
        196.247.60.225
        unknownSeychelles
        41564AS41564SEfalse
        145.131.223.72
        unknownNetherlands
        28685ASN-ROUTITNLfalse
        91.44.2.107
        unknownGermany
        3320DTAGInternetserviceprovideroperationsDEfalse
        86.86.132.45
        unknownNetherlands
        1136KPNKPNNationalEUfalse
        112.20.205.10
        unknownChina
        56046CMNET-JIANGSU-APChinaMobilecommunicationscorporationCNfalse
        199.209.36.222
        unknownUnited States
        721DNIC-ASBLK-00721-00726USfalse
        134.12.55.229
        unknownUnited States
        270AS270USfalse
        157.168.230.20
        unknownSwitzerland
        22192SSHENETUSfalse
        253.216.122.239
        unknownReserved
        unknownunknownfalse
        131.127.120.80
        unknownUnited States
        668DNIC-AS-00668USfalse
        166.146.116.6
        unknownUnited States
        6167CELLCO-PARTUSfalse
        153.15.14.86
        unknownNorway
        4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
        53.193.209.203
        unknownGermany
        31399DAIMLER-ASITIGNGlobalNetworkDEfalse
        58.167.228.180
        unknownAustralia
        1221ASN-TELSTRATelstraCorporationLtdAUfalse
        177.72.19.16
        unknownunknown
        262537DataSafeITSolucoesemTecnologiaBRfalse
        80.33.186.77
        unknownSpain
        3352TELEFONICA_DE_ESPANAESfalse
        212.137.210.222
        unknownUnited Kingdom
        1273CWVodafoneGroupPLCEUfalse
        203.137.219.160
        unknownJapan4694IDCFIDCFrontierIncJPfalse
        212.222.240.70
        unknownUnited Kingdom
        3257GTT-BACKBONEGTTDEfalse
        69.181.177.29
        unknownUnited States
        7922COMCAST-7922USfalse
        152.130.163.46
        unknownUnited States
        29992VA-TMP-COREUSfalse
        17.3.87.29
        unknownUnited States
        714APPLE-ENGINEERINGUSfalse
        217.46.188.101
        unknownUnited Kingdom
        6871PLUSNETUKInternetServiceProviderGBfalse
        27.59.44.110
        unknownIndia
        45609BHARTI-MOBILITY-AS-APBhartiAirtelLtdASforGPRSServicefalse
        65.13.253.121
        unknownUnited States
        7018ATT-INTERNET4USfalse
        56.25.161.4
        unknownUnited States
        2686ATGS-MMD-ASUSfalse
        1.119.157.21
        unknownChina
        4847CNIX-APChinaNetworksInter-ExchangeCNfalse
        184.118.230.138
        unknownUnited States
        7922COMCAST-7922USfalse
        193.207.211.160
        unknownItaly
        3269ASN-IBSNAZITfalse
        204.235.126.14
        unknownUnited States
        30030SIMPLEXITYUSfalse
        119.90.12.105
        unknownChina
        24143CNNIC-QCN-APQingdaoCableTVNetworkCenterCNfalse
        61.130.143.143
        unknownChina
        4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
        57.254.163.62
        unknownBelgium
        2686ATGS-MMD-ASUSfalse
        22.180.220.222
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        22.216.57.76
        unknownUnited States
        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
        200.19.1.255
        unknownBrazil
        2716UniversidadeFederaldoRioGrandedoSulBRfalse
        130.41.40.1
        unknownUnited States
        243HARRIS-ATD-ASUSfalse
        16.128.90.16
        unknownUnited States
        unknownunknownfalse
        18.232.167.114
        unknownUnited States
        14618AMAZON-AESUSfalse
