Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Smqw34mNlm

Overview

General Information

Sample Name:Smqw34mNlm
Analysis ID:679269
MD5:280c087a0073bd36784e8af0b7254670
SHA1:0c650be334cc8f692102e27d4a0e9ae3d97afd71
SHA256:8b5fc53ad49b0005798e9fdd8a9738d798755ee6070b08d1fff41c848200548a
Tags:64elfmirai
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Yara detected Mirai
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Yara signature match
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:35.0.0 Citrine
Analysis ID:679269
Start date and time: 05/08/202214:02:572022-08-05 14:02:57 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 56s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:Smqw34mNlm
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal76.troj.lin@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/Smqw34mNlm
PID:6223
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
your device just got infected to a bootnoot
Standard Error:
  • system is lnxubuntu20
  • Smqw34mNlm (PID: 6223, Parent: 6122, MD5: 280c087a0073bd36784e8af0b7254670) Arguments: /tmp/Smqw34mNlm
  • cleanup
SourceRuleDescriptionAuthorStrings
Smqw34mNlmLinux_Trojan_Gafgyt_9e9530a7unknownunknown
  • 0x5634:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
Smqw34mNlmLinux_Trojan_Gafgyt_807911a2unknownunknown
  • 0x5e23:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
Smqw34mNlmLinux_Trojan_Gafgyt_d4227dbfunknownunknown
  • 0x4d2e:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
  • 0x4e64:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
Smqw34mNlmLinux_Trojan_Gafgyt_620087b9unknownunknown
  • 0x59e3:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
Smqw34mNlmLinux_Trojan_Gafgyt_0cd591cdunknownunknown
  • 0x5272:$a: 4E F8 48 8D 4E D8 49 8D 42 E0 48 83 C7 03 EB 6B 4C 8B 46 F8 48 8D
Click to see the 3 entries
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    6223.1.0000000000400000.0000000000409000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
    • 0x5634:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
    6223.1.0000000000400000.0000000000409000.r-x.sdmpLinux_Trojan_Gafgyt_807911a2unknownunknown
    • 0x5e23:$a: FE 48 39 F3 0F 94 C2 48 83 F9 FF 0F 94 C0 84 D0 74 16 4B 8D
    6223.1.0000000000400000.0000000000409000.r-x.sdmpLinux_Trojan_Gafgyt_d4227dbfunknownunknown
    • 0x4d2e:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    • 0x4e64:$a: FF 48 81 EC D0 00 00 00 48 8D 84 24 E0 00 00 00 48 89 54 24 30 C7 04 24 18 00
    6223.1.0000000000400000.0000000000409000.r-x.sdmpLinux_Trojan_Gafgyt_620087b9unknownunknown
    • 0x59e3:$a: 48 89 D8 48 83 C8 01 EB 04 48 8B 76 10 48 3B 46 08 72 F6 48 8B
    6223.1.0000000000400000.0000000000409000.r-x.sdmpLinux_Trojan_Gafgyt_0cd591cdunknownunknown
    • 0x5272:$a: 4E F8 48 8D 4E D8 49 8D 42 E0 48 83 C7 03 EB 6B 4C 8B 46 F8 48 8D
    Click to see the 3 entries
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: Smqw34mNlmAvira: detected
    Source: Smqw34mNlmVirustotal: Detection: 38%Perma Link
    Source: Smqw34mNlmReversingLabs: Detection: 76%
    Source: Smqw34mNlmJoe Sandbox ML: detected
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:38182 -> 31.7.58.162:5556
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 7.168.141.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 118.131.166.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 193.254.59.44:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 248.20.109.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 70.27.243.152:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 187.200.25.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 194.131.0.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 57.2.199.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 58.88.193.35:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 164.7.174.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 189.54.119.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 50.84.124.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 11.224.41.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 175.22.111.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 59.30.152.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 188.168.248.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 241.151.153.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 59.87.20.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 121.56.162.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 22.121.3.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 31.21.36.64:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 199.1.233.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 50.158.183.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 96.143.115.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 95.102.235.252:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 102.22.197.35:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 105.65.190.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 71.110.80.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 99.9.131.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 47.161.214.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 84.159.157.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 240.154.84.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 31.161.218.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 32.148.104.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 31.83.17.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 62.60.104.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 55.146.80.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 82.68.138.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 83.33.27.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 44.139.115.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 207.82.220.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 40.12.224.28:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 89.168.8.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 165.131.140.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 47.80.226.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 136.67.198.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 26.46.66.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 107.81.128.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 26.183.201.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 174.202.244.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 151.6.109.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 134.56.184.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 223.183.168.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 76.124.136.38:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 2.93.1.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 79.122.84.93:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 255.140.150.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 34.154.100.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 23.182.236.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 104.78.21.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 83.29.88.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 64.130.192.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 113.39.49.