Loading ...

Play interactive tourEdit tour

Linux Analysis Report V2WzER53Tt

Overview

General Information

Sample Name:V2WzER53Tt
Analysis ID:512648
MD5:4b0259083c8800d18cb941c66639a2e6
SHA1:f58aa2b927047749395a47b16b458f5220d19f3a
SHA256:7feef5ad07bad632f6440d1fb5e0aaf9464fe27eb7ea5e489ae4f79bfee5b2ea
Tags:32elfintelmirai
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Uses known network protocols on non-standard ports
Machine Learning detection for sample
Yara signature match
Sample has stripped symbol table
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports

Classification

Analysis Advice

All HTTP servers contacted by the sample do not answer. Likely the sample is an old dropper which does no longer work

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:512648
Start date:01.11.2021
Start time:09:42:44
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:V2WzER53Tt
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.troj.lin@0/0@1/0
Warnings:
Show All
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100

Process Tree

  • system is lnxubuntu20
  • V2WzER53Tt (PID: 5240, Parent: 5115, MD5: 4b0259083c8800d18cb941c66639a2e6) Arguments: /tmp/V2WzER53Tt
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
V2WzER53TtSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
  • 0x10ba8:$xo1: Dfs`eeh&<'9
  • 0x10c20:$xo1: Dfs`eeh&<'9
  • 0x10c94:$xo1: Dfs`eeh&<'9
  • 0x10d04:$xo1: Dfs`eeh&<'9
  • 0x10d50:$xo1: Dfs`eeh&<'9

PCAP (Network Traffic)

SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security

    Memory Dumps

    SourceRuleDescriptionAuthorStrings
    5241.1.000000007fd4a080.0000000002b07ef2.rw-.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x6d0:$xo1: Dfs`eeh&<'9
    • 0x750:$xo1: Dfs`eeh&<'9
    • 0x7c8:$xo1: Dfs`eeh&<'9
    • 0x840:$xo1: Dfs`eeh&<'9
    • 0x890:$xo1: Dfs`eeh&<'9
    5240.1.000000001a887bdc.0000000019a04c35.r-x.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x10ba8:$xo1: Dfs`eeh&<'9
    • 0x10c20:$xo1: Dfs`eeh&<'9
    • 0x10c94:$xo1: Dfs`eeh&<'9
    • 0x10d04:$xo1: Dfs`eeh&<'9
    • 0x10d50:$xo1: Dfs`eeh&<'9
    5243.1.000000007fd4a080.0000000002b07ef2.rw-.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x6d0:$xo1: Dfs`eeh&<'9
    • 0x750:$xo1: Dfs`eeh&<'9
    • 0x7c8:$xo1: Dfs`eeh&<'9
    • 0x840:$xo1: Dfs`eeh&<'9
    • 0x890:$xo1: Dfs`eeh&<'9
    5243.1.000000001a887bdc.0000000019a04c35.r-x.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x10ba8:$xo1: Dfs`eeh&<'9
    • 0x10c20:$xo1: Dfs`eeh&<'9
    • 0x10c94:$xo1: Dfs`eeh&<'9
    • 0x10d04:$xo1: Dfs`eeh&<'9
    • 0x10d50:$xo1: Dfs`eeh&<'9
    5240.1.000000007fd4a080.0000000002b07ef2.rw-.sdmpSUSP_XORed_MozillaDetects suspicious XORed keyword - Mozilla/5.0Florian Roth
    • 0x6d0:$xo1: Dfs`eeh&<'9
    • 0x750:$xo1: Dfs`eeh&<'9
    • 0x7c8:$xo1: Dfs`eeh&<'9
    • 0x840:$xo1: Dfs`eeh&<'9
    • 0x890:$xo1: Dfs`eeh&<'9
    Click to see the 1 entries

    Jbx Signature Overview

    Click to jump to signature section

    Show All Signature Results

    AV Detection:

    barindex
    Multi AV Scanner detection for submitted fileShow sources
    Source: V2WzER53TtVirustotal: Detection: 32%Perma Link
    Source: V2WzER53TtReversingLabs: Detection: 40%
    Machine Learning detection for sampleShow sources
    Source: V2WzER53TtJoe Sandbox ML: detected

    Networking:

    barindex
    Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
    Source: TrafficSnort IDS: 2023442 ET TROJAN Possible Linux.Mirai Login Attempt (jvbzd) 192.168.2.23:33852 -> 185.39.46.82:23
    Source: TrafficSnort IDS: 2023436 ET TROJAN Possible Linux.Mirai Login Attempt (anko) 192.168.2.23:33866 -> 185.39.46.82:23
    Source: TrafficSnort IDS: 2025080 ET EXPLOIT Actiontec C1000A backdoor account M1 192.168.2.23:33876 -> 185.39.46.82:23
    Source: TrafficSnort IDS: 2023447 ET TROJAN Possible Linux.Mirai Login Attempt (service) 192.168.2.23:33986 -> 185.39.46.82:23
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.15.248.60:23 -> 192.168.2.23:42578
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.15.248.60:23 -> 192.168.2.23:42578
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38026
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38046
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.15.248.60:23 -> 192.168.2.23:42676
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.15.248.60:23 -> 192.168.2.23:42676
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38088
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38122
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38150
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38166
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.15.248.60:23 -> 192.168.2.23:42768
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.15.248.60:23 -> 192.168.2.23:42768
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38176
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38190
    Source: TrafficSnort IDS: 716 INFO TELNET access 59.11.190.116:23 -> 192.168.2.23:57452
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38266
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.15.248.60:23 -> 192.168.2.23:42844
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.15.248.60:23 -> 192.168.2.23:42844
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.11.190.116:23 -> 192.168.2.23:57452
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.11.190.116:23 -> 192.168.2.23:57452
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38386
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38536
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38614
    Source: TrafficSnort IDS: 716 INFO TELNET access 59.11.190.116:23 -> 192.168.2.23:57858
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 190.15.248.60:23 -> 192.168.2.23:43250
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 190.15.248.60:23 -> 192.168.2.23:43250
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38680
    Source: TrafficSnort IDS: 1251 INFO TELNET Bad Login 59.11.190.116:23 -> 192.168.2.23:57858
    Source: TrafficSnort IDS: 718 INFO TELNET login incorrect 59.11.190.116:23 -> 192.168.2.23:57858
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38748
    Source: TrafficSnort IDS: 2023447 ET TROJAN Possible Linux.Mirai Login Attempt (service) 192.168.2.23:56502 -> 73.222.54.242:23
    Source: TrafficSnort IDS: 716 INFO TELNET access 190.167.54.164:23 -> 192.168.2.23:38754
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46368
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46372
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46376
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46380
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46386
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46400
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46410
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46418
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46432
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46438
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46442
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46448
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46466
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46472
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46490
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46496
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46500
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46510
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46514
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46516
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46520
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46522
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46524
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46528
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46532
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46536
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46540
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46544
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46546
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 65.76.10.157:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 165.114.154.251:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 123.237.191.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 83.117.106.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 97.203.48.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 109.40.137.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 37.52.25.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 203.161.129.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 196.2.10.111:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 218.131.219.131:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 202.79.107.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 66.22.135.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 35.200.224.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 101.53.9.206:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 105.211.70.13:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 71.221.179.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:60692 -> 37.0.10.67:11199
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 207.144.169.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 183.170.11.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 69.4.243.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 116.241.74.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 23.246.65.17:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 159.149.105.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 27.33.205.213:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 117.221.60.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 59.19.40.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 79.136.134.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 9.90.137.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 63.3.167.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 114.1.76.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 194.47.176.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 222.188.203.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 199.62.227.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 200.57.216.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 32.209.212.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 154.177.29.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 168.44.23.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 147.125.149.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 200.56.74.170:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 151.50.187.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 222.186.12.248:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 145.184.127.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 150.216.210.28:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 157.129.82.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 23.22.55.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 179.227.239.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 104.123.15.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 75.39.28.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 57.52.163.46:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 174.201.137.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 210.67.45.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 74.246.114.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 146.163.132.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 164.152.174.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 148.145.81.94:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 58.147.143.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 63.27.44.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 8.55.233.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 208.126.224.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 138.247.188.84:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 102.129.135.74:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 157.143.20.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 70.43.43.57:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 204.17.234.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 218.2.33.78:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 190.174.61.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 117.15.100.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 152.35.148.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 14.83.182.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 170.186.60.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 48.190.228.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 149.83.197.69:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 82.151.48.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 158.204.117.47:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 204.96.192.8:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 163.115.111.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 31.149.45.109:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 133.33.180.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 23.29.105.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 124.72.58.132:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 193.77.103.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 14.1.4.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 113.139.214.27:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 1.43.238.23:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 18.77.20.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 167.98.13.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 146.215.192.137:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 150.1.192.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 47.116.84.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 115.228.86.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 120.109.8.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 159.190.219.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 47.213.133.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 191.222.64.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 151.97.35.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 111.22.195.65:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 70.138.137.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 98.10.102.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 209.208.85.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 71.119.79.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 119.227.148.39:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 210.184.29.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 112.237.207.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 12.119.80.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 66.112.164.22:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 23.235.13.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 147.74.178.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 17.126.20.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 114.7.181.130:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 161.151.95.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 4.127.79.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 152.4.231.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 108.115.191.96:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 67.23.204.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 153.165.107.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 110.21.4.75:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 158.48.126.192:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 18.231.131.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 198.249.146.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 217.207.74.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 146.51.182.26:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 195.123.14.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 79.215.144.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 39.241.91.225:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 111.166.55.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 44.42.192.164:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 106.120.22.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 200.87.115.3:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 20.61.158.77:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 81.59.196.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 13.69.244.102:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 169.35.221.113:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 129.20.217.228:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 197.117.105.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 95.102.165.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 115.150.130.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 2.198.60.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 32.196.117.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 182.217.191.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 109.27.200.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 42.214.24.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 120.227.141.93:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 198.74.227.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 118.103.154.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 152.182.104.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 8.56.9.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 177.157.180.178:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 210.240.34.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 165.40.57.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 222.224.4.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 201.109.167.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 210.168.11.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 198.22.227.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 74.129.206.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 70.61.31.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 57.157.146.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 86.111.234.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 112.159.128.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 222.32.200.222:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 209.167.211.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 194.170.231.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 67.5.218.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 186.108.42.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 212.73.174.231:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 199.6.122.180:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.22.20.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 96.224.163.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 18.159.5.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 114.161.88.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 90.67.77.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 46.146.141.41:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 62.239.250.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 27.89.110.193:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 147.83.154.28:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 183.207.230.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 165.87.219.25:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 173.161.220.66:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 100.247.153.