        129.234.12.157
        unknownUnited Kingdom
        786JANETJiscServicesLimitedGBfalse
        211.127.141.254
        unknownJapan4725ODNSoftBankMobileCorpJPfalse
        218.69.20.117
        unknownChina
        4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
        133.59.142.56
        unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
        11.226.204.223
        unknownUnited States
        3356LEVEL3USfalse
        48.166.50.111
        unknownUnited States
        2686ATGS-MMD-ASUSfalse
        84.185.121.75
        unknownGermany
        3320DTAGInternetserviceprovideroperationsDEfalse
        3.89.7.218
        unknownUnited States
        14618AMAZON-AESUSfalse
        161.81.250.8
        unknownHong Kong
        137872PEOPLESPHONE-HKChinaMobileHongKongCompanyLimitedHKfalse
        59.55.32.214
        unknownChina
        4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
        150.223.227.59
        unknownChina
        58519CHINATELECOM-CTCLOUDCloudComputingCorporationCNfalse
        54.2.225.241
        unknownUnited States
        14618AMAZON-AESUSfalse
        240.253.190.20
        unknownReserved
        unknownunknownfalse
        75.179.52.87
        unknownUnited States
        10796TWC-10796-MIDWESTUSfalse
        27.167.147.1
        unknownKorea Republic of
        9644SKTELECOM-NET-ASSKTelecomKRfalse
        No context
        No context
        No context
        No context
        No context
        Process:/usr/bin/wget
        File Type:ASCII text
        Category:dropped
        Size (bytes):191
        Entropy (8bit):4.515771857099866
        Encrypted:false
        SSDEEP:3:P2lnI+5MsqqzNLz+FRNScHUBfRau95++sZzR5woLB1Fh0VTGTl/X5kURn:OZ8uNLzDc0pR75+9Zz/woFmIT52URn
        MD5:DD514F892B5F93ED615D366E58AC58AF
        SHA1:BA75EDB3C2232CC260BC187F604DC8F25AA72C11
        SHA-256:F40D0DCE6E83DF74109FEF5E68E51CC255727783EEAE04C3E34677E23F7552CF
        SHA-512:9150BDE63F6C4850C5340D8877892B4D9BBF9EBDC98CDCF557A93FA304C1222CEE446418F5BE2ACCDBF38393778AFA5D4F3EDCB37A47BF57D3A4B2DEAD42A2D0
        Malicious:false
        Reputation:high, very likely benign file
        Preview: * Super-optimized for small spaces - read how we shrank the memory. footprint of MicroK8s to make it the smallest full K8s around... https://ubuntu.com/blog/microk8s-memory-optimisation.
        Process:/usr/bin/wget
        File Type:UTF-8 Unicode text
        Category:dropped
        Size (bytes):494
        Entropy (8bit):4.945181413004465
        Encrypted:false
        SSDEEP:6:HXB9GAYLEHKLG13/3xg7F/uZCHKLGZgM/Tt5RhgZDl7jzisnfJvXWG9iFua4kpa5:HRoTL6OM48QTt5Rh0isBPWGwzG
        MD5:F54FF0712E841F4F0A7B21018B9136AD
        SHA1:98301ABDDC6A7D664DFAA52EEB06152D2312D28E
        SHA-256:228178873A4D4AF072E3717F1C6B5DD018547BAA520D14E327BC0FC027126A06
        SHA-512:0BB6A6782E2C6BA02B214F9724B5FDE064C3D655F227F2F88AA6FA2491E684E54372D48B6F90077A0B822D6CED0969E9C3B50CC79AF0E8471E84FE81E6C9AA07
        Malicious:false
        Reputation:low
        Preview:--2022-08-05 13:55:49-- https://motd.ubuntu.com/.Resolving motd.ubuntu.com (motd.ubuntu.com)... 54.171.230.55, 34.249.145.219, 2a05:d018:91c:3200:2846:99fb:81b6:1e11, ....Connecting to motd.ubuntu.com (motd.ubuntu.com)|54.171.230.55|:443... connected..HTTP request sent, awaiting response... 200 OK.Length: 191 [text/plain].Saving to: .STDOUT... 0K 100% 62.9K=0.003s..2022-08-05 13:55:50 (62.9 KB/s) - written to stdout [191/191]..