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 251.19.187.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 54.169.138.72:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 75.177.109.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 178.160.97.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 94.109.98.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 120.64.16.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 142.195.133.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 97.200.49.243:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 107.25.123.73:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 15.6.95.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 61.241.246.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 64.33.221.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 77.39.251.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 187.231.158.146:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 178.35.25.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 53.108.221.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 242.49.206.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 104.136.73.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 116.3.116.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 177.26.9.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 96.0.53.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 65.248.211.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 190.223.148.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 252.211.223.125:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 41.98.34.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 42.175.83.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 6.167.91.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 206.15.222.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 138.191.5.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 17.221.201.156:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 54.201.69.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 81.109.125.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 126.197.60.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 97.179.155.251:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 177.9.172.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 160.14.199.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 81.105.134.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 121.130.122.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 110.162.132.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 178.250.101.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 71.51.138.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 214.45.255.28:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 20.40.24.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 156.101.194.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 44.7.66.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 144.143.250.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 206.59.237.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 201.158.216.126:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 248.232.119.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 186.110.79.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 133.150.202.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 85.144.8.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 48.20.167.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 107.170.134.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 222.25.94.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 42.160.111.53:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 95.237.102.206:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 252.143.205.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 21.67.9.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 169.181.128.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 60.26.228.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 6.224.23.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 23.63.241.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 95.185.63.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 189.97.85.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 16.20.113.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 207.49.189.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 60.154.128.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 23.226.14.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 173.85.177.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 140.129.11.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 160.80.201.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 111.105.210.83:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 114.132.27.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 18.100.105.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 170.82.71.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 244.252.173.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 179.29.36.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 74.55.92.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 176.138.133.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 90.146.93.137:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 110.173.177.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 242.227.159.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 176.224.171.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 43.4.114.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 210.151.160.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 133.227.163.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 17.236.74.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 181.62.248.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 87.72.206.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 8.123.122.28:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 26.50.189.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 206.103.247.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 250.153.83.46:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 245.5.170.152:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 20.203.170.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 121.203.7.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 251.73.232.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 153.0.106.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 99.237.215.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 59.70.81.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 49.142.188.146:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 186.216.29.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 98.45.118.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 115.102.255.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 244.226.10.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 45.8.10.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 208.110.150.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 35.27.15.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 66.220.112.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 141.138.86.75:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 179.99.153.