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 136.53.213.129:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 205.129.161.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 81.168.208.156:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 185.113.18.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 31.248.224.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 126.183.192.218:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 124.78.0.229:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 95.167.189.29:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 75.3.190.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 45.215.191.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 69.70.60.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 157.207.146.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 67.150.192.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 117.196.169.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 143.8.157.12:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 152.6.12.186:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 208.15.98.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 164.80.226.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 135.94.138.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 47.194.146.61:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 123.54.199.87:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 38.209.244.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 204.133.219.76:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 116.20.236.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 182.27.197.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 213.88.77.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 103.169.82.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 223.82.84.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 135.216.163.214:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 89.22.48.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.109.43.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 159.199.171.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 198.194.108.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 101.239.25.37:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 143.15.89.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 4.154.206.95:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 58.2.215.0:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 151.79.119.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 66.240.86.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 208.250.114.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 111.210.127.122:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 82.131.27.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 81.28.55.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 61.14.235.254:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 81.164.63.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 45.60.70.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 208.94.77.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 206.122.50.94:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.61.176.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 191.78.70.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 95.203.143.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 141.144.227.206:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 73.158.8.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 168.225.138.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 120.166.59.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 81.85.61.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 68.53.181.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 157.60.147.126:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 100.225.249.30:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 39.83.70.92:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 142.109.19.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 82.61.172.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 174.190.163.236:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 175.137.11.187:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 93.152.46.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 108.91.8.98:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.49.19.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 180.213.17.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 157.8.172.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 173.84.6.155:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 95.73.199.143:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 5.64.67.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 124.14.139.74:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 158.147.114.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 111.15.155.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 80.83.52.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 86.242.21.117:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 186.189.83.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 91.7.11.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 59.52.63.246:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 151.205.78.124:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 150.94.6.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 105.186.240.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 209.239.139.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 168.202.83.120:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 122.230.150.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 156.231.243.191:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 220.112.198.46:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 114.223.153.58:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 123.170.237.40:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.63.123.72:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 75.61.7.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 145.128.53.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 110.58.217.10:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 108.34.220.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 169.60.112.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 173.191.147.20:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 177.43.244.60:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 151.184.125.137:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 72.113.79.237:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 147.208.39.41:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 5.121.41.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 177.75.7.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 164.36.211.119:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 110.213.167.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 222.20.164.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 156.218.158.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 189.66.30.2:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.33.192.185:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 73.105.249.11:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 93.192.217.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 194.48.108.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 142.46.246.198:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 58.213.40.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 183.215.194.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 48.8.254.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 175.46.235.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 177.39.88.202:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 40.136.33.67:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 185.250.11.201:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 40.99.118.161:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 60.92.25.121:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 105.76.57.179:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 98.133.228.148:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 58.0.165.109:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 136.119.128.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 78.216.176.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 48.201.213.16:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 69.124.102.42:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 194.126.197.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 159.206.71.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 217.48.65.207:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 130.210.252.115:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 97.181.93.217:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 117.37.143.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 78.222.39.81:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 117.14.114.249:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 67.178.136.169:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 32.54.156.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 181.250.225.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 85.132.37.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 166.213.222.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 158.203.113.130:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 151.242.108.9:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 145.11.190.108:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 194.24.29.34:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 179.45.19.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 216.130.19.235:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 152.127.232.52:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 105.49.17.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 44.177.6.133:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 80.33.45.99:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 126.22.159.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 34.170.68.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 75.16.73.82:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 96.151.219.171:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 43.14.161.221:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 185.54.34.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 115.170.206.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 179.41.233.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 177.46.19.194:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 38.251.105.123:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 201.245.42.38:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 161.27.177.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 196.18.240.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 191.72.43.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 165.132.158.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 83.74.252.208:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 67.76.152.6:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 102.39.253.35:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 119.21.150.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 177.80.255.175:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 210.194.144.205:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 103.220.103.148:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 222.194.231.154:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 146.150.114.238:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 104.130.141.255:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 95.59.74.158:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 197.198.212.220:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 212.91.131.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 45.85.126.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 2.183.236.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 82.93.184.253:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 43.107.236.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 88.27.227.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 220.168.194.163:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 53.199.224.139:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 113.9.221.14:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 150.216.4.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 162.33.93.170:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 48.254.28.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 181.154.254.138:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 212.154.126.198:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 59.30.48.62:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 150.208.20.91:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 45.92.221.160:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 156.229.64.253:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 69.0.5.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 60.145.238.230:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 126.41.198.17:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 38.121.126.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 65.184.73.181:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 156.237.17.31:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 207.187.40.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 74.236.93.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 82.86.217.184:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 110.149.49.73:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 18.28.43.165:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 96.237.200.134:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 219.105.248.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 188.13.139.4:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 159.61.48.19:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 188.237.94.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.41.246.187:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 124.167.72.144:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 164.196.89.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 161.138.241.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 169.234.94.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 148.108.101.239:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 187.68.47.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 67.145.52.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 4.224.226.242:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 116.222.75.85:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 196.160.180.114:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 104.103.170.15:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 122.182.218.172:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 145.89.169.78:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 126.55.13.198:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 88.87.134.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 13.64.131.82:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 77.196.229.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 139.193.141.153:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 146.202.89.189:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 104.140.237.141:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 121.46.65.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 13.205.133.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 160.128.120.7:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 68.207.149.33:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 174.42.166.71:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 166.28.58.199:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 1.18.133.200:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 216.212.78.240:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 205.230.107.162:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 86.93.47.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 212.163.140.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 1.64.64.216:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 77.178.201.87:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 62.47.152.