        Process:/usr/bin/cloud-id
        File Type:ASCII text
        Category:dropped
        Size (bytes):5
        Entropy (8bit):1.9219280948873623
        Encrypted:false
        SSDEEP:3:x:x
        MD5:7E5B152FCF63F8DAB71A695D1DBE01FA
        SHA1:02135FF9133DB03A40AAFF586BB173E6A7A6998F
        SHA-256:FCF33DFBE13C2354BF0E1B063F9FB422747A46CEE00B7420BCEFF2B81457B345
        SHA-512:92E89A3C69C643FBB194686598193C219C1A11F07DD36F3883D63AAA867077691F193F8E89F31AE3754EA0E860E2910A3F9247927C93C0B977009FD860F812DA
        Malicious:false
        Reputation:moderate, very likely benign file
        Preview:none.
        Process:/usr/bin/cut
        File Type:ASCII text
        Category:dropped
        Size (bytes):191
        Entropy (8bit):4.515771857099866
        Encrypted:false
        SSDEEP:3:P2lnI+5MsqqzNLz+FRNScHUBfRau95++sZzR5woLB1Fh0VTGTl/X5kURn:OZ8uNLzDc0pR75+9Zz/woFmIT52URn
        MD5:DD514F892B5F93ED615D366E58AC58AF
        SHA1:BA75EDB3C2232CC260BC187F604DC8F25AA72C11
        SHA-256:F40D0DCE6E83DF74109FEF5E68E51CC255727783EEAE04C3E34677E23F7552CF
        SHA-512:9150BDE63F6C4850C5340D8877892B4D9BBF9EBDC98CDCF557A93FA304C1222CEE446418F5BE2ACCDBF38393778AFA5D4F3EDCB37A47BF57D3A4B2DEAD42A2D0
        Malicious:false
        Reputation:high, very likely benign file
        Preview: * Super-optimized for small spaces - read how we shrank the memory. footprint of MicroK8s to make it the smallest full K8s around... https://ubuntu.com/blog/microk8s-memory-optimisation.
        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
        Entropy (8bit):5.802220381620875
        TrID:
        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
        File name:VefqQeU0Xt
        File size:37884
        MD5:b8ec31b1eff948abc9e797eb796d10cb
        SHA1:5590da71a98232aa873143780f4f9e36e1a8359a
        SHA256:f67ac47d33f3681cd957585c4338c43e939eb5fc0d8da4ac84aa33ccf52fcb1e
        SHA512:43662da6d6b544a3e34409b1e52f0147a4f74a27e3592d057f3913e888001ba1c8e8f2322ccd87eab2a56ff7d5926431d603b9be1807f68133b5a03ef8b43b0c
        SSDEEP:768:ZUcgPbzj5HoD2ogElo5fEFUsduP5KZ7m8LIZkk:Gcg8oDfYduxy7x
        TLSH:E903E784B9869A07CAD4537BFA1E42DD3B2573C8F2CE3313DE162F51368A92B0D6B145
        File Content Preview:.ELF...a..........(.........4...l.......4. ...(.....................................................,...............Q.td..................................-...L.".... ..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:ARM
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:ARM - ABI
        ABI Version:0
        Entry Point Address:0x8190
        Flags:0x2
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:3
        Section Header Offset:37484
        Section Header Size:40
        Number of Section Headers:10
        Header String Table Index:9
        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .initPROGBITS0x80940x940x180x00x6AX004
        .textPROGBITS0x80b00xb00x83900x00x6AX0016
        .finiPROGBITS0x104400x84400x140x00x6AX004
        .rodataPROGBITS0x104540x84540x7700x00x2A004
        .ctorsPROGBITS0x190000x90000x80x00x3WA004
        .dtorsPROGBITS0x190080x90080x80x00x3WA004
        .dataPROGBITS0x190140x90140x2180x00x3WA004
        .bssNOBITS0x1922c0x922c0x2d00x00x3WA004
        .shstrtabSTRTAB0x00x922c0x3e0x00x0001
        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x80000x80000x8bc40x8bc45.93770x5R E0x8000.init .text .fini .rodata
        LOAD0x90000x190000x190000x22c0x4fc2.93600x6RW 0x8000.ctors .dtors .data .bss