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 102.146.113.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 178.167.239.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 147.96.70.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 29.130.23.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 26.2.238.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 250.25.4.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 250.0.174.82:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 85.15.27.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 117.89.207.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 143.169.244.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 243.103.146.64:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 157.209.230.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 19.129.103.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 248.12.131.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 23.83.48.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 185.120.253.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 191.110.156.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 207.14.218.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 153.30.173.233:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 63.9.251.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 46.65.93.248:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 169.231.246.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 47.176.15.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 18.70.96.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 249.207.100.224:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 126.183.96.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 82.76.113.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 207.107.15.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 195.37.109.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 216.101.144.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 30.185.153.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 161.138.172.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 28.30.110.53:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 78.101.248.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 136.172.83.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 188.186.176.252:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 41.221.113.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 194.140.186.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 74.94.35.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 40.181.146.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 55.131.246.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 178.184.156.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 189.0.204.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 45.63.121.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 35.171.94.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 45.238.29.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 11.209.140.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 73.69.50.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 9.77.132.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 99.47.63.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 35.190.115.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 129.67.217.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 126.80.119.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 142.213.116.13:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 204.166.117.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 143.25.8.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 180.49.7.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 68.252.102.75:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 148.97.237.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 209.187.16.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 177.80.241.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 187.183.96.155:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 59.127.217.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 103.171.189.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 37.174.28.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 39.9.55.96:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 200.201.156.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 198.176.80.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 18.188.246.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 57.139.230.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 126.123.2.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 208.82.152.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 240.61.238.83:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 110.50.34.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 63.154.68.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 244.162.66.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 122.47.177.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 221.166.28.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 250.235.175.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 193.51.33.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 202.109.153.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 77.103.184.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 131.41.111.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 58.4.2.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 178.46.169.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 248.1.187.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 219.11.123.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 94.159.238.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 247.47.49.56:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 203.255.223.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 62.248.159.73:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 25.150.180.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 99.100.95.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 62.151.211.170:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 85.144.163.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 97.86.213.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 64.170.251.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 73.229.200.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 220.205.52.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 124.85.49.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 149.84.183.120:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 148.63.130.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 108.69.35.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 108.132.59.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 110.139.184.47:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 36.176.220.118:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 178.230.72.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 179.163.65.96:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 254.19.231.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 14.225.104.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 184.185.47.