Loading ...

Play interactive tourEdit tour

Linux Analysis Report z0x3n.x86

Overview

General Information

Sample Name:z0x3n.x86
Analysis ID:512619
MD5:c2c1c54bbc5f372df082aebc0d983716
SHA1:2c9ebbad068ea09d2fcf7cfff48608a8abdf4337
SHA256:dd9c8a7d71f944ded984394fcc021043403e3a39ef424d70d2a3a18c3b58b69d
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Yara signature match
Sample has stripped symbol table
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:512619
Start date:01.11.2021
Start time:08:54:01
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:z0x3n.x86
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.troj.linX86@0/0@1/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • z0x3n.x86 (PID: 5231, Parent: 5116, MD5: c2c1c54bbc5f372df082aebc0d983716) Arguments: /tmp/z0x3n.x86
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
z0x3n.x86SUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
  • 0xedc8:$xo1: Dfs`eeh&<'9
  • 0xee40:$xo1: Dfs`eeh&<'9
  • 0xeeb4:$xo1: Dfs`eeh&<'9
  • 0xef24:$xo1: Dfs`eeh&<'9
  • 0xef70:$xo1: Dfs`eeh&<'9

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Memory Dumps

    SourceRuleDescriptionAuthorStrings
    5231.1.0000000019671de5.00000000c7254e12.rw-.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x6d0:$xo1: Dfs`eeh&<'9
    • 0x750:$xo1: Dfs`eeh&<'9
    • 0x7c8:$xo1: Dfs`eeh&<'9
    • 0x840:$xo1: Dfs`eeh&<'9
    • 0x890:$xo1: Dfs`eeh&<'9
    5234.1.0000000019671de5.00000000c7254e12.rw-.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x6d0:$xo1: Dfs`eeh&<'9
    • 0x750:$xo1: Dfs`eeh&<'9
    • 0x7c8:$xo1: Dfs`eeh&<'9
    • 0x840:$xo1: Dfs`eeh&<'9
    • 0x890:$xo1: Dfs`eeh&<'9
    5232.1.0000000019671de5.00000000c7254e12.rw-.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x6d0:$xo1: Dfs`eeh&<'9
    • 0x750:$xo1: Dfs`eeh&<'9
    • 0x7c8:$xo1: Dfs`eeh&<'9
    • 0x840:$xo1: Dfs`eeh&<'9
    • 0x890:$xo1: Dfs`eeh&<'9
    5232.1.000000001a887bdc.00000000328ec990.r-x.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0xedc8:$xo1: Dfs`eeh&<'9
    • 0xee40:$xo1: Dfs`eeh&<'9
    • 0xeeb4:$xo1: Dfs`eeh&<'9
    • 0xef24:$xo1: Dfs`eeh&<'9
    • 0xef70:$xo1: Dfs`eeh&<'9
    5231.1.000000001a887bdc.00000000328ec990.r-x.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0xedc8:$xo1: Dfs`eeh&<'9
    • 0xee40:$xo1: Dfs`eeh&<'9
    • 0xeeb4:$xo1: Dfs`eeh&<'9
    • 0xef24:$xo1: Dfs`eeh&<'9
    • 0xef70:$xo1: Dfs`eeh&<'9
    Click to see the 1 entries

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: z0x3n.x86Virustotal: Detection: 41%Perma Link
    Machine Learning detection for sampleShow sources
    Source: z0x3n.x86Joe Sandbox ML: detected