        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
        TimestampSource PortDest PortSource IPDest IP
        Aug 5, 2022 13:55:50.582647085 CEST42836443192.168.2.2391.189.91.43
        Aug 5, 2022 13:55:51.094340086 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.094418049 CEST4433361654.171.230.55192.168.2.23
        Aug 5, 2022 13:55:51.094507933 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.099719048 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.099771023 CEST4433361654.171.230.55192.168.2.23
        Aug 5, 2022 13:55:51.258222103 CEST4433361654.171.230.55192.168.2.23
        Aug 5, 2022 13:55:51.258311987 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.260899067 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.260920048 CEST4433361654.171.230.55192.168.2.23
        Aug 5, 2022 13:55:51.262674093 CEST4433361654.171.230.55192.168.2.23
        Aug 5, 2022 13:55:51.262762070 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.311269045 CEST381845556192.168.2.2331.7.58.162
        Aug 5, 2022 13:55:51.331625938 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.331691980 CEST55563818431.7.58.162192.168.2.23
        Aug 5, 2022 13:55:51.332030058 CEST4433361654.171.230.55192.168.2.23
        Aug 5, 2022 13:55:51.332083941 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.332106113 CEST4433361654.171.230.55192.168.2.23
        Aug 5, 2022 13:55:51.332143068 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.332823992 CEST33616443192.168.2.2354.171.230.55
        Aug 5, 2022 13:55:51.333270073 CEST2712723192.168.2.2392.240.212.111
        Aug 5, 2022 13:55:51.333276987 CEST271272323192.168.2.23191.30.223.111
        Aug 5, 2022 13:55:51.333290100 CEST2712723192.168.2.23192.59.80.156
        Aug 5, 2022 13:55:51.333292007 CEST2712723192.168.2.2347.184.111.104
        Aug 5, 2022 13:55:51.333316088 CEST2712723192.168.2.23191.102.53.236
        Aug 5, 2022 13:55:51.333318949 CEST2712723192.168.2.23220.216.99.136
        Aug 5, 2022 13:55:51.333323002 CEST2712723192.168.2.23215.99.232.174
        Aug 5, 2022 13:55:51.333323956 CEST2712723192.168.2.2397.141.194.17
        Aug 5, 2022 13:55:51.333328962 CEST2712723192.168.2.2326.238.62.70
        Aug 5, 2022 13:55:51.333338022 CEST2712723192.168.2.23194.213.28.114
        Aug 5, 2022 13:55:51.333339930 CEST271272323192.168.2.23100.149.208.9
        Aug 5, 2022 13:55:51.333448887 CEST2712723192.168.2.2378.55.226.3
        Aug 5, 2022 13:55:51.333494902 CEST2712723192.168.2.23118.134.191.213
        Aug 5, 2022 13:55:51.333506107 CEST2712723192.168.2.23111.69.31.143
        Aug 5, 2022 13:55:51.333509922 CEST2712723192.168.2.23174.29.179.151
        Aug 5, 2022 13:55:51.333512068 CEST2712723192.168.2.23140.127.145.26
        Aug 5, 2022 13:55:51.333514929 CEST2712723192.168.2.2349.4.192.238
        Aug 5, 2022 13:55:51.333517075 CEST2712723192.168.2.2389.135.24.152
        Aug 5, 2022 13:55:51.333519936 CEST2712723192.168.2.2363.182.68.30
        Aug 5, 2022 13:55:51.333533049 CEST271272323192.168.2.2337.123.5.229
        Aug 5, 2022 13:55:51.333539963 CEST2712723192.168.2.2322.47.147.217
        Aug 5, 2022 13:55:51.333545923 CEST2712723192.168.2.2376.20.22.151
        Aug 5, 2022 13:55:51.333558083 CEST2712723192.168.2.23221.79.225.118
        Aug 5, 2022 13:55:51.333564997 CEST2712723192.168.2.23183.143.197.44
        Aug 5, 2022 13:55:51.333566904 CEST2712723192.168.2.2377.23.199.142
        Aug 5, 2022 13:55:51.333576918 CEST2712723192.168.2.23104.46.191.149