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 47.17.155.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 138.220.23.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 95.6.33.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 201.192.212.251:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 87.197.192.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 92.113.179.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 47.57.12.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 93.236.25.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 106.195.194.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 105.154.26.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 144.107.87.173:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 181.254.176.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 245.38.139.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 145.171.31.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 151.226.124.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 99.172.197.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 79.117.19.115:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 59.185.158.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 142.82.129.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 200.113.91.195:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 56.15.80.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 102.17.252.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 191.148.165.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 110.234.116.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 8.189.175.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 153.165.210.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 57.183.189.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 189.199.236.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 175.38.210.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 22.133.58.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 185.242.140.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 51.21.230.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 38.28.246.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 41.144.245.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 46.128.158.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 21.150.123.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 94.143.128.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 74.243.109.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 88.85.242.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 107.152.151.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 135.98.242.83:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 25.161.156.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 175.242.11.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 79.199.10.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 90.167.127.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 149.99.126.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 185.1.203.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 215.188.93.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 79.231.183.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 66.47.169.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 31.62.90.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 196.61.156.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 254.168.32.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 213.141.164.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 38.129.174.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 5.20.95.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 69.124.219.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 46.228.175.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 14.104.117.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 120.244.192.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 179.217.118.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 104.244.131.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 135.16.123.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 143.205.3.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 76.171.37.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 199.81.180.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 203.101.75.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 15.143.74.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 164.154.43.213:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 254.244.184.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 55.89.79.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 240.111.177.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 49.125.159.152:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 146.17.74.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 221.235.198.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 213.159.19.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 54.114.178.252:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 248.147.9.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 20.42.212.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 24.102.176.228:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 103.120.59.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 198.246.8.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 31.122.244.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 215.5.49.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 210.244.221.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 1.86.232.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 46.89.85.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 197.204.127.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 212.93.189.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 212.59.173.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 165.100.236.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 67.211.83.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 150.202.176.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 186.228.187.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 168.104.173.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 92.121.128.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 145.220.239.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 14.111.170.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 149.192.107.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 215.249.61.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 13.31.182.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 210.114.120.224:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 104.142.165.231:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 128.81.115.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 55.248.165.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 14.95.80.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 54.213.52.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 51.117.182.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 123.238.65.75:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 252.177.208.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 66.222.20.198:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 28.100.98.