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46804
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46812
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46814
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46816
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46820
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46868
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46908
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46918
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.242.254.71:23 -> 192.168.2.23:42324
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.242.254.71:23 -> 192.168.2.23:42324
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46936
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46954
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:46990
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47048
    Source: TrafficSnort IDS: 2025080 ET EXPLOIT Actiontec C1000A backdoor account M1 192.168.2.23:47048 -> 177.126.89.178:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47088
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47128
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47168
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47188
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.242.254.71:23 -> 192.168.2.23:42604
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.242.254.71:23 -> 192.168.2.23:42604
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47198
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47206
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47214
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47222
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47228
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47236
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47282
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47332
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47342
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 14.242.254.71:23 -> 192.168.2.23:42760
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 14.242.254.71:23 -> 192.168.2.23:42760
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47356
    Source: TrafficSnort IDS: 492 INFO TELNET login failed 103.192.76.235:23 -> 192.168.2.23:43346
    Source: TrafficSnort IDS: 716 INFO TELNET access 177.126.89.178:23 -> 192.168.2.23:47364
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 47.1.101.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 125.229.138.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 105.13.231.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 213.147.72.17:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 37.37.20.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 181.70.39.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 68.190.30.118:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 156.58.60.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 169.159.209.10:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 86.0.55.109:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 159.44.145.109:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 208.121.47.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 23.227.190.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 80.126.58.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 70.246.158.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:60692 -> 37.0.10.67:11199
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 221.33.62.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 92.9.54.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 88.169.66.145:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 184.107.27.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 188.78.150.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 158.92.133.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 168.220.47.66:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 67.216.157.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 47.94.166.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 161.141.44.53:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 90.34.76.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 219.165.130.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 142.22.31.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 23.90.136.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 13.169.44.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 87.135.162.69:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 79.161.77.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 202.230.104.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 185.245.106.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 66.170.200.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 141.88.84.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 168.195.222.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 111.13.221.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 93.188.18.248:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 37.81.180.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 171.99.64.49:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 44.149.111.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 5.36.233.166:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 208.13.104.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 47.147.64.228:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 163.71.180.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 37.22.251.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 108.110.47.66:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 200.107.192.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 152.245.254.233:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 96.236.225.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 109.232.170.66:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 85.196.240.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 142.122.73.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 181.49.62.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 58.230.50.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 125.199.112.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 114.187.246.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 201.67.77.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 46.17.125.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 103.51.108.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 145.24.171.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 72.140.85.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 104.68.237.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 93.161.152.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 175.79.101.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 216.197.142.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 143.253.25.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 4.231.190.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 119.155.48.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 141.167.46.146:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 89.12.160.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 109.85.221.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 60.15.174.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 197.239.79.228:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 147.32.196.147:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 197.140.54.82:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 96.185.139.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 87.248.84.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 66.177.116.44:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 125.145.186.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 179.67.250.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 157.139.215.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 221.67.167.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 83.73.29.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 166.118.94.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 188.183.116.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 76.154.80.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 169.165.32.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 2.5.99.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 146.190.65.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 118.226.196.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 98.140.74.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 84.164.182.25:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 75.22.228.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 166.241.67.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 38.145.157.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 173.91.115.87:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 146.34.11.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 217.19.45.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 8.80.25.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 122.184.234.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 102.31.192.73:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 8.214.20.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 96.241.91.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 188.83.6.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 109.43.136.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 123.74.18.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 208.91.202.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 212.114.152.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 218.140.168.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 61.181.112.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 17.119.83.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 213.181.249.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 42.150.225.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 4.234.100.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 1.12.34.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 168.240.84.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 80.75.125.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 61.93.211.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 178.185.39.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 178.225.49.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 68.201.245.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 125.177.181.195:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 36.98.187.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 94.242.48.79:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 129.8.101.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 149.194.60.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 48.118.100.206:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 186.225.134.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 110.52.205.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 155.63.4.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 185.206.56.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 42.208.172.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 217.30.37.44:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 13.127.5.82:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 195.143.165.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 102.46.144.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 190.127.105.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 142.29.163.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 59.124.112.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 63.251.42.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 95.83.19.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 91.101.137.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 67.155.200.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 105.171.41.173:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 154.199.17.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 13.161.22.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 39.58.182.13:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 5.128.25.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 94.31.35.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 217.18.124.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 108.100.149.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 145.254.198.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 171.52.71.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 151.193.135.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 115.99.234.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 97.133.53.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 200.200.172.130:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 109.140.73.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 220.10.92.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 69.90.181.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 213.128.81.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 221.225.149.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 210.210.209.155:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 18.33.216.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 158.205.147.130:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 188.110.183.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 221.59.94.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 121.229.132.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 148.14.93.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 68.1.152.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 42.232.21.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 80.52.205.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 102.95.95.125:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 1.29.156.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 142.248.75.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 89.243.243.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 111.4.255.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 217.113.110.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 180.145.44.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 221.152.196.44:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 209.137.225.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 93.237.29.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 184.98.75.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 12.186.163.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 181.113.181.251:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 93.41.25.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 112.43.103.87:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 219.176.105.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 74.20.29.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 124.32.46.152:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 196.67.219.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 200.117.53.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 151.73.95.1:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 218.161.230.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 109.40.58.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 91.190.253.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 178.98.139.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 89.39.90.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 60.253.15.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 182.117.8.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 108.76.175.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 113.3.137.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 223.221.20.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 86.31.225.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 80.162.93.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 197.60.176.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 13.79.59.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 81.90.105.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 69.245.252.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 101.59.251.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 196.205.220.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 40.126.29.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 182.36.117.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 112.243.228.1:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 211.157.150.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 102.173.156.173:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 176.1.204.94:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 135.141.0.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 120.70.217.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 70.140.2.13:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 8.77.29.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 57.44.137.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 96.102.62.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 116.119.175.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 119.40.45.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 189.11.34.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 83.103.17.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 72.177.18.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 73.14.90.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 113.71.46.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 115.185.152.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 169.165.211.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 174.236.86.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 180.120.47.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 9.191.85.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 106.88.129.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 31.105.253.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 213.163.28.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 1.115.111.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 164.14.148.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 82.210.60.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 182.145.103.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 83.79.229.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 19.198.251.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 158.29.176.53:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 147.213.127.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 173.40.194.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 38.102.155.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 130.223.218.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 153.55.168.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 88.156.149.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 168.10.226.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 184.56.137.125:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 162.245.157.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 136.139.187.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 180.123.247.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 125.106.132.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 151.9.68.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 2.0.172.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 197.252.140.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 174.169.241.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 93.104.195.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 94.100.163.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 149.192.217.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 39.107.252.74:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 65.200.82.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 154.130.142.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 102.121.90.210:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 141.140.17.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 39.219.49.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 167.87.231.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 99.202.69.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 126.24.131.43:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 54.122.83.204:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 4.211.37.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 70.199.97.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 12.205.77.41:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 208.13.203.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 163.17.54.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 1.93.103.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 124.218.81.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 37.91.237.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 41.210.7.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 4.253.74.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 97.111.15.106:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 146.117.25.115:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 209.73.10.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 87.99.174.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 126.196.148.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 108.134.228.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 91.153.164.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 115.92.32.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 47.13.156.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 113.217.205.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 194.21.223.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 73.141.45.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 103.30.225.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 157.163.80.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 147.206.96.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 20.194.249.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 193.104.57.72:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 114.43.35.224:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 23.205.105.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 146.30.215.148:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 202.31.210.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 136.52.96.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 161.55.110.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 169.80.206.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 54.62.168.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 37.227.154.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 98.145.169.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 66.52.215.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 188.230.28.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 80.149.40.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 167.236.190.