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 31.178.86.54:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 118.42.71.245:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 176.102.70.87:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 147.125.123.233:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 41.13.105.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 191.94.55.250:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 85.203.218.70:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 62.30.0.97:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 147.68.89.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 14.130.109.63:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 63.229.112.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 43.51.43.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 199.62.90.148:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 202.67.81.142:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 217.183.240.100:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 193.107.222.167:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 165.108.255.148:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 9.234.36.244:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 177.98.192.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 69.171.238.232:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 60.114.105.224:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 97.128.136.88:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 179.26.249.136:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 151.31.91.147:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 44.88.159.211:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 1.253.7.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 69.19.70.112:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 31.157.248.45:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 201.192.221.104:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 18.237.63.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 109.250.191.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 188.70.123.168:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 123.220.19.174:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 40.188.6.89:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 74.223.9.188:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 178.72.170.56:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 157.145.177.50:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 163.79.102.64:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 179.93.184.107:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 27.12.195.227:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 68.191.123.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 173.134.60.140:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 149.59.255.212:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 196.129.79.177:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 94.195.154.110:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 102.209.169.209:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 13.230.170.176:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 85.90.180.226:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 71.213.42.206:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 222.106.15.223:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 68.210.226.51:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 109.187.92.55:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 166.21.229.109:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 60.13.48.197:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 211.215.86.170:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 206.206.190.18:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 153.36.91.80:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 47.238.47.5:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 121.133.13.32:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 108.230.103.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 70.237.139.247:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 24.108.145.106:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 69.169.81.128:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 122.125.153.135:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 57.3.233.190:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 113.79.225.101:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 73.64.36.182:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 221.53.243.179:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 53.220.208.224:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 102.187.248.68:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 99.60.194.127:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 24.176.72.196:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 205.188.196.90:2323
    Source: global trafficTCP traffic: 192.168.2.23:63108 -> 100.52.31.140:2323
    Source: unknownDNS traffic detected: queries for: z0x3n.cf
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: unknownTCP traffic detected without corresponding DNS query: 68.151.86.156
    Source: unknownTCP traffic detected without corresponding DNS query: 1.31.45.62
    Source: unknownTCP traffic detected without corresponding DNS query: 124.50.255.107
    Source: unknownTCP traffic detected without corresponding DNS query: 187.200.47.75
    Source: unknownTCP traffic detected without corresponding DNS query: 96.27.91.97
    Source: unknownTCP traffic detected without corresponding DNS query: 54.141.130.19
    Source: unknownTCP traffic detected without corresponding DNS query: 156.232.194.44
    Source: unknownTCP traffic detected without corresponding DNS query: 14.60.219.36
    Source: unknownTCP traffic detected without corresponding DNS query: 80.66.92.95
    Source: unknownTCP traffic detected without corresponding DNS query: 121.11.62.135
    Source: unknownTCP traffic detected without corresponding DNS query: 165.114.154.251
    Source: unknownTCP traffic detected without corresponding DNS query: 77.197.61.153
    Source: unknownTCP traffic detected without corresponding DNS query: 104.125.179.179
    Source: unknownTCP traffic detected without corresponding DNS query: 47.78.75.38
    Source: unknownTCP traffic detected without corresponding DNS query: 159.147.207.244
    Source: unknownTCP traffic detected without corresponding DNS query: 24.74.123.108
    Source: unknownTCP traffic detected without corresponding DNS query: 144.62.250.181
    Source: unknownTCP traffic detected without corresponding DNS query: 160.96.29.164
    Source: unknownTCP traffic detected without corresponding DNS query: 183.2.65.125
    Source: unknownTCP traffic detected without corresponding DNS query: 161.89.115.135
    Source: unknownTCP traffic detected without corresponding DNS query: 4.215.32.161
    Source: unknownTCP traffic detected without corresponding DNS query: 53.222.122.229
    Source: unknownTCP traffic detected without corresponding DNS query: 186.217.153.216
    Source: unknownTCP traffic detected without corresponding DNS query: 126.175.225.244
    Source: unknownTCP traffic detected without corresponding DNS query: 95.136.38.80
    Source: unknownTCP traffic detected without corresponding DNS query: 84.23.168.34
    Source: unknownTCP traffic detected without corresponding DNS query: 149.141.117.70
    Source: unknownTCP traffic detected without corresponding DNS query: 123.237.191.254
    Source: unknownTCP traffic detected without corresponding DNS query: 159.45.79.76
    Source: unknownTCP traffic detected without corresponding DNS query: 118.70.160.208
    Source: unknownTCP traffic detected without corresponding DNS query: 83.117.106.174
    Source: unknownTCP traffic detected without corresponding DNS query: 160.130.94.1
    Source: unknownTCP traffic detected without corresponding DNS query: 188.214.26.137
    Source: unknownTCP traffic detected without corresponding DNS query: 186.99.167.244
    Source: unknownTCP traffic detected without corresponding DNS query: 121.69.134.116
    Source: unknownTCP traffic detected without corresponding DNS query: 148.34.102.50
    Source: unknownTCP traffic detected without corresponding DNS query: 99.207.115.45
    Source: unknownTCP traffic detected without corresponding DNS query: 216.90.237.233
    Source: unknownTCP traffic detected without corresponding DNS query: 212.145.133.178
    Source: unknownTCP traffic detected without corresponding DNS query: 123.202.34.22
    Source: unknownTCP traffic detected without corresponding DNS query: 77.125.22.168
    Source: unknownTCP traffic detected without corresponding DNS query: 4.1.161.43
    Source: unknownTCP traffic detected without corresponding DNS query: 198.35.117.70
    Source: unknownTCP traffic detected without corresponding DNS query: 190.230.90.182
    Source: unknownTCP traffic detected without corresponding DNS query: 122.175.224.219
    Source: unknownTCP traffic detected without corresponding DNS query: 192.48.51.176
    Source: unknownTCP traffic detected without corresponding DNS query: 191.1.143.85
    Source: unknownTCP traffic detected without corresponding DNS query: 158.50.209.210
    Source: unknownTCP traffic detected without corresponding DNS query: 74.221.3.251
    Source: unknownTCP traffic detected without corresponding DNS query: 97.203.48.33
    Source: V2WzER53Tt, type: SAMPLEMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5241.1.000000007fd4a080.0000000002b07ef2.rw-.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5240.1.000000001a887bdc.0000000019a04c35.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5243.1.000000007fd4a080.0000000002b07ef2.rw-.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5243.1.000000001a887bdc.0000000019a04c35.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5240.1.000000007fd4a080.0000000002b07ef2.rw-.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: 5241.1.000000001a887bdc.0000000019a04c35.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious XORed keyword - Mozilla/5.0, reference = Internal Research, score =
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal72.troj.lin@0/0@1/0
    Source: V2WzER53TtJoe Sandbox Cloud Basic: Detection: clean Score: 0Perma Link
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1582/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2033/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1612/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1579/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1699/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1335/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1698/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2028/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1334/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1576/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2025/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2146/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/910/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/912/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/517/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/759/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/918/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1594/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1349/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1623/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/761/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1622/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/884/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1983/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2038/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1344/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1465/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1586/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1860/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1463/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/800/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/801/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1629/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1627/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1900/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/491/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2050/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1877/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/772/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1633/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1599/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1632/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/774/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1477/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/654/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/896/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1476/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1872/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2048/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/655/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1475/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/656/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/777/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/657/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/658/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/419/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/936/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1639/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1638/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1809/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1494/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1890/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2063/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2062/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1888/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1886/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/420/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1489/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/785/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1642/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/788/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/667/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/789/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1648/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2078/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2077/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2074/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/670/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/793/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1656/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1654/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/674/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1532/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/796/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/675/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/797/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/676/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/677/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2069/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2102/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/799/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2080/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2084/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2083/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1668/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1664/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1389/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/720/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2114/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/721/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/1661/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2079/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/847/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2097/maps
    Source: /tmp/V2WzER53Tt (PID: 5244)File opened: /proc/2096/maps