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 17.111.114.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 180.201.249.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 181.10.18.126:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 69.39.37.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 66.35.255.10:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 46.62.21.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 207.149.126.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 158.102.203.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 88.109.0.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 150.167.145.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 35.180.38.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 85.214.251.10:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 128.238.135.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 39.14.181.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 15.33.89.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 91.238.252.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 207.6.122.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 118.105.82.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 209.202.107.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 193.135.33.66:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 136.105.100.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 249.227.0.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 155.12.185.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 77.6.5.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 103.254.190.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 215.209.242.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 23.31.139.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 80.171.240.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 157.32.153.148:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 70.29.97.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 75.33.50.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 87.16.160.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 216.219.172.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 17.142.99.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 190.143.201.83:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 100.66.122.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 255.11.25.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 164.4.53.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 160.123.210.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 153.109.32.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 24.168.73.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 134.85.81.203:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 120.69.147.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 155.68.58.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 101.124.180.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 206.225.203.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 212.196.251.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 119.88.204.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 184.175.250.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 16.165.215.210:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 95.30.86.206:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 194.227.63.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 202.46.56.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 49.20.209.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 35.168.120.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 155.115.246.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 45.66.211.120:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 106.89.172.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 240.229.120.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 17.33.166.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 61.66.122.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 163.190.71.203:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 147.62.196.47:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 15.46.7.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 15.62.165.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 193.88.104.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 133.36.206.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 103.26.91.35:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 31.70.239.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 129.147.249.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 61.31.130.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 114.51.180.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 164.168.213.195:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 196.246.56.125:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 121.17.190.115:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 16.22.227.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 91.19.137.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 66.176.110.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 253.249.214.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 183.81.72.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 2.112.94.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 163.0.187.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 7.113.48.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 45.90.151.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 69.93.94.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 11.150.101.25:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 144.5.162.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 189.93.232.56:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 129.178.251.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 89.43.95.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 136.12.243.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 241.223.231.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 246.96.128.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 143.181.158.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 147.49.223.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 50.200.213.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 55.249.17.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 145.2.70.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 243.162.2.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 147.150.92.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:58671 -> 139.70.39.201:2323
    Source: /tmp/Smqw34mNlm (PID: 6223)Socket: 127.0.0.1::4668
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 31.7.58.162
    Source: unknownTCP traffic detected without corresponding DNS query: 7.168.141.249
    Source: unknownTCP traffic detected without corresponding DNS query: 198.68.134.249
    Source: unknownTCP traffic detected without corresponding DNS query: 122.114.166.159
    Source: unknownTCP traffic detected without corresponding DNS query: 211.177.36.167
    Source: unknownTCP traffic detected without corresponding DNS query: 104.13.196.249
    Source: unknownTCP traffic detected without corresponding DNS query: 93.174.77.50