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 103.190.220.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 202.141.255.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 38.64.38.116:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 101.152.104.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 111.5.229.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 59.58.176.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 37.117.228.17:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 159.166.177.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 96.241.59.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 46.147.185.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 123.246.37.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 109.31.128.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 86.234.159.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 194.141.131.47:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 23.39.223.78:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 114.253.241.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 159.217.22.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 220.51.111.94:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 62.243.169.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 184.130.204.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 112.185.94.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 76.76.26.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 117.170.226.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 107.45.166.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 107.224.50.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 43.5.182.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 219.183.241.13:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 201.134.125.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 60.104.42.103:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 8.25.90.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 206.205.232.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 113.170.18.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 216.216.124.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 41.133.114.203:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 148.118.118.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 152.33.10.251:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 44.161.70.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 177.88.230.150:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 23.65.13.179:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 14.151.27.96:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 182.43.242.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 178.196.21.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 2.240.46.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 207.212.80.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 1.207.147.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 184.119.22.82:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 12.77.182.74:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 114.35.80.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 219.61.152.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 207.116.56.159:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 222.184.178.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 45.181.53.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 153.207.55.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 91.70.95.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 95.93.11.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 119.133.116.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 165.206.138.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 204.121.184.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 87.30.195.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 42.69.163.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 2.158.72.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 90.116.127.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 100.221.213.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 152.9.94.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 219.72.214.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 220.23.201.21:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 65.149.204.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 220.206.145.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 47.105.234.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 208.75.107.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 78.54.211.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 142.241.227.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 46.229.251.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 79.172.103.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 57.147.191.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 175.84.244.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 202.124.111.79:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 114.4.108.105:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 98.126.231.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 198.127.110.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 97.169.146.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 194.245.162.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 107.219.54.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 43.110.33.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 106.44.67.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 185.79.220.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 188.30.128.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 146.18.196.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 157.26.23.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 170.27.217.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 157.210.103.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 142.44.79.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 65.159.255.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 183.68.221.241:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 60.79.203.156:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 27.169.24.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 142.99.161.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 196.255.81.253:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 14.169.2.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 196.9.143.125:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 93.37.38.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 70.138.151.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 109.118.145.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 102.220.166.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 105.82.82.69:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 121.196.27.234:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 194.110.150.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 68.71.24.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 34.98.22.215:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 53.187.127.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 13.69.21.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 41.20.66.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 62.4.185.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 42.144.122.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 212.254.213.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 153.53.150.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 95.29.250.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 60.128.141.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 223.236.3.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 20.118.235.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 87.110.177.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 220.117.148.24:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 158.184.49.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 173.230.70.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 65.31.20.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 61.2.243.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 210.215.231.86:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 125.55.87.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 5.16.140.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 98.183.103.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 195.81.195.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 126.118.108.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 41.68.221.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 201.199.15.151:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 112.77.17.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 73.101.218.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 223.201.126.17:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 31.230.227.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 193.58.153.166:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 58.210.71.75:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 124.132.216.149:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 201.109.52.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 80.10.251.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 173.233.194.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 156.154.198.183:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 112.183.211.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 203.242.2.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 72.34.73.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 61.90.55.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 168.103.254.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 4.115.182.219:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 221.175.48.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 92.24.86.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 12.101.89.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 164.128.223.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 37.86.107.203:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 83.38.116.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 212.152.43.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 189.162.9.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 101.210.143.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 193.135.133.48:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 117.41.17.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 125.82.4.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 94.46.144.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 161.110.163.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 188.194.79.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 200.45.158.72:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 20.173.48.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 96.217.230.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 207.74.116.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 108.170.91.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 182.125.255.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 180.187.214.243:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 84.70.233.36:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 135.254.189.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 66.160.67.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 44.190.26.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 183.157.170.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 207.179.219.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 211.167.230.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 202.159.48.59:2323
    Source: global trafficTCP traffic: 192.168.2.23:23086 -> 155.158.127.144:2323
    Source: unknownDNS traffic detected: queries for: z0x3n.cf
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 103.61.176.109
    Source: unknownTCP traffic detected without corresponding DNS query: 47.1.101.157
    Source: unknownTCP traffic detected without corresponding DNS query: 182.193.240.200
    Source: unknownTCP traffic detected without corresponding DNS query: 84.203.31.69
    Source: unknownTCP traffic detected without corresponding DNS query: 149.100.205.117
    Source: unknownTCP traffic detected without corresponding DNS query: 36.119.11.175
    Source: unknownTCP traffic detected without corresponding DNS query: 125.229.138.235
    Source: unknownTCP traffic detected without corresponding DNS query: 77.163.249.232
    Source: unknownTCP traffic detected without corresponding DNS query: 196.101.75.42
    Source: unknownTCP traffic detected without corresponding DNS query: 54.128.144.224
    Source: unknownTCP traffic detected without corresponding DNS query: 95.44.64.51
    Source: unknownTCP traffic detected without corresponding DNS query: 62.169.67.211
    Source: unknownTCP traffic detected without corresponding DNS query: 87.194.59.225
    Source: unknownTCP traffic detected without corresponding DNS query: 67.228.183.69
    Source: unknownTCP traffic detected without corresponding DNS query: 17.253.179.71
    Source: unknownTCP traffic detected without corresponding DNS query: 102.71.3.185
    Source: unknownTCP traffic detected without corresponding DNS query: 91.111.19.201
    Source: unknownTCP traffic detected without corresponding DNS query: 57.236.55.216
    Source: unknownTCP traffic detected without corresponding DNS query: 166.150.88.190
    Source: unknownTCP traffic detected without corresponding DNS query: 94.231.7.73
    Source: unknownTCP traffic detected without corresponding DNS query: 114.112.47.159
    Source: unknownTCP traffic detected without corresponding DNS query: 117.90.192.120
    Source: unknownTCP traffic detected without corresponding DNS query: 135.2.225.206
    Source: unknownTCP traffic detected without corresponding DNS query: 168.144.25.169
    Source: unknownTCP traffic detected without corresponding DNS query: 71.158.19.146
    Source: unknownTCP traffic detected without corresponding DNS query: 208.151.213.102
    Source: unknownTCP traffic detected without corresponding DNS query: 81.95.135.55
    Source: unknownTCP traffic detected without corresponding DNS query: 169.26.177.164
    Source: unknownTCP traffic detected without corresponding DNS query: 99.11.81.41
    Source: unknownTCP traffic detected without corresponding DNS query: 105.13.231.165
    Source: unknownTCP traffic detected without corresponding DNS query: 90.180.225.184
    Source: unknownTCP traffic detected without corresponding DNS query: 213.147.72.17
    Source: unknownTCP traffic detected without corresponding DNS query: 88.133.77.153
    Source: unknownTCP traffic detected without corresponding DNS query: 13.144.12.20
    Source: unknownTCP traffic detected without corresponding DNS query: 9.113.2.215
    Source: unknownTCP traffic detected without corresponding DNS query: 192.182.27.143
    Source: unknownTCP traffic detected without corresponding DNS query: 93.147.13.9
    Source: unknownTCP traffic detected without corresponding DNS query: 157.248.119.132
    Source: unknownTCP traffic detected without corresponding DNS query: 41.244.119.157
    Source: unknownTCP traffic detected without corresponding DNS query: 38.231.100.31
    Source: unknownTCP traffic detected without corresponding DNS query: 177.126.89.178
    Source: unknownTCP traffic detected without corresponding DNS query: 175.29.25.120
    Source: unknownTCP traffic detected without corresponding DNS query: 168.96.135.118
    Source: unknownTCP traffic detected without corresponding DNS query: 79.144.135.159
    Source: unknownTCP traffic detected without corresponding DNS query: 192.39.107.5
    Source: unknownTCP traffic detected without corresponding DNS query: 207.200.60.116
    Source: unknownTCP traffic detected without corresponding DNS query: 106.9.22.179
    Source: unknownTCP traffic detected without corresponding DNS query: 168.188.118.67
    Source: unknownTCP traffic detected without corresponding DNS query: 172.101.143.80
    Source: unknownTCP traffic detected without corresponding DNS query: 90.36.198.213
    Source: z0x3n.x86, type: SAMPLEMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5231.1.0000000019671de5.00000000c7254e12.rw-.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5234.1.0000000019671de5.00000000c7254e12.rw-.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5232.1.0000000019671de5.00000000c7254e12.rw-.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5232.1.000000001a887bdc.00000000328ec990.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5231.1.000000001a887bdc.00000000328ec990.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5234.1.000000001a887bdc.00000000328ec990.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal68.troj.linX86@0/0@1/0
    Source: z0x3n.x86Joe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1582/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2033/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1612/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1579/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1699/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1335/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1698/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2028/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1334/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1576/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2025/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2146/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/910/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/912/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/517/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/759/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/918/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1594/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1349/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1623/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/761/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1622/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/884/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1983/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2038/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1344/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1465/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1586/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1860/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1463/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/800/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/801/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1629/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1627/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1900/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/491/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2050/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1877/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/772/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1633/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1599/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1632/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/774/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1477/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/654/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/896/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1476/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1872/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2048/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/655/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1475/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/656/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/777/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/657/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/658/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/419/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/936/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1639/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1638/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1809/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1494/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1890/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2063/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2062/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1888/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1886/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/420/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1489/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/785/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1642/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/788/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/667/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/789/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1648/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2078/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2077/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2074/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/670/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/793/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1656/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1654/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/674/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1532/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/796/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/675/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/797/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/676/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/677/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2069/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2102/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/799/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2080/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2084/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2083/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1668/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1664/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1389/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/720/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2114/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/721/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/1661/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2079/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/847/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2097/maps
    Source: /tmp/z0x3n.x86 (PID: 5235)File opened: /proc/2096/maps