    Hooking and other Techniques for Hiding and Protection:

    barindex
    Uses known network protocols on non-standard portsShow sources
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46368
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46372
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46376
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46380
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46386
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46390
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46396
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46400
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46406
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46410
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46418
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46424
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46428
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46432
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46438
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46442
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46448
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46454
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46458
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46466
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46472
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46476
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46482
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46490
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46492
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46496
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46500
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46504
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46510
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46514
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46516
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46520
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46522
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46524
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46528
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46532
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46536
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46540
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46544
    Source: unknownNetwork traffic detected: HTTP traffic on port 23 -> 46546

    Stealing of Sensitive Information:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Remote Access Functionality:

    barindex
    Yara detected MiraiShow sources
    Source: Yara matchFile source: dump.pcap, type: PCAP

    Mitre Att&ck Matrix

    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1System Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port11Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationNon-Application Layer Protocol1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferApplication Layer Protocol2SIM Card SwapCarrier Billing Fraud

    Malware Configuration

    No configs have been found

    Behavior Graph

    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 512648 Sample: V2WzER53Tt Startdate: 01/11/2021 Architecture: LINUX Score: 72 20 31.169.33.111, 23 VTG-ASGB United Kingdom 2->20 22 37.159.88.153 VODAFONE-IT-ASNIT Italy 2->22 24 99 other IPs or domains 2->24 26 Snort IDS alert for network traffic (e.g. based on Emerging Threat rules) 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Yara detected Mirai 2->30 32 2 other signatures 2->32 8 V2WzER53Tt 2->8         started        signatures3 process4 process5 10 V2WzER53Tt 8->10         started        12 V2WzER53Tt 8->12         started        process6 14 V2WzER53Tt 10->14         started        16 V2WzER53Tt 10->16         started        18 V2WzER53Tt 10->18         started       

    Antivirus, Machine Learning and Genetic Malware Detection

    Initial Sample

    SourceDetectionScannerLabelLink
    V2WzER53Tt32%VirustotalBrowse
    V2WzER53Tt40%ReversingLabsLinux.Trojan.Mirai
    V2WzER53Tt100%Joe Sandbox ML

    Dropped Files

    No Antivirus matches

    Domains

    No Antivirus matches

    URLs

    No Antivirus matches

    Domains and IPs

    Contacted Domains

    NameIPActiveMaliciousAntivirus DetectionReputation
    z0x3n.cf
    37.0.10.67
    truefalse
      unknown