    Source: unknownTCP traffic detected without corresponding DNS query: 80.112.1.82
    Source: unknownTCP traffic detected without corresponding DNS query: 172.128.194.250
    Source: unknownTCP traffic detected without corresponding DNS query: 205.21.227.60
    Source: unknownTCP traffic detected without corresponding DNS query: 245.105.85.166
    Source: unknownTCP traffic detected without corresponding DNS query: 172.4.56.65
    Source: unknownTCP traffic detected without corresponding DNS query: 100.144.78.230
    Source: unknownTCP traffic detected without corresponding DNS query: 218.158.107.199
    Source: unknownTCP traffic detected without corresponding DNS query: 107.106.118.92
    Source: unknownTCP traffic detected without corresponding DNS query: 54.53.148.170
    Source: unknownTCP traffic detected without corresponding DNS query: 243.217.160.184
    Source: unknownTCP traffic detected without corresponding DNS query: 118.131.166.21
    Source: unknownTCP traffic detected without corresponding DNS query: 200.69.77.152
    Source: unknownTCP traffic detected without corresponding DNS query: 170.163.179.38
    Source: unknownTCP traffic detected without corresponding DNS query: 198.149.212.106
    Source: unknownTCP traffic detected without corresponding DNS query: 100.9.154.2
    Source: unknownTCP traffic detected without corresponding DNS query: 33.45.97.93
    Source: unknownTCP traffic detected without corresponding DNS query: 2.125.220.123
    Source: unknownTCP traffic detected without corresponding DNS query: 152.3.107.53
    Source: unknownTCP traffic detected without corresponding DNS query: 193.254.59.44
    Source: unknownTCP traffic detected without corresponding DNS query: 248.20.109.37
    Source: unknownTCP traffic detected without corresponding DNS query: 184.159.52.183
    Source: unknownTCP traffic detected without corresponding DNS query: 218.78.127.85
    Source: unknownTCP traffic detected without corresponding DNS query: 95.42.62.18
    Source: unknownTCP traffic detected without corresponding DNS query: 167.95.143.87
    Source: unknownTCP traffic detected without corresponding DNS query: 245.253.223.223
    Source: unknownTCP traffic detected without corresponding DNS query: 75.56.163.140
    Source: unknownTCP traffic detected without corresponding DNS query: 167.195.211.111
    Source: unknownTCP traffic detected without corresponding DNS query: 101.92.139.72
    Source: unknownTCP traffic detected without corresponding DNS query: 206.98.193.173
    Source: unknownTCP traffic detected without corresponding DNS query: 143.222.240.47
    Source: unknownTCP traffic detected without corresponding DNS query: 222.42.166.140
    Source: unknownTCP traffic detected without corresponding DNS query: 39.39.199.249
    Source: unknownTCP traffic detected without corresponding DNS query: 70.27.243.152
    Source: unknownTCP traffic detected without corresponding DNS query: 247.253.250.130
    Source: unknownTCP traffic detected without corresponding DNS query: 7.101.126.217
    Source: unknownTCP traffic detected without corresponding DNS query: 180.66.202.69
    Source: unknownTCP traffic detected without corresponding DNS query: 157.131.86.241
    Source: unknownTCP traffic detected without corresponding DNS query: 248.163.253.145
    Source: unknownTCP traffic detected without corresponding DNS query: 11.24.219.118
    Source: unknownTCP traffic detected without corresponding DNS query: 14.137.86.116
    Source: unknownTCP traffic detected without corresponding DNS query: 187.200.25.201
    Source: unknownTCP traffic detected without corresponding DNS query: 124.242.166.66
    Source: unknownTCP traffic detected without corresponding DNS query: 34.38.61.171

    System Summary

    barindex
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1cb033f3 Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1cb033f3 Author: unknown
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
    Source: Smqw34mNlm, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1cb033f3 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358, id = 1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
    Source: 6223.1.0000000000400000.0000000000409000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1cb033f3 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358, id = 1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e, last_modified = 2021-09-16
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal76.troj.lin@0/0@0/0

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: dump.pcap, type: PCAP
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    Smqw34mNlm38%VirustotalBrowse
    Smqw34mNlm77%ReversingLabsLinux.Trojan.Mirai
    Smqw34mNlm100%AviraLINUX/Mirai.zxjge
    Smqw34mNlm100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    130.41.108.217
    unknownUnited States
    243HARRIS-ATD-ASUSfalse
    105.170.217.79
    unknownAngola
    37119unitel-ASAOfalse
    172.95.97.83
    unknownUnited States
    5650FRONTIER-FRTRUSfalse
    24.119.32.80
    unknownUnited States
    11492CABLEONEUSfalse
    30.69.36.129
    unknownUnited States
    7922COMCAST-7922USfalse
    75.58.102.119
    unknownUnited States
    7018ATT-INTERNET4USfalse
    245.241.93.17
    unknownReserved
    unknownunknownfalse
    252.212.204.109
    unknownReserved
    unknownunknownfalse
    108.17.85.21
    unknownUnited States
    701UUNETUSfalse
    125.84.43.238
    unknownChina
    4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
    74.39.32.134
    unknownUnited States
    7011FRONTIER-AND-CITIZENSUSfalse
    81.248.152.139
    unknownFrance
    3215FranceTelecom-OrangeFRfalse
    56.243.22.28
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    82.163.179.146
    unknownUnited Kingdom
    34119WILDCARD-ASWildcardUKLimitedGBfalse
    59.204.179.226
    unknownChina
    2516KDDIKDDICORPORATIONJPfalse
    6.204.135.131
    unknownUnited States
    3356LEVEL3USfalse
    120.73.155.204
    unknownKorea Republic of
    9761KUMHO-ASKUMHOKRfalse
    116.203.175.100
    unknownGermany
    24940HETZNER-ASDEfalse
    21.113.206.71
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    86.122.212.76
    unknownRomania
    8708RCS-RDS73-75DrStaicoviciROfalse
    102.241.140.246
    unknownTunisia
    36926CKL1-ASNKEfalse
    99.243.147.138
    unknownCanada
    812ROGERS-COMMUNICATIONSCAfalse
    93.173.74.246
    unknownIsrael
    1680NV-ASNCELLCOMltdILfalse
    251.168.78.125
    unknownReserved
    unknownunknownfalse
    172.182.151.38
    unknownUnited States
    7018ATT-INTERNET4USfalse
    108.137.250.74
    unknownUnited States
    16509AMAZON-02USfalse
    216.157.141.99
    unknownUnited States
    64200VIVIDHOSTINGUSfalse
    21.235.122.143
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    87.40.33.219
    unknownIreland
    1213HEANETIEfalse
    13.64.110.77
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    46.164.101.132
    unknownIran (ISLAMIC Republic Of)
    21283A1SI-ASA1SlovenijaSIfalse
    252.168.83.145
    unknownReserved
    unknownunknownfalse
    47.70.101.167
    unknownUnited States
    3209VODANETInternationalIP-BackboneofVodafoneDEfalse
    243.151.202.251
    unknownReserved