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1System Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol2SIM Card SwapCarrier Billing Fraud

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 512619 Sample: z0x3n.x86 Startdate: 01/11/2021 Architecture: LINUX Score: 68 20 120.20.106.82, 23 VODAFONE-AS-APVodafoneAustraliaPtyLtdAU Australia 2->20 22 14.166.103.211, 23 VNPT-AS-VNVNPTCorpVN Viet Nam 2->22 24 99 other IPs or domains 2->24 26 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Yara detected Mirai 2->30 32 Machine Learning detection for sample 2->32 8 z0x3n.x86 2->8         started        signatures3 process4 process5 10 z0x3n.x86 8->10         started        12 z0x3n.x86 8->12         started        process6 14 z0x3n.x86 10->14         started        16 z0x3n.x86 10->16         started        18 z0x3n.x86 10->18         started       

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    z0x3n.x8642%VirustotalBrowse
    z0x3n.x86100%Joe Sandbox ML

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    z0x3n.cf
    37.0.10.67
    truefalse
      unknown

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      111.12.128.239
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      8.102.49.78
      unknownUnited States
      3356LEVEL3USfalse
      192.77.169.162
      unknownUnited States
      394008DBI-ASUSfalse
      57.111.236.183
      unknownBelgium
      51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
      191.255.128.161
      unknownBrazil
      27699TELEFONICABRASILSABRfalse
      178.22.52.188
      unknownRussian Federation
      44943RAMNET-ASInternetServiceProviderRamNetRUfalse
      91.156.163.171
      unknownFinland
      719ELISA-ASHelsinkiFinlandEUfalse
      179.67.250.16
      unknownBrazil
      7738TelemarNorteLesteSABRfalse
      113.133.36.115
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      195.89.233.144
      unknownUnited Kingdom
      1273CWVodafoneGroupPLCEUfalse
      130.223.218.209
      unknownSwitzerland
      559SWITCHPeeringrequestspeeringswitchchEUfalse
      106.44.67.176
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      181.28.71.103
      unknownArgentina
      10318TelecomArgentinaSAARfalse
      112.246.77.240
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      73.180.82.168
      unknownUnited States
      7922COMCAST-7922USfalse
      213.202.53.40
      unknownSwitzerland
      21466ASQUICKNETKabelfernsehnBoedeliinInterlakenSwitzerlandfalse
      146.190.146.173
      unknownUnited States
      702UUNETUSfalse
      89.27.99.244
      unknownFinland
      16086DNAFIfalse
      20.73.200.192
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      169.64.152.199
      unknownUnited States
      37611AfrihostZAfalse
      210.200.107.2
      unknownTaiwan; Republic of China (ROC)
      9311HITRON-AS-APHITRONTECHNOLOGYINCTWfalse
      200.64.54.219
      unknownMexico
      8151UninetSAdeCVMXfalse
      173.225.75.100
      unknownUnited States
      26878TWRS-NYCUSfalse
      94.43.140.207
      unknownGeorgia
      35805SILKNET-ASGEfalse
      111.253.7.151
      unknownTaiwan; Republic of China (ROC)
      3462HINETDataCommunicationBusinessGroupTWfalse
      1.81.74.63
      unknownChina
      134768CHINANET-SHAANXI-CLOUD-BASECHINANETSHAANXIprovinceCloudfalse
      98.225.187.150
      unknownUnited States
      7922COMCAST-7922USfalse
      183.91.246.58
      unknownKorea Republic of
      9976ICNDP-AS-KRNamincheonBrodcastingCoLtdKRfalse
      200.98.94.223
      unknownBrazil
      7162UniversoOnlineSABRfalse
      177.247.199.47
      unknownMexico
      13999MegaCableSAdeCVMXfalse
      125.51.30.130
      unknownJapan2516KDDIKDDICORPORATIONJPfalse
      185.151.99.5
      unknownIran (ISLAMIC Republic Of)
      62153PANAIRfalse
      42.68.109.132
      unknownTaiwan; Republic of China (ROC)
      4249LILLY-ASUSfalse
      76.0.12.143
      unknownUnited States
      18494CENTURYLINK-LEGACY-EMBARQ-WRBGUSfalse
      83.80.167.254
      unknownNetherlands
      33915TNF-ASNLfalse
      120.20.106.82
      unknownAustralia
      133612VODAFONE-AS-APVodafoneAustraliaPtyLtdAUfalse
      82.76.185.25
      unknownRomania
      8708RCS-RDS73-75DrStaicoviciROfalse
      205.194.107.171
      unknownCanada
      3356LEVEL3USfalse
      119.63.255.29
      unknownKorea Republic of
      17577GIGAPASS-AS-KRLGHelloVisionCorpKRfalse
      95.19.35.69
      unknownSpain
      12479UNI2-ASESfalse
      169.144.15.17
      unknownUnited States
      158ERI-ASUSfalse
      8.55.105.60
      unknownUnited States
      3356LEVEL3USfalse
      107.209.55.138
      unknownUnited States
      7018ATT-INTERNET4USfalse
      202.102.100.47
      unknownChina
      137702CHINATELECOM-JIANGSU-NANJING-IDCNanjingJiangsuProvincefalse
      161.152.120.87
      unknownAustralia
      9328DATACOM-AUDATACOMSYSTEMSAUPTYLTDAUfalse
      54.21.179.8
      unknownUnited States
      14618AMAZON-AESUSfalse
      12.101.24.89
      unknownUnited States
      7018ATT-INTERNET4USfalse
      170.12.117.113
      unknownUnited States
      27283RJF-INTERNETUSfalse
      88.58.19.233
      unknownItaly
      3269ASN-IBSNAZITfalse
      125.48.186.209
      unknownJapan2516KDDIKDDICORPORATIONJPfalse
      140.234.210.128
      unknownUnited States
      6932EBSCOPUBUSfalse
      165.245.232.222
      unknownUnited States
      4668LGNET-AS-KRLGCNSKRfalse
      171.253.42.137
      unknownViet Nam
      7552VIETEL-AS-APViettelGroupVNfalse
      200.7.36.227
      unknownSint Maarten
      27734NewTechnologiesGroupNVSXfalse
      156.186.86.117
      unknownEgypt
      36992ETISALAT-MISREGfalse
      195.135.1.151
      unknownFrance
      8399SEWAN-FRfalse
      207.197.1.26
      unknownUnited States
      3851NSHE-NEVADANETUSfalse
      186.58.217.66
      unknownArgentina
      22927TelefonicadeArgentinaARfalse
      154.56.2.191
      unknownUnited States
      174COGENT-174USfalse
      62.212.29.71
      unknownItaly
      9026ULI-MAINULIITfalse
      97.121.96.184
      unknownUnited States
      209CENTURYLINK-US-LEGACY-QWESTUSfalse
      68.89.131.171
      unknownUnited States
      7018ATT-INTERNET4USfalse
      116.17.39.25
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      14.166.103.211
      unknownViet Nam
      45899VNPT-AS-VNVNPTCorpVNfalse
      150.227.240.141
      unknownSweden
      3246TDCSONGTele2BusinessTDCSwedenSEfalse
      91.113.151.22
      unknownAustria
      8447TELEKOM-ATA1TelekomAustriaAGATfalse
      4.44.24.55
      unknownUnited States
      3356LEVEL3USfalse
      156.169.238.165
      unknownEgypt
      36992ETISALAT-MISREGfalse
      163.141.21.203
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      93.120.179.216
      unknownRussian Federation
      12389ROSTELECOM-ASRUfalse
      47.0.120.15
      unknownUnited States
      34533ESAMARA-ASRUfalse
      114.170.2.111
      unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
      66.212.66.237
      unknownUnited States
      21525AS-SPLUSfalse
      196.80.15.132
      unknownMorocco
      6713IAM-ASMAfalse
      23.253.210.18
      unknownUnited States
      19994RACKSPACEUSfalse
      151.226.142.75
      unknownUnited Kingdom
      5607BSKYB-BROADBAND-ASGBfalse
      101.7.232.251
      unknownChina
      4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
      117.176.199.169
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      185.92.209.62
      unknownSwitzerland
      200879SWISSBROTHERSCHfalse
      160.172.146.38
      unknownMorocco
      6713IAM-ASMAfalse
      39.89.15.205
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      219.17.70.121
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      168.154.89.155
      unknownKorea Republic of
      10049SKNET-ASSKCoKRfalse
      40.71.135.48
      unknownUnited States
      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
      212.22.221.83
      unknownUkraine
      31148FREENET_LLCUAfalse
      202.238.46.90
      unknownJapan10001MICSNETMicsNetworkCorporationJPfalse
      152.11.76.235
      unknownUnited States
      81NCRENUSfalse
      81.222.210.53
      unknownRussian Federation
      20597ELTEL-ASRUfalse
      192.30.221.157
      unknownUnited States
      23275LM-USAUSfalse
      74.140.211.129
      unknownUnited States
      10796TWC-10796-MIDWESTUSfalse
      97.78.71.158
      unknownUnited States
      33363BHN-33363USfalse
      184.142.114.154
      unknownUnited States
      5778CENTURYLINK-LEGACY-EMBARQ-RCMTUSfalse
      93.32.193.143
      unknownItaly
      12874FASTWEBITfalse
      93.50.106.246
      unknownItaly
      12874FASTWEBITfalse
      45.143.235.203
      unknownEstonia
      39855MOD-EUNLfalse
      72.59.167.134
      unknownUnited States
      10507SPCSUSfalse
      38.200.160.186
      unknownUnited States
      174COGENT-174USfalse
      70.131.55.48
      unknownUnited States
      7018ATT-INTERNET4USfalse
      24.194.248.225
      unknownUnited States
      11351TWC-11351-NORTHEASTUSfalse
      8.166.90.215
      unknownSingapore
      37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse


      Runtime Messages

      Command:/tmp/z0x3n.x86
      Exit Code:0
      Exit Code Info:
      Killed:False
      Standard Output:
      0G0dn3t Got To Ya!
      Standard Error:

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      20.73.200.192x86Get hashmaliciousBrowse