      Contacted IPs

      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs

      Public

      IPDomainCountryFlagASNASN NameMalicious
      72.61.165.33
      unknownUnited States
      10507SPCSUSfalse
      174.231.28.33
      unknownUnited States
      22394CELLCOUSfalse
      39.24.241.136
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      80.182.138.23
      unknownItaly
      3269ASN-IBSNAZITfalse
      204.251.17.168
      unknownUnited States
      22713CAC-HQ2USfalse
      219.172.230.13
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      126.124.161.79
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      37.136.71.101
      unknownFinland
      16086DNAFIfalse
      138.209.196.84
      unknownUnited States
      21727HAMLINE-EDUUSfalse
      43.241.121.32
      unknownIndia
      134033HIREACH-BROADBAND-ASHIREACHBROADBANDPRIVATELTDINfalse
      54.44.16.34
      unknownUnited States
      14618AMAZON-AESUSfalse
      80.169.192.37
      unknownUnited Kingdom
      8220COLTCOLTTechnologyServicesGroupLimitedGBfalse
      181.211.64.123
      unknownEcuador
      28006CORPORACIONNACIONALDETELECOMUNICACIONES-CNTEPECfalse
      70.59.57.90
      unknownUnited States
      209CENTURYLINK-US-LEGACY-QWESTUSfalse
      43.95.13.184
      unknownJapan4249LILLY-ASUSfalse
      182.227.223.141
      unknownKorea Republic of
      17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
      4.44.140.137
      unknownUnited States
      3356LEVEL3USfalse
      196.127.145.120
      unknownMorocco
      36925ASMediMAfalse
      17.116.204.52
      unknownUnited States
      714APPLE-ENGINEERINGUSfalse
      38.52.8.233
      unknownUnited States
      174COGENT-174USfalse
      105.151.162.125
      unknownMorocco
      6713IAM-ASMAfalse
      51.0.250.204
      unknownUnited Kingdom
      2686ATGS-MMD-ASUSfalse
      45.254.230.231
      unknownChina
      132116ANINETWORK-INAniNetworkPvtLtdINfalse
      41.123.244.87
      unknownSouth Africa
      16637MTNNS-ASZAfalse
      195.6.129.86
      unknownFrance
      3215FranceTelecom-OrangeFRfalse
      58.219.212.189
      unknownChina
      134769CHINANET-JIANGSU-CHANGZHOU-IDCChinaNetJiangsuChangzhouIDfalse
      175.75.234.174
      unknownChina
      9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
      153.157.16.253
      unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
      64.26.154.152
      unknownCanada
      812ROGERS-COMMUNICATIONSCAfalse
      69.119.10.251
      unknownUnited States
      6128CABLE-NET-1USfalse
      39.89.3.190
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      37.159.88.153
      unknownItaly
      30722VODAFONE-IT-ASNITfalse
      216.8.206.18
      unknownUnited States
      8008ETC-60-ASUSfalse
      112.98.49.112
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      19.129.23.236
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      73.174.67.125
      unknownUnited States
      7922COMCAST-7922USfalse
      48.227.10.242
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      112.85.157.26
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      212.103.208.192
      unknownItaly
      12481TRIVENETTELECOMUNICAZIONIITfalse
      185.247.249.224
      unknownFrance
      16347RMI-FITECHFRfalse
      95.69.98.131
      unknownPortugal
      42863MEO-MOVELPTfalse
      180.205.175.239
      unknownTaiwan; Republic of China (ROC)
      24158TAIWANMOBILE-ASTaiwanMobileCoLtdTWfalse
      193.7.233.94
      unknownGermany
      12680GRUNER-UND-JAHR-AS1HamburgGermanyDEfalse
      186.121.83.11
      unknownColombia
      28118ALTICEDOMINICANASADOfalse
      38.148.28.63
      unknownUnited States
      174COGENT-174USfalse
      115.202.233.11
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      80.71.44.37
      unknownCanada
      395965CARRY-TELECOMCAfalse
      46.34.19.139
      unknownUnited Kingdom
      8190MDNXGBfalse
      150.4.28.217
      unknownJapan6400CompaniaDominicanadeTelefonosSADOfalse
      92.228.85.84
      unknownGermany
      6805TDDE-ASN1DEfalse
      153.198.14.200
      unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
      45.174.220.33
      unknownBrazil
      268869FIBRAPLUSTELECOMUNICACOESLTDAEPPBRfalse
      201.209.195.191
      unknownVenezuela
      8048CANTVServiciosVenezuelaVEfalse
      54.140.16.174
      unknownUnited States
      14618AMAZON-AESUSfalse
      83.82.205.155
      unknownNetherlands
      33915TNF-ASNLfalse
      62.34.235.245
      unknownFrance
      5410BOUYGTEL-ISPFRfalse
      109.52.47.222
      unknownItaly
      16232ASN-TIMServiceProviderITfalse
      91.105.101.213
      unknownLatvia
      12578APOLLO-ASLatviaLVfalse
      103.71.132.236
      unknownSingapore
      45062NETEASE-ASGuangzhouNetEaseComputerSystemCoLtdCNfalse
      24.95.244.76
      unknownUnited States
      33363BHN-33363USfalse
      201.99.236.86
      unknownMexico
      8151UninetSAdeCVMXfalse
      174.174.228.191
      unknownUnited States
      7922COMCAST-7922USfalse
      206.101.65.213
      unknownUnited States
      7991CENTURYLINK-LEGACY-SAVVIS-ASIA-TRANSITUSfalse
      110.135.70.133
      unknownJapan9824JTCL-JP-ASJupiterTelecommunicationCoLtdJPfalse
      201.218.134.124
      unknownChile
      52439OPTICCLfalse
      161.51.59.122
      unknownUnited States
      16525KBRUSfalse
      81.177.17.65
      unknownRussian Federation
      8342RTCOMM-ASRUfalse
      141.70.176.199
      unknownGermany
      553BELWUEBelWue-KoordinationEUfalse
      48.172.161.127
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      206.106.173.7
      unknownUnited States
      1239SPRINTLINKUSfalse
      204.98.5.51
      unknownUnited States
      209CENTURYLINK-US-LEGACY-QWESTUSfalse
      40.1.113.122
      unknownUnited States
      4249LILLY-ASUSfalse
      142.84.38.207
      unknownCanada
      11489BACICAfalse
      78.111.77.240
      unknownGermany
      33984SURFPLANET-ASDEfalse
      196.86.138.209
      unknownMorocco
      6713IAM-ASMAfalse
      107.185.34.158
      unknownUnited States
      20001TWC-20001-PACWESTUSfalse
      124.225.246.124
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      176.50.235.57
      unknownRussian Federation
      12389ROSTELECOM-ASRUfalse
      61.89.86.94
      unknownJapan18081KCNKintetsuCableNetworkCoLtdJPfalse
      175.85.234.246
      unknownChina
      9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
      210.69.66.11
      unknownTaiwan; Republic of China (ROC)
      4782GSNETDataCommunicationBusinessGroupTWfalse
      160.87.222.141
      unknownUnited States
      299UCINET-ASUSfalse
      19.207.207.91
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      37.155.95.200
      unknownTurkey
      20978TT_MOBILIstanbulTRfalse
      35.82.186.28
      unknownUnited States
      237MERIT-AS-14USfalse
      145.82.121.128
      unknownSaudi Arabia
      1103SURFNET-NLSURFnetTheNetherlandsNLfalse
      19.21.250.153
      unknownUnited States
      3MIT-GATEWAYSUSfalse
      108.29.81.107
      unknownUnited States
      701UUNETUSfalse
      110.63.108.249
      unknownChina
      9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
      32.105.99.166
      unknownUnited States
      2688ATGS-MMD-ASUSfalse
      146.87.199.178
      unknownUnited Kingdom
      786JANETJiscServicesLimitedGBfalse
      82.32.160.125
      unknownUnited Kingdom
      5089NTLGBfalse
      164.150.162.231
      unknownSouth Africa
      37130SITA-ASZAfalse
      206.176.163.168
      unknownUnited States
      18818LSUHSCS-NET2USfalse
      31.169.33.111
      unknownUnited Kingdom
      60194VTG-ASGBfalse
      74.166.99.108
      unknownUnited States
      7018ATT-INTERNET4USfalse
      207.177.239.150
      unknownUnited States
      7735REDSHIFTUSfalse
      159.222.210.23
      unknownUnited States
      26395JOHNSON-CONTROLSUSfalse
      200.183.188.183
      unknownBrazil
      4230CLAROSABRfalse
      4.143.28.65
      unknownUnited States
      3356LEVEL3USfalse