    unknownunknownfalse
    223.175.71.94
    unknownKorea Republic of
    17853LGTELECOM-AS-KRLGTELECOMKRfalse
    241.120.231.67
    unknownReserved
    unknownunknownfalse
    205.23.67.181
    unknownUnited States
    2914NTT-COMMUNICATIONS-2914USfalse
    163.242.135.255
    unknownGermany
    668DNIC-AS-00668USfalse
    4.88.72.209
    unknownUnited States
    3356LEVEL3USfalse
    48.88.173.146
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    65.223.235.70
    unknownUnited States
    14251MLSLIUSfalse
    184.221.32.102
    unknownUnited States
    10507SPCSUSfalse
    2.202.172.190
    unknownGermany
    3209VODANETInternationalIP-BackboneofVodafoneDEfalse
    15.181.88.203
    unknownUnited States
    5073HPESUSfalse
    155.46.249.142
    unknownUnited States
    24324KORDIA-TRANSIT-AS-APKordiaLimitedNZfalse
    81.137.110.100
    unknownUnited Kingdom
    2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
    13.185.138.46
    unknownUnited States
    7018ATT-INTERNET4USfalse
    206.139.179.160
    unknownUnited States
    701UUNETUSfalse
    199.10.82.74
    unknownUnited States
    397086LAYER-HOST-HOUSTONUSfalse
    132.202.39.111
    unknownCanada
    10754GOV-FRB-BOGUSfalse
    72.127.213.109
    unknownUnited States
    22394CELLCOUSfalse
    190.109.191.109
    unknownColombia
    27695EDATELSAESPCOfalse
    173.140.11.76
    unknownUnited States
    10507SPCSUSfalse
    156.158.51.159
    unknownTanzania United Republic of
    37133airtel-tz-asTZfalse
    25.54.136.191
    unknownUnited Kingdom
    7922COMCAST-7922USfalse
    93.246.95.232
    unknownGermany
    3320DTAGInternetserviceprovideroperationsDEfalse
    52.107.25.220
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    45.185.84.70
    unknownBrazil
    269408EdmilsondeLimaAraujo-meBRfalse
    55.35.146.194
    unknownUnited States
    322DNIC-ASBLK-00306-00371USfalse
    76.58.177.92
    unknownUnited States
    18494CENTURYLINK-LEGACY-EMBARQ-WRBGUSfalse
    89.141.144.186
    unknownSpain
    12430VODAFONE_ESESfalse
    24.57.77.34
    unknownCanada
    7992COGECOWAVECAfalse
    212.84.77.133
    unknownUnited Kingdom
    198382FIRSTEASY-ASGBfalse
    100.88.99.186
    unknownReserved
    701UUNETUSfalse
    152.0.104.82
    unknownDominican Republic
    6400CompaniaDominicanadeTelefonosSADOfalse
    240.228.111.21
    unknownReserved
    unknownunknownfalse
    222.159.198.164
    unknownJapan2510INFOWEBFUJITSULIMITEDJPfalse
    40.102.64.11
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    181.87.83.61
    unknownArgentina
    7303TelecomArgentinaSAARfalse
    54.51.52.171
    unknownUnited States
    14618AMAZON-AESUSfalse
    8.222.140.99
    unknownSingapore
    45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
    138.99.105.43
    unknownBrazil
    52764DeltaBroadbandTelecomProvedoresdeInternetLtdBRfalse
    162.202.25.19
    unknownUnited States
    7018ATT-INTERNET4USfalse
    136.74.244.2
    unknownUnited States
    60311ONEFMCHfalse
    250.177.253.177
    unknownReserved
    unknownunknownfalse
    71.233.212.132
    unknownUnited States
    7922COMCAST-7922USfalse
    96.195.149.26
    unknownUnited States
    7922COMCAST-7922USfalse
    5.234.141.95
    unknownIran (ISLAMIC Republic Of)
    58224TCIIRfalse
    133.125.49.232
    unknownJapan7684SAKURA-ASAKURAInternetIncJPfalse
    26.138.209.53
    unknownUnited States
    7922COMCAST-7922USfalse
    243.182.99.116
    unknownReserved
    unknownunknownfalse
    49.227.44.247
    unknownNew Zealand
    9500VODAFONE-TRANSIT-ASVodafoneNZLtdNZfalse
    8.123.122.28
    unknownUnited States
    3356LEVEL3USfalse
    13.20.238.138
    unknownUnited States
    395959XEROX-ELLUSfalse
    46.107.141.193
    unknownHungary
    5483MAGYAR-TELEKOM-MAIN-ASMagyarTelekomNyrtHUfalse
    186.234.255.181
    unknownBrazil
    19089UOLDIVEOSABRfalse
    69.166.99.217
    unknownUnited States
    26527LIGHTWAVE-NETWORKSUSfalse
    177.203.221.213
    unknownBrazil
    8167BrasilTelecomSA-FilialDistritoFederalBRfalse
    40.216.186.116
    unknownUnited States
    4249LILLY-ASUSfalse
    133.106.140.194
    unknownJapan138384RMNI-AS-APRakutenMobileNetworkIncJPfalse
    137.8.149.51
    unknownUnited States
    721DNIC-ASBLK-00721-00726USfalse
    216.110.27.234
    unknownUnited States
    36070NCHCORPUSfalse
    82.75.178.20
    unknownNetherlands
    33915TNF-ASNLfalse
    38.77.254.22
    unknownUnited States
    395719EMERALDUSfalse
    152.14.250.158
    unknownUnited States
    11442NCSUUSfalse
    34.142.42.124
    unknownUnited States
    2686ATGS-MMD-ASUSfalse
    82.214.10.135
    unknownSweden
    42708PORTLANEwwwportlanecomSEfalse
    124.105.52.172
    unknownPhilippines
    9299IPG-AS-APPhilippineLongDistanceTelephoneCompanyPHfalse
    15.123.220.174
    unknownUnited States
    13979ATT-IPFRUSfalse
    107.111.117.130
    unknownUnited States
    7018ATT-INTERNET4USfalse
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
    Entropy (8bit):5.764749674440205
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:Smqw34mNlm
    File size:38144
    MD5:280c087a0073bd36784e8af0b7254670
    SHA1:0c650be334cc8f692102e27d4a0e9ae3d97afd71
    SHA256:8b5fc53ad49b0005798e9fdd8a9738d798755ee6070b08d1fff41c848200548a
    SHA512:55d0b717f05af68ddf090e8423b6b296713ef8a63355c7818d077794b6b0082a220bb67782882ce5dde35b64836c66aadaad3b4cc06bee6fbb48c0a82645eee4
    SSDEEP:768:gl18lk3XKf9kLb5R3c97Clb6jrojNC5I:olHOo/q7CF6fB5I
    TLSH:020318132450C1FCD549C5705BBFA22BCA33F07D5235FA8A73A47E2A6E0BE311E1A849
    File Content Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@.....@.......@.................................P.......P.....@.......................Q.td....................................................H...._.....w..H........

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x400194
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:3
    Section Header Offset:37504
    Section Header Size:64
    Number of Section Headers:10
    Header String Table Index:9
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x4000e80xe80x130x00x6AX001
    .textPROGBITS0x4001000x1000x77e60x00x6AX0016
    .finiPROGBITS0x4078e60x78e60xe0x00x6AX001
    .rodataPROGBITS0x4079000x79000xc400x00x2A0032
    .ctorsPROGBITS0x5090000x90000x100x00x3WA008
    .dtorsPROGBITS0x5090100x90100x100x00x3WA008
    .dataPROGBITS0x5090400x90400x2000x00x3WA0032
    .bssNOBITS0x5092400x92400xb680x00x3WA0032
    .shstrtabSTRTAB0x00x92400x3e0x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x85400x85406.14660x5R E0x100000.init .text .fini .rodata
    LOAD0x90000x5090000x5090000x2400xda82.87040x6RW 0x100000.ctors .dtors .data .bss
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
    TimestampSource PortDest PortSource IPDest IP
    Aug 5, 2022 14:03:44.273574114 CEST381825556192.168.2.2331.7.58.162
    Aug 5, 2022 14:03:44.274401903 CEST586712323192.168.2.237.168.141.249
    Aug 5, 2022 14:03:44.274419069 CEST5867123192.168.2.23198.68.134.249
    Aug 5, 2022 14:03:44.274421930 CEST5867123192.168.2.23122.114.166.159
    Aug 5, 2022 14:03:44.274426937 CEST5867123192.168.2.23211.177.36.167
    Aug 5, 2022 14:03:44.274439096 CEST5867123192.168.2.23104.13.196.249
    Aug 5, 2022 14:03:44.274444103 CEST5867123192.168.2.2393.174.77.50