        Aug 5, 2022 13:55:51.333583117 CEST2712723192.168.2.23113.208.229.47
        Aug 5, 2022 13:55:51.333586931 CEST271272323192.168.2.23161.65.22.168
        Aug 5, 2022 13:55:51.333594084 CEST2712723192.168.2.23159.106.12.96
        Aug 5, 2022 13:55:51.333595991 CEST2712723192.168.2.23144.114.107.235
        Aug 5, 2022 13:55:51.333606005 CEST2712723192.168.2.2393.116.19.127
        Aug 5, 2022 13:55:51.333616018 CEST2712723192.168.2.23189.176.215.111
        Aug 5, 2022 13:55:51.333619118 CEST2712723192.168.2.23203.66.11.88
        Aug 5, 2022 13:55:51.333625078 CEST2712723192.168.2.23199.38.203.72
        Aug 5, 2022 13:55:51.333638906 CEST2712723192.168.2.23186.98.116.215
        Aug 5, 2022 13:55:51.333646059 CEST2712723192.168.2.231.78.235.5
        Aug 5, 2022 13:55:51.333657026 CEST271272323192.168.2.23216.169.15.177
        Aug 5, 2022 13:55:51.333662987 CEST2712723192.168.2.233.123.192.200
        Aug 5, 2022 13:55:51.333662987 CEST2712723192.168.2.2351.54.77.199
        Aug 5, 2022 13:55:51.333667994 CEST2712723192.168.2.23248.162.82.18
        Aug 5, 2022 13:55:51.333674908 CEST2712723192.168.2.2363.75.125.139
        Aug 5, 2022 13:55:51.333677053 CEST2712723192.168.2.23120.58.206.46
        Aug 5, 2022 13:55:51.333683014 CEST2712723192.168.2.23124.216.192.219
        Aug 5, 2022 13:55:51.333690882 CEST2712723192.168.2.233.245.22.5
        Aug 5, 2022 13:55:51.333692074 CEST2712723192.168.2.23219.122.164.77
        Aug 5, 2022 13:55:51.333698034 CEST2712723192.168.2.23113.54.142.72
        Aug 5, 2022 13:55:51.333707094 CEST2712723192.168.2.2359.49.126.100
        Aug 5, 2022 13:55:51.333710909 CEST271272323192.168.2.2358.18.79.236
        Aug 5, 2022 13:55:51.333755016 CEST2712723192.168.2.23240.114.176.164
        Aug 5, 2022 13:55:51.333760023 CEST2712723192.168.2.23172.11.221.132
        Aug 5, 2022 13:55:51.333765030 CEST2712723192.168.2.23102.11.135.241
        Aug 5, 2022 13:55:51.333770990 CEST2712723192.168.2.23174.0.173.208
        Aug 5, 2022 13:55:51.333774090 CEST2712723192.168.2.2317.25.73.177
        Aug 5, 2022 13:55:51.333759069 CEST2712723192.168.2.2317.97.8.33
        Aug 5, 2022 13:55:51.333791971 CEST271272323192.168.2.2395.153.125.220
        Aug 5, 2022 13:55:51.333791971 CEST2712723192.168.2.23184.133.76.186
        Aug 5, 2022 13:55:51.333802938 CEST2712723192.168.2.23176.33.151.226
        Aug 5, 2022 13:55:51.333806992 CEST2712723192.168.2.23168.237.119.219
        Aug 5, 2022 13:55:51.333817959 CEST2712723192.168.2.23187.165.244.252
        Aug 5, 2022 13:55:51.333827972 CEST2712723192.168.2.23253.244.108.96
        Aug 5, 2022 13:55:51.333832026 CEST2712723192.168.2.23104.150.203.160
        Aug 5, 2022 13:55:51.333837986 CEST2712723192.168.2.23168.24.10.49
        Aug 5, 2022 13:55:51.333842039 CEST2712723192.168.2.23148.144.9.109
        Aug 5, 2022 13:55:51.333854914 CEST2712723192.168.2.23101.190.39.242
        Aug 5, 2022 13:55:51.333864927 CEST271272323192.168.2.2358.93.74.180
        Aug 5, 2022 13:55:51.333868980 CEST2712723192.168.2.23176.2.87.161
        Aug 5, 2022 13:55:51.333872080 CEST2712723192.168.2.2379.226.207.240
        Aug 5, 2022 13:55:51.333878994 CEST2712723192.168.2.23171.133.177.159
        Aug 5, 2022 13:55:51.333884954 CEST2712723192.168.2.23249.185.238.120
        Aug 5, 2022 13:55:51.333889961 CEST2712723192.168.2.23114.226.197.88
        Aug 5, 2022 13:55:51.333911896 CEST2712723192.168.2.2317.10.229.138
        Aug 5, 2022 13:55:51.333913088 CEST2712723192.168.2.23218.63.140.227
        Aug 5, 2022 13:55:51.333919048 CEST2712723192.168.2.23139.163.138.153