      Runtime Messages

      Command:/tmp/V2WzER53Tt
      Exit Code:0
      Exit Code Info:
      Killed:False
      Standard Output:
      0G0dn3t Got To Ya!
      Standard Error:

      Joe Sandbox View / Context

      IPs

      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
      58.219.212.189jew.arm7Get hashmaliciousBrowse

        Domains

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        z0x3n.cf1bL17EUgTkGet hashmaliciousBrowse
        • 37.0.10.67
        pTF1iICUEmGet hashmaliciousBrowse
        • 37.0.10.67
        z0x3n.arm7Get hashmaliciousBrowse
        • 37.0.10.67
        z0x3n.x86Get hashmaliciousBrowse
        • 37.0.10.67

        ASN

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        SPCSUS032k4JmR0UGet hashmaliciousBrowse
        • 108.113.255.159
        armGet hashmaliciousBrowse
        • 173.135.71.137
        x86Get hashmaliciousBrowse
        • 70.9.116.82
        arm7Get hashmaliciousBrowse
        • 68.26.166.237
        z0x3n.arm7Get hashmaliciousBrowse
        • 108.124.110.113
        z0x3n.x86Get hashmaliciousBrowse
        • 72.59.167.134
        armGet hashmaliciousBrowse
        • 174.151.241.175
        QtNnZoNz75Get hashmaliciousBrowse
        • 184.207.33.128
        S13B4aCa4EGet hashmaliciousBrowse
        • 184.209.111.81
        gbk4XWulUoGet hashmaliciousBrowse
        • 184.205.51.89
        QZ2CN6CUyvGet hashmaliciousBrowse
        • 184.251.25.180
        8MPbeDAwwZGet hashmaliciousBrowse
        • 184.243.41.199
        HgTC70XRumGet hashmaliciousBrowse
        • 184.239.67.225
        Xs0PMn85CNGet hashmaliciousBrowse
        • 108.110.174.155
        Tsunami.x86Get hashmaliciousBrowse
        • 184.223.137.41
        Tsunami.arm7Get hashmaliciousBrowse
        • 184.253.108.231
        Tsunami.armGet hashmaliciousBrowse
        • 184.245.8.26
        x86Get hashmaliciousBrowse
        • 184.216.124.79
        KXAJjgoH22Get hashmaliciousBrowse
        • 173.152.132.234
        0r73kbzSGCGet hashmaliciousBrowse
        • 184.192.179.21
        CELLCOUSa5nulABeSkGet hashmaliciousBrowse
        • 72.109.28.224
        032k4JmR0UGet hashmaliciousBrowse
        • 97.45.108.79
        armGet hashmaliciousBrowse
        • 70.221.126.72
        x86Get hashmaliciousBrowse
        • 166.159.16.21
        z0x3n.arm7Get hashmaliciousBrowse
        • 75.235.188.204
        QZ2CN6CUyvGet hashmaliciousBrowse
        • 97.56.241.131
        x86Get hashmaliciousBrowse
        • 174.219.17.232
        arm7Get hashmaliciousBrowse
        • 174.237.27.157
        WnhlYWJ5C5Get hashmaliciousBrowse
        • 72.127.172.19
        dqnskKAmQqGet hashmaliciousBrowse
        • 72.104.231.57
        jJ6GK5qbZtGet hashmaliciousBrowse
        • 166.145.186.136
        x86Get hashmaliciousBrowse
        • 166.239.43.208
        JUZVpUSH0WGet hashmaliciousBrowse
        • 174.239.100.9
        07xBxVsvEnGet hashmaliciousBrowse
        • 166.140.14.127
        5mLAGfiGBfGet hashmaliciousBrowse
        • 72.115.215.214
        wannacry.exeGet hashmaliciousBrowse
        • 72.105.156.213
        wTFR3LK4MoGet hashmaliciousBrowse
        • 174.192.243.230
        yZ7D7o1Z7pGet hashmaliciousBrowse
        • 70.201.163.147
        eNrYzJWFvBGet hashmaliciousBrowse
        • 166.161.44.184
        IcwrPqGkXPGet hashmaliciousBrowse
        • 72.113.124.144