        Domains

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext

        ASN

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        ORANGE-BUSINESS-SERVICES-IPSN-ASNFRgbk4XWulUoGet hashmaliciousBrowse
        • 212.167.164.218
        Tsunami.armGet hashmaliciousBrowse
        • 156.134.58.72
        x86Get hashmaliciousBrowse
        • 57.111.44.42
        ivImhRZqGaGet hashmaliciousBrowse
        • 57.111.19.90
        07xBxVsvEnGet hashmaliciousBrowse
        • 57.79.150.70
        wTFR3LK4MoGet hashmaliciousBrowse
        • 57.92.163.149
        bKHI9UT0D1Get hashmaliciousBrowse
        • 57.127.117.170
        eNrYzJWFvBGet hashmaliciousBrowse
        • 200.240.115.57
        GQM8qzLfFsGet hashmaliciousBrowse
        • 57.105.13.102
        sora.armGet hashmaliciousBrowse
        • 57.70.235.20
        Tf9ATzpdKRGet hashmaliciousBrowse
        • 200.226.197.191
        b3astmode.armGet hashmaliciousBrowse
        • 57.74.72.11
        yFbmGHoONEGet hashmaliciousBrowse
        • 156.134.58.77
        FWsCarsq8QGet hashmaliciousBrowse
        • 156.135.155.197
        buiodawbdawbuiopdw.x86Get hashmaliciousBrowse
        • 62.229.123.252
        arm7Get hashmaliciousBrowse
        • 57.99.202.79
        armGet hashmaliciousBrowse
        • 57.86.239.254
        arm7Get hashmaliciousBrowse
        • 156.134.58.88
        armGet hashmaliciousBrowse
        • 57.84.148.190
        sora.armGet hashmaliciousBrowse
        • 57.117.171.166
        LEVEL3USz0x3n.armGet hashmaliciousBrowse
        • 4.77.193.187
        jGVlUAzDbQGet hashmaliciousBrowse
        • 138.12.216.235
        ev1JsPbdMAGet hashmaliciousBrowse
        • 138.12.216.253
        QZ2CN6CUyvGet hashmaliciousBrowse
        • 9.162.77.202
        Xs0PMn85CNGet hashmaliciousBrowse
        • 4.7.177.40
        x86Get hashmaliciousBrowse
        • 216.141.213.58
        KXAJjgoH22Get hashmaliciousBrowse
        • 4.45.235.181
        Z7QqCH0bakGet hashmaliciousBrowse
        • 157.199.162.106
        zouBbQwUTbGet hashmaliciousBrowse
        • 9.44.191.61
        x86_64Get hashmaliciousBrowse
        • 64.154.123.164
        U1WRbn3wOaGet hashmaliciousBrowse
        • 9.152.52.161
        RVG73cR3DPGet hashmaliciousBrowse
        • 4.136.211.76
        9QPGr9LMaqGet hashmaliciousBrowse
        • 206.33.161.35
        32UX3eB2m0Get hashmaliciousBrowse
        • 9.169.60.90
        jJ6GK5qbZtGet hashmaliciousBrowse
        • 4.125.80.128
        x86Get hashmaliciousBrowse
        • 166.90.237.153
        hvYTLlrdRmGet hashmaliciousBrowse
        • 4.204.173.89
        1b5356SnwBGet hashmaliciousBrowse
        • 75.103.49.235
        vEBWe85OY5Get hashmaliciousBrowse
        • 8.196.29.107
        S1WMHUXAQUGet hashmaliciousBrowse
        • 4.234.132.186
        CMNET-GDGuangdongMobileCommunicationCoLtdCNQZ2CN6CUyvGet hashmaliciousBrowse
        • 183.224.188.131
        x86Get hashmaliciousBrowse
        • 183.255.19.37
        ivImhRZqGaGet hashmaliciousBrowse
        • 117.139.191.41
        Z7QqCH0bakGet hashmaliciousBrowse
        • 36.175.118.55
        PpZvxl4DJgGet hashmaliciousBrowse
        • 36.164.147.131
        arm7Get hashmaliciousBrowse
        • 117.187.200.202
        U1WRbn3wOaGet hashmaliciousBrowse
        • 112.47.118.185
        RVG73cR3DPGet hashmaliciousBrowse
        • 39.131.235.1
        hvYTLlrdRmGet hashmaliciousBrowse
        • 123.82.185.223
        2pPPNW1XSoGet hashmaliciousBrowse
        • 112.50.147.80
        S1WMHUXAQUGet hashmaliciousBrowse
        • 117.150.97.40
        st2AAeCXsRGet hashmaliciousBrowse
        • 112.31.237.169
        OklOTajM3X.exeGet hashmaliciousBrowse
        • 111.12.28.24
        mdyu2wtnR8Get hashmaliciousBrowse
        • 36.167.38.135
        egd7wSpaw2Get hashmaliciousBrowse
        • 39.133.46.94
        KfvEoN0wIwGet hashmaliciousBrowse
        • 223.75.114.193
        Xb1sM3W7BKGet hashmaliciousBrowse
        • 111.28.163.155
        txwaNf62fvGet hashmaliciousBrowse
        • 122.77.200.46
        nLfUJu0kEAGet hashmaliciousBrowse
        • 223.82.2.220
        K1fia4oWepGet hashmaliciousBrowse
        • 111.60.197.135

        JA3 Fingerprints

        No context

        Dropped Files

        No context

        Created / dropped Files

        No created / dropped files found

        Static File Info

        General

        File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
        Entropy (8bit):6.455104594575481
        TrID:
        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
        File name:z0x3n.x86
        File size:63664
        MD5:c2c1c54bbc5f372df082aebc0d983716
        SHA1:2c9ebbad068ea09d2fcf7cfff48608a8abdf4337
        SHA256:dd9c8a7d71f944ded984394fcc021043403e3a39ef424d70d2a3a18c3b58b69d
        SHA512:dfd1c9ad3a1da9d190717f77e407774d2b9bd68986fdeb3fd7dff3bd7d8852311d5df9eb1d0f350e4d221d9b494f00afc128e3a2ef3f96e67456020e6f73dfa2
        SSDEEP:1536:WuIDGwqmkZxXP5XM4wCadEzKC18HqmPWJBus0eD/OQAy9T:PIDsbZxf5XM4wCq0zCHqpEs5/22
        File Content Preview:.ELF....................d...4... .......4. ...(.....................................................\...\...........Q.td............................U..S............h........[]...$.............U......=.....t..5...................u........t....h.u..........