        Aug 5, 2022 13:55:51.333929062 CEST2712723192.168.2.23253.69.47.6
        Aug 5, 2022 13:55:51.333933115 CEST2712723192.168.2.2319.217.67.151
        Aug 5, 2022 13:55:51.333935976 CEST2712723192.168.2.23215.255.164.29
        Aug 5, 2022 13:55:51.333944082 CEST271272323192.168.2.23216.144.63.27
        Aug 5, 2022 13:55:51.333946943 CEST2712723192.168.2.2343.123.192.4
        Aug 5, 2022 13:55:51.333947897 CEST2712723192.168.2.2336.100.40.157
        Aug 5, 2022 13:55:51.333960056 CEST2712723192.168.2.2345.76.216.183

        System Behavior

        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/lib/systemd/systemd
        Arguments:n/a
        File size:1620224 bytes
        MD5 hash:9b2bec7092a40488108543f9334aab75
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:/etc/update-motd.d/50-motd-news --force
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/mktemp
        Arguments:mktemp
        File size:47448 bytes
        MD5 hash:e117ed1c2172d436fa31cc9d263131e8
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/mktemp
        Arguments:mktemp
        File size:47448 bytes
        MD5 hash:e117ed1c2172d436fa31cc9d263131e8
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/mktemp
        Arguments:mktemp
        File size:47448 bytes
        MD5 hash:e117ed1c2172d436fa31cc9d263131e8
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/dpkg
        Arguments:dpkg -l wget
        File size:309944 bytes
        MD5 hash:5e18156b434fc45062eec2f28b9147be
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/dpkg-query
        Arguments:dpkg-query --list -- wget
        File size:166488 bytes
        MD5 hash:bf81745ea62201f11bc674cc7c1935fc
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/awk
        Arguments:awk "$1 == \"ii\" { print($3); exit(0); }"
        File size:711136 bytes
        MD5 hash:7e9b2ed1272331cfbd2aac2e5eb3f84b
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/sed
        Arguments:sed -e "s/ /\\//g"
        File size:121288 bytes
        MD5 hash:885062561f66aa1d4af4c54b9e7cc81a
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/uname
        Arguments:uname -o
        File size:39288 bytes
        MD5 hash:4ac7c634c5bec95753c480e9d421dcc2
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/uname
        Arguments:uname -r
        File size:39288 bytes
        MD5 hash:4ac7c634c5bec95753c480e9d421dcc2
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/uname
        Arguments:uname -m
        File size:39288 bytes
        MD5 hash:4ac7c634c5bec95753c480e9d421dcc2
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/uname
        Arguments:uname -m
        File size:39288 bytes
        MD5 hash:4ac7c634c5bec95753c480e9d421dcc2
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/grep
        Arguments:grep -m1 "^model name" /proc/cpuinfo
        File size:199136 bytes
        MD5 hash:1e6ebb9dd094f774478f72727bdba0f5
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/sed
        Arguments:sed -e "s/.*: //" -e s:\\s\\+:/:g
        File size:121288 bytes
        MD5 hash:885062561f66aa1d4af4c54b9e7cc81a
        Start time:13:55:43
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:43
        Start date:05/08/2022
        Path:/usr/bin/cloud-id
        Arguments:/usr/bin/cloud-id
        File size:5490352 bytes
        MD5 hash:69f442c3e33b5f9a66b722c29ad89435
        Start time:13:55:48
        Start date:05/08/2022
        Path:/usr/bin/cloud-id
        Arguments:n/a