    Aug 5, 2022 14:03:44.274444103 CEST5867123192.168.2.2380.112.1.82
    Aug 5, 2022 14:03:44.274456978 CEST5867123192.168.2.23172.128.194.250
    Aug 5, 2022 14:03:44.274475098 CEST5867123192.168.2.23205.21.227.60
    Aug 5, 2022 14:03:44.274478912 CEST5867123192.168.2.23245.105.85.166
    Aug 5, 2022 14:03:44.274483919 CEST5867123192.168.2.23172.4.56.65
    Aug 5, 2022 14:03:44.274490118 CEST5867123192.168.2.23100.144.78.230
    Aug 5, 2022 14:03:44.274504900 CEST5867123192.168.2.23218.158.107.199
    Aug 5, 2022 14:03:44.274507999 CEST5867123192.168.2.23107.106.118.92
    Aug 5, 2022 14:03:44.274532080 CEST5867123192.168.2.2354.53.148.170
    Aug 5, 2022 14:03:44.274535894 CEST5867123192.168.2.23243.217.160.184
    Aug 5, 2022 14:03:44.274538040 CEST586712323192.168.2.23118.131.166.21
    Aug 5, 2022 14:03:44.274540901 CEST5867123192.168.2.23200.69.77.152
    Aug 5, 2022 14:03:44.274544001 CEST5867123192.168.2.23170.163.179.38
    Aug 5, 2022 14:03:44.274549007 CEST5867123192.168.2.23198.149.212.106
    Aug 5, 2022 14:03:44.274549961 CEST5867123192.168.2.23100.9.154.2
    Aug 5, 2022 14:03:44.274549961 CEST5867123192.168.2.2333.45.97.93
    Aug 5, 2022 14:03:44.274566889 CEST5867123192.168.2.232.125.220.123
    Aug 5, 2022 14:03:44.274569035 CEST5867123192.168.2.23152.3.107.53
    Aug 5, 2022 14:03:44.274574041 CEST586712323192.168.2.23193.254.59.44
    Aug 5, 2022 14:03:44.274574041 CEST586712323192.168.2.23248.20.109.37
    Aug 5, 2022 14:03:44.274578094 CEST5867123192.168.2.23184.159.52.183
    Aug 5, 2022 14:03:44.274585009 CEST5867123192.168.2.23218.78.127.85
    Aug 5, 2022 14:03:44.274590015 CEST5867123192.168.2.2395.42.62.18
    Aug 5, 2022 14:03:44.274602890 CEST5867123192.168.2.23167.95.143.87
    Aug 5, 2022 14:03:44.274612904 CEST5867123192.168.2.23245.253.223.223
    Aug 5, 2022 14:03:44.274619102 CEST5867123192.168.2.2375.56.163.140
    Aug 5, 2022 14:03:44.274631977 CEST5867123192.168.2.23167.195.211.111
    Aug 5, 2022 14:03:44.274632931 CEST5867123192.168.2.23101.92.139.72
    Aug 5, 2022 14:03:44.274637938 CEST5867123192.168.2.23206.98.193.173
    Aug 5, 2022 14:03:44.274646997 CEST5867123192.168.2.23143.222.240.47
    Aug 5, 2022 14:03:44.274661064 CEST5867123192.168.2.23222.42.166.140
    Aug 5, 2022 14:03:44.274667025 CEST5867123192.168.2.2339.39.199.249
    Aug 5, 2022 14:03:44.274671078 CEST586712323192.168.2.2370.27.243.152
    Aug 5, 2022 14:03:44.274676085 CEST5867123192.168.2.23243.110.162.249
    Aug 5, 2022 14:03:44.274686098 CEST5867123192.168.2.23247.253.250.130
    Aug 5, 2022 14:03:44.274704933 CEST5867123192.168.2.237.101.126.217
    Aug 5, 2022 14:03:44.274708033 CEST5867123192.168.2.23180.66.202.69
    Aug 5, 2022 14:03:44.274708033 CEST5867123192.168.2.23157.131.86.241
    Aug 5, 2022 14:03:44.274710894 CEST5867123192.168.2.23248.163.253.145
    Aug 5, 2022 14:03:44.274713993 CEST5867123192.168.2.2311.24.219.118
    Aug 5, 2022 14:03:44.274715900 CEST5867123192.168.2.2314.137.86.116
    Aug 5, 2022 14:03:44.274717093 CEST586712323192.168.2.23187.200.25.201
    Aug 5, 2022 14:03:44.274727106 CEST5867123192.168.2.23124.242.166.66
    Aug 5, 2022 14:03:44.274728060 CEST5867123192.168.2.2334.38.61.171
    Aug 5, 2022 14:03:44.274730921 CEST5867123192.168.2.2360.254.164.254
    Aug 5, 2022 14:03:44.274735928 CEST5867123192.168.2.2351.59.193.66
    Aug 5, 2022 14:03:44.274741888 CEST5867123192.168.2.2323.129.84.224
    Aug 5, 2022 14:03:44.274743080 CEST5867123192.168.2.23142.100.110.68
    Aug 5, 2022 14:03:44.274749041 CEST5867123192.168.2.2351.241.122.171
    Aug 5, 2022 14:03:44.274758101 CEST5867123192.168.2.23139.4.142.252
    Aug 5, 2022 14:03:44.274764061 CEST5867123192.168.2.2357.58.249.222
    Aug 5, 2022 14:03:44.274766922 CEST5867123192.168.2.2393.163.56.197
    Aug 5, 2022 14:03:44.274768114 CEST5867123192.168.2.236.38.12.186
    Aug 5, 2022 14:03:44.274766922 CEST5867123192.168.2.2375.151.187.16
    Aug 5, 2022 14:03:44.274770021 CEST586712323192.168.2.23194.131.0.230
    Aug 5, 2022 14:03:44.274777889 CEST586712323192.168.2.2357.2.199.227
    Aug 5, 2022 14:03:44.274779081 CEST5867123192.168.2.23188.206.79.140
    Aug 5, 2022 14:03:44.274781942 CEST5867123192.168.2.2375.62.154.146
    Aug 5, 2022 14:03:44.274786949 CEST5867123192.168.2.2380.28.91.83
    Aug 5, 2022 14:03:44.274789095 CEST5867123192.168.2.23250.26.33.150
    Aug 5, 2022 14:03:44.274790049 CEST5867123192.168.2.23197.193.255.2
    Aug 5, 2022 14:03:44.274801970 CEST5867123192.168.2.23118.20.14.195
    Aug 5, 2022 14:03:44.274802923 CEST5867123192.168.2.2396.135.14.176
    Aug 5, 2022 14:03:44.274806976 CEST5867123192.168.2.2320.35.89.221
    Aug 5, 2022 14:03:44.274822950 CEST5867123192.168.2.23139.138.95.3
    Aug 5, 2022 14:03:44.274826050 CEST5867123192.168.2.2357.253.107.68
    Aug 5, 2022 14:03:44.274827957 CEST5867123192.168.2.23198.33.52.254
    Aug 5, 2022 14:03:44.274836063 CEST5867123192.168.2.236.75.212.106
    Aug 5, 2022 14:03:44.274878979 CEST586712323192.168.2.2358.88.193.35
    Aug 5, 2022 14:03:44.274913073 CEST5867123192.168.2.2384.215.145.90
    Aug 5, 2022 14:03:44.274919033 CEST5867123192.168.2.2325.201.33.64
    Aug 5, 2022 14:03:44.274919987 CEST5867123192.168.2.2340.139.152.70
    Aug 5, 2022 14:03:44.274919987 CEST5867123192.168.2.23104.224.189.125
    Aug 5, 2022 14:03:44.274926901 CEST5867123192.168.2.2394.243.188.181
    Aug 5, 2022 14:03:44.274929047 CEST5867123192.168.2.2391.173.248.9
    Aug 5, 2022 14:03:44.274930000 CEST586712323192.168.2.23164.7.174.192
    Aug 5, 2022 14:03:44.274933100 CEST5867123192.168.2.23165.155.56.60
    Aug 5, 2022 14:03:44.274938107 CEST5867123192.168.2.23126.104.10.145
    Aug 5, 2022 14:03:44.274939060 CEST5867123192.168.2.23131.115.105.118
    Aug 5, 2022 14:03:44.274944067 CEST5867123192.168.2.23249.88.87.110
    Aug 5, 2022 14:03:44.274946928 CEST5867123192.168.2.23180.113.9.201
    Aug 5, 2022 14:03:44.274952888 CEST5867123192.168.2.23141.16.183.65
    Aug 5, 2022 14:03:44.274957895 CEST5867123192.168.2.2386.154.71.245
    Aug 5, 2022 14:03:44.274961948 CEST5867123192.168.2.2310.252.207.71
    Aug 5, 2022 14:03:44.274965048 CEST5867123192.168.2.23223.130.65.85
    Aug 5, 2022 14:03:44.274965048 CEST5867123192.168.2.2338.155.104.197
    Aug 5, 2022 14:03:44.274967909 CEST5867123192.168.2.23202.234.118.131
    Aug 5, 2022 14:03:44.274970055 CEST5867123192.168.2.23122.121.209.119
    Aug 5, 2022 14:03:44.274971962 CEST5867123192.168.2.23159.142.29.231
    Aug 5, 2022 14:03:44.274972916 CEST586712323192.168.2.23189.54.119.8
    Aug 5, 2022 14:03:44.274975061 CEST5867123192.168.2.23109.214.241.220
    Aug 5, 2022 14:03:44.274976969 CEST586712323192.168.2.2350.84.124.105
    Aug 5, 2022 14:03:44.274980068 CEST5867123192.168.2.23193.52.91.108

    System Behavior

    Start time:14:03:43
    Start date:05/08/2022
    Path:/tmp/Smqw34mNlm
    Arguments:/tmp/Smqw34mNlm
    File size:38144 bytes
    MD5 hash:280c087a0073bd36784e8af0b7254670
    Start time:14:03:43
    Start date:05/08/2022
    Path:/tmp/Smqw34mNlm
    Arguments:n/a
    File size:38144 bytes
    MD5 hash:280c087a0073bd36784e8af0b7254670
    Start time:14:03:43
    Start date:05/08/2022
    Path:/tmp/Smqw34mNlm
    Arguments:n/a
    File size:38144 bytes
    MD5 hash:280c087a0073bd36784e8af0b7254670