        Static ELF Info

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:Intel 80386
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:UNIX - System V
        ABI Version:0
        Entry Point Address:0x8048164
        Flags:0x0
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:3
        Section Header Offset:63264
        Section Header Size:40
        Number of Section Headers:10
        Header String Table Index:9

        Sections

        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .initPROGBITS0x80480940x940x1c0x00x6AX001
        .textPROGBITS0x80480b00xb00xe6360x00x6AX0016
        .finiPROGBITS0x80566e60xe6e60x170x00x6AX001
        .rodataPROGBITS0x80567000xe7000xe800x00x2A0032
        .ctorsPROGBITS0x80585840xf5840x80x00x3WA004
        .dtorsPROGBITS0x805858c0xf58c0x80x00x3WA004
        .dataPROGBITS0x80585c00xf5c00x1200x00x3WA0032
        .bssNOBITS0x80586e00xf6e00x8000x00x3WA0032
        .shstrtabSTRTAB0x00xf6e00x3e0x00x0001

        Program Segments

        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x80480000x80480000xf5800xf5803.78420x5R E0x1000.init .text .fini .rodata
        LOAD0xf5840x80585840x80585840x15c0x95c2.44700x6RW 0x1000.ctors .dtors .data .bss
        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

        Network Behavior

        Network Port Distribution

        TCP Packets

        TimestampSource PortDest PortSource IPDest IP
        Nov 1, 2021 08:54:44.494484901 CET2308623192.168.2.23103.61.176.109
        Nov 1, 2021 08:54:44.494487047 CET230862323192.168.2.2347.1.101.157
        Nov 1, 2021 08:54:44.494514942 CET2308623192.168.2.23182.193.240.200
        Nov 1, 2021 08:54:44.494519949 CET2308623192.168.2.2384.203.31.69
        Nov 1, 2021 08:54:44.494525909 CET2308623192.168.2.23149.100.205.117
        Nov 1, 2021 08:54:44.494533062 CET2308623192.168.2.23210.212.65.221
        Nov 1, 2021 08:54:44.494535923 CET2308623192.168.2.23136.162.110.105
        Nov 1, 2021 08:54:44.494556904 CET2308623192.168.2.2336.119.11.175
        Nov 1, 2021 08:54:44.494566917 CET230862323192.168.2.23125.229.138.235
        Nov 1, 2021 08:54:44.494570017 CET2308623192.168.2.2377.163.249.232
        Nov 1, 2021 08:54:44.494575977 CET2308623192.168.2.23196.101.75.42
        Nov 1, 2021 08:54:44.494575024 CET2308623192.168.2.2354.128.144.224
        Nov 1, 2021 08:54:44.494580984 CET2308623192.168.2.2395.44.64.51
        Nov 1, 2021 08:54:44.494581938 CET2308623192.168.2.2362.169.67.211
        Nov 1, 2021 08:54:44.494589090 CET2308623192.168.2.2387.194.59.225
        Nov 1, 2021 08:54:44.494595051 CET2308623192.168.2.2367.228.183.69
        Nov 1, 2021 08:54:44.494599104 CET2308623192.168.2.2317.253.179.71
        Nov 1, 2021 08:54:44.494615078 CET2308623192.168.2.23102.71.3.185
        Nov 1, 2021 08:54:44.494621038 CET2308623192.168.2.2391.111.19.201
        Nov 1, 2021 08:54:44.494625092 CET2308623192.168.2.2357.236.55.216
        Nov 1, 2021 08:54:44.494630098 CET2308623192.168.2.23166.150.88.190
        Nov 1, 2021 08:54:44.494633913 CET2308623192.168.2.2394.231.7.73
        Nov 1, 2021 08:54:44.494637966 CET2308623192.168.2.23114.112.47.159
        Nov 1, 2021 08:54:44.494642973 CET2308623192.168.2.23117.90.192.120
        Nov 1, 2021 08:54:44.494652987 CET2308623192.168.2.23135.2.225.206
        Nov 1, 2021 08:54:44.494654894 CET2308623192.168.2.23168.144.25.169
        Nov 1, 2021 08:54:44.494666100 CET2308623192.168.2.2371.158.19.146
        Nov 1, 2021 08:54:44.494669914 CET2308623192.168.2.23208.151.213.102
        Nov 1, 2021 08:54:44.494676113 CET2308623192.168.2.2381.95.135.55
        Nov 1, 2021 08:54:44.494678974 CET2308623192.168.2.23169.26.177.164
        Nov 1, 2021 08:54:44.494688034 CET2308623192.168.2.2399.11.81.41
        Nov 1, 2021 08:54:44.494695902 CET230862323192.168.2.23105.13.231.165
        Nov 1, 2021 08:54:44.494703054 CET2308623192.168.2.23142.110.219.84
        Nov 1, 2021 08:54:44.494710922 CET2308623192.168.2.2390.180.225.184
        Nov 1, 2021 08:54:44.494718075 CET230862323192.168.2.23213.147.72.17
        Nov 1, 2021 08:54:44.494728088 CET2308623192.168.2.2388.133.77.153
        Nov 1, 2021 08:54:44.494735956 CET2308623192.168.2.2313.144.12.20
        Nov 1, 2021 08:54:44.494744062 CET2308623192.168.2.239.113.2.215
        Nov 1, 2021 08:54:44.494829893 CET230862323192.168.2.23192.182.27.143
        Nov 1, 2021 08:54:44.494848967 CET2308623192.168.2.2393.147.13.9
        Nov 1, 2021 08:54:44.494860888 CET2308623192.168.2.23157.248.119.132