        File size:5490352 bytes
        MD5 hash:69f442c3e33b5f9a66b722c29ad89435
        Start time:13:55:48
        Start date:05/08/2022
        Path:/usr/bin/uname
        Arguments:uname -p
        File size:39288 bytes
        MD5 hash:4ac7c634c5bec95753c480e9d421dcc2
        Start time:13:55:49
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:49
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:49
        Start date:05/08/2022
        Path:/usr/bin/cut
        Arguments:cut -c -40 /tmp/tmp.ZtXsY8H9DY
        File size:47480 bytes
        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3
        Start time:13:55:49
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:49
        Start date:05/08/2022
        Path:/usr/bin/tr
        Arguments:tr -c -d [:alnum:]
        File size:51544 bytes
        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5
        Start time:13:55:49
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:49
        Start date:05/08/2022
        Path:/usr/bin/wget
        Arguments:wget --timeout 60 -U "wget/1.20.3-1ubuntu1 Ubuntu/20.04.2/LTS GNU/Linux/5.4.0-72-generic/x86_64 Intel(R)/Xeon(R)/Silver/4210/CPU/@/2.20GHz cloud_id/none" -O- --content-on-error https://motd.ubuntu.com
        File size:548568 bytes
        MD5 hash:996940118df7bb2aaa718589d4e95c08
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/cat
        Arguments:cat /tmp/tmp.EQLgjCNBFD
        File size:43416 bytes
        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/head
        Arguments:head -n 10
        File size:47480 bytes
        MD5 hash:fd96a67145172477dd57131396fc9608
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/tr
        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
        File size:51544 bytes
        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/cut
        Arguments:cut -c -80
        File size:47480 bytes
        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/cat
        Arguments:cat /tmp/tmp.EQLgjCNBFD
        File size:43416 bytes
        MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/head
        Arguments:head -n 10
        File size:47480 bytes
        MD5 hash:fd96a67145172477dd57131396fc9608
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/tr
        Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
        File size:51544 bytes
        MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/cut
        Arguments:cut -c -80
        File size:47480 bytes
        MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3
        Start time:13:55:50
        Start date:05/08/2022
        Path:/etc/update-motd.d/50-motd-news
        Arguments:n/a
        File size:129816 bytes
        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
        Start time:13:55:50
        Start date:05/08/2022
        Path:/usr/bin/rm
        Arguments:rm -f /tmp/tmp.EQLgjCNBFD /tmp/tmp.ONisxp5pqw /tmp/tmp.ZtXsY8H9DY
        File size:72056 bytes
        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b
        Start time:13:55:49
        Start date:05/08/2022
        Path:/tmp/VefqQeU0Xt
        Arguments:/tmp/VefqQeU0Xt
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
        Start time:13:55:49
        Start date:05/08/2022
        Path:/tmp/VefqQeU0Xt
        Arguments:n/a
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1
        Start time:13:55:49
        Start date:05/08/2022
        Path:/tmp/VefqQeU0Xt
        Arguments:n/a
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1