        Nov 1, 2021 08:54:44.494879961 CET2308623192.168.2.2341.244.119.157
        Nov 1, 2021 08:54:44.494893074 CET2308623192.168.2.2338.231.100.31
        Nov 1, 2021 08:54:44.494894028 CET2308623192.168.2.23177.126.89.178
        Nov 1, 2021 08:54:44.494899035 CET2308623192.168.2.23175.29.25.120
        Nov 1, 2021 08:54:44.494900942 CET2308623192.168.2.23168.96.135.118
        Nov 1, 2021 08:54:44.494904041 CET2308623192.168.2.2379.144.135.159
        Nov 1, 2021 08:54:44.494908094 CET2308623192.168.2.2323.203.110.240
        Nov 1, 2021 08:54:44.494913101 CET2308623192.168.2.23192.39.107.5
        Nov 1, 2021 08:54:44.494920015 CET2308623192.168.2.23207.200.60.116
        Nov 1, 2021 08:54:44.494921923 CET2308623192.168.2.23106.9.22.179
        Nov 1, 2021 08:54:44.494925022 CET2308623192.168.2.23168.188.118.67
        Nov 1, 2021 08:54:44.494931936 CET2308623192.168.2.23172.101.143.80
        Nov 1, 2021 08:54:44.494940042 CET2308623192.168.2.2390.36.198.213
        Nov 1, 2021 08:54:44.494940996 CET2308623192.168.2.2395.37.84.8
        Nov 1, 2021 08:54:44.494944096 CET2308623192.168.2.23148.113.199.84
        Nov 1, 2021 08:54:44.494947910 CET230862323192.168.2.2337.37.20.176
        Nov 1, 2021 08:54:44.494949102 CET2308623192.168.2.23211.135.191.116
        Nov 1, 2021 08:54:44.494950056 CET2308623192.168.2.2343.25.49.174
        Nov 1, 2021 08:54:44.494956017 CET2308623192.168.2.23220.180.220.136
        Nov 1, 2021 08:54:44.494956970 CET2308623192.168.2.23144.38.62.167
        Nov 1, 2021 08:54:44.494960070 CET2308623192.168.2.23206.178.246.74
        Nov 1, 2021 08:54:44.494961977 CET2308623192.168.2.23204.247.180.235
        Nov 1, 2021 08:54:44.494961977 CET2308623192.168.2.2391.81.206.80
        Nov 1, 2021 08:54:44.494967937 CET2308623192.168.2.23173.235.156.192
        Nov 1, 2021 08:54:44.494971037 CET2308623192.168.2.23181.168.181.208
        Nov 1, 2021 08:54:44.494976044 CET2308623192.168.2.23194.175.77.180
        Nov 1, 2021 08:54:44.494981050 CET230862323192.168.2.23181.70.39.27
        Nov 1, 2021 08:54:44.494985104 CET2308623192.168.2.23135.80.10.226
        Nov 1, 2021 08:54:44.494987011 CET2308623192.168.2.2370.111.162.198
        Nov 1, 2021 08:54:44.494987965 CET2308623192.168.2.23191.65.249.239
        Nov 1, 2021 08:54:44.494990110 CET2308623192.168.2.23219.75.195.252
        Nov 1, 2021 08:54:44.494997025 CET2308623192.168.2.23219.50.175.75
        Nov 1, 2021 08:54:44.494997978 CET2308623192.168.2.2353.46.48.214
        Nov 1, 2021 08:54:44.494998932 CET2308623192.168.2.23199.2.2.244
        Nov 1, 2021 08:54:44.495001078 CET2308623192.168.2.23105.195.34.226
        Nov 1, 2021 08:54:44.495006084 CET230862323192.168.2.2368.190.30.118
        Nov 1, 2021 08:54:44.495008945 CET230862323192.168.2.23156.58.60.49
        Nov 1, 2021 08:54:44.495011091 CET230862323192.168.2.23169.159.209.10
        Nov 1, 2021 08:54:44.495012999 CET2308623192.168.2.23159.153.1.91
        Nov 1, 2021 08:54:44.495014906 CET2308623192.168.2.23130.16.13.39
        Nov 1, 2021 08:54:44.495016098 CET2308623192.168.2.2384.240.21.120
        Nov 1, 2021 08:54:44.495018959 CET2308623192.168.2.23202.86.191.141
        Nov 1, 2021 08:54:44.495019913 CET2308623192.168.2.23113.184.232.18
        Nov 1, 2021 08:54:44.495021105 CET2308623192.168.2.2396.122.148.73
        Nov 1, 2021 08:54:44.495024920 CET2308623192.168.2.23169.99.97.134
        Nov 1, 2021 08:54:44.495024920 CET2308623192.168.2.23118.25.39.241
        Nov 1, 2021 08:54:44.495028973 CET2308623192.168.2.2380.240.39.202
        Nov 1, 2021 08:54:44.495028973 CET2308623192.168.2.23151.170.136.79
        Nov 1, 2021 08:54:44.495028973 CET2308623192.168.2.23209.117.244.238
        Nov 1, 2021 08:54:44.495031118 CET2308623192.168.2.23213.90.218.55
        Nov 1, 2021 08:54:44.495037079 CET2308623192.168.2.2389.229.157.236
        Nov 1, 2021 08:54:44.495039940 CET2308623192.168.2.23197.64.130.104
        Nov 1, 2021 08:54:44.495047092 CET2308623192.168.2.2395.233.233.99
        Nov 1, 2021 08:54:44.495049000 CET2308623192.168.2.23161.107.177.4
        Nov 1, 2021 08:54:44.495053053 CET2308623192.168.2.23145.45.101.231
        Nov 1, 2021 08:54:44.495058060 CET2308623192.168.2.2317.168.180.243
        Nov 1, 2021 08:54:44.495059967 CET2308623192.168.2.23138.245.62.181
        Nov 1, 2021 08:54:44.495066881 CET230862323192.168.2.2386.0.55.109
        Nov 1, 2021 08:54:44.495070934 CET2308623192.168.2.23158.220.84.116

        DNS Queries

        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
        Nov 1, 2021 08:54:44.484302044 CET192.168.2.238.8.8.80xee26Standard query (0)z0x3n.cfA (IP address)IN (0x0001)

        DNS Answers

        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
        Nov 1, 2021 08:54:44.512578011 CET8.8.8.8192.168.2.230xee26No error (0)z0x3n.cf37.0.10.67A (IP address)IN (0x0001)

        System Behavior

        General

        Start time:08:54:44
        Start date:01/11/2021
        Path:/tmp/z0x3n.x86
        Arguments:/tmp/z0x3n.x86
        File size:63664 bytes
        MD5 hash:c2c1c54bbc5f372df082aebc0d983716

        General

        Start time:08:54:44
        Start date:01/11/2021
        Path:/tmp/z0x3n.x86
        Arguments:n/a
        File size:63664 bytes
        MD5 hash:c2c1c54bbc5f372df082aebc0d983716

        General

        Start time:08:54:44
        Start date:01/11/2021
        Path:/tmp/z0x3n.x86
        Arguments:n/a
        File size:63664 bytes
        MD5 hash:c2c1c54bbc5f372df082aebc0d983716

        General

        Start time:08:54:44
        Start date:01/11/2021
        Path:/tmp/z0x3n.x86
        Arguments:n/a
        File size:63664 bytes
        MD5 hash:c2c1c54bbc5f372df082aebc0d983716

        General

        Start time:08:54:44
        Start date:01/11/2021
        Path:/tmp/z0x3n.x86
        Arguments:n/a
        File size:63664 bytes
        MD5 hash:c2c1c54bbc5f372df082aebc0d983716

        General

        Start time:08:54:44
        Start date:01/11/2021
        Path:/tmp/z0x3n.x86
        Arguments:n/a
        File size:63664 bytes
        MD5 hash:c2c1c54bbc5f372df082aebc0d983716