        JA3 Fingerprints

        No context

        Dropped Files

        No context

        Created / dropped Files

        No created / dropped files found

        Static File Info

        General

        File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
        Entropy (8bit):6.203678716949746
        TrID:
        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
        File name:V2WzER53Tt
        File size:71312
        MD5:4b0259083c8800d18cb941c66639a2e6
        SHA1:f58aa2b927047749395a47b16b458f5220d19f3a
        SHA256:7feef5ad07bad632f6440d1fb5e0aaf9464fe27eb7ea5e489ae4f79bfee5b2ea
        SHA512:d72d40832e31803a73d1615ffc6eb6b6e046d36afac6cb1d4462b3dc50dd5a8ebce10c5ba4d44fb4fad8f6760167d3c219fecfe6c65359d07226b8e1199555d7
        SSDEEP:1536:bWscjmrfvWdHCX9hGnYtWQgJIY3pp6mqOj:bWirfvWxCXGYtFcpImH
        File Content Preview:.ELF....................h...4...........4. ...(.....................`...`...............d...d...d...\...\...........Q.td............................U..S........"...h........[]...$.............U......=.....t..1...................u........t...$`............

        Static ELF Info

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:Intel 80386
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:UNIX - System V
        ABI Version:0
        Entry Point Address:0x8048168
        Flags:0x0
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:3
        Section Header Offset:70912
        Section Header Size:40
        Number of Section Headers:10
        Header String Table Index:9

        Sections

        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .initPROGBITS0x80480940x940x1c0x00x6AX001
        .textPROGBITS0x80480b00xb00x104010x00x6AX0016
        .finiPROGBITS0x80584b10x104b10x170x00x6AX001
        .rodataPROGBITS0x80584e00x104e00xe800x00x2A0032
        .ctorsPROGBITS0x805a3640x113640x80x00x3WA004
        .dtorsPROGBITS0x805a36c0x1136c0x80x00x3WA004
        .dataPROGBITS0x805a3a00x113a00x1200x00x3WA0032
        .bssNOBITS0x805a4c00x114c00x8000x00x3WA0032
        .shstrtabSTRTAB0x00x114c00x3e0x00x0001

        Program Segments

        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x80480000x80480000x113600x113603.50010x5R E0x1000.init .text .fini .rodata
        LOAD0x113640x805a3640x805a3640x15c0x95c2.43640x6RW 0x1000.ctors .dtors .data .bss
        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

        Network Behavior

        Network Port Distribution

        TCP Packets

        TimestampSource PortDest PortSource IPDest IP
        Nov 1, 2021 09:43:28.392122030 CET6310823192.168.2.2368.151.86.156
        Nov 1, 2021 09:43:28.392126083 CET631082323192.168.2.2365.76.10.157
        Nov 1, 2021 09:43:28.392153025 CET6310823192.168.2.231.31.45.62
        Nov 1, 2021 09:43:28.392158031 CET6310823192.168.2.23124.50.255.107
        Nov 1, 2021 09:43:28.392158985 CET6310823192.168.2.23187.200.47.75
        Nov 1, 2021 09:43:28.392162085 CET6310823192.168.2.2396.27.91.97
        Nov 1, 2021 09:43:28.392160892 CET6310823192.168.2.2354.141.130.19
        Nov 1, 2021 09:43:28.392172098 CET6310823192.168.2.23156.232.194.44
        Nov 1, 2021 09:43:28.392183065 CET6310823192.168.2.2314.60.219.36
        Nov 1, 2021 09:43:28.392184973 CET6310823192.168.2.2380.66.92.95
        Nov 1, 2021 09:43:28.392184019 CET6310823192.168.2.23121.11.62.135
        Nov 1, 2021 09:43:28.392191887 CET631082323192.168.2.23165.114.154.251
        Nov 1, 2021 09:43:28.392194033 CET6310823192.168.2.2377.197.61.153
        Nov 1, 2021 09:43:28.392199993 CET6310823192.168.2.23104.125.179.179
        Nov 1, 2021 09:43:28.392200947 CET6310823192.168.2.2347.78.75.38
        Nov 1, 2021 09:43:28.392205954 CET6310823192.168.2.23159.147.207.244
        Nov 1, 2021 09:43:28.392211914 CET6310823192.168.2.2324.74.123.108
        Nov 1, 2021 09:43:28.392226934 CET6310823192.168.2.23101.138.110.71
        Nov 1, 2021 09:43:28.392230034 CET6310823192.168.2.23144.62.250.181
        Nov 1, 2021 09:43:28.392234087 CET6310823192.168.2.23160.96.29.164
        Nov 1, 2021 09:43:28.392235994 CET6310823192.168.2.23183.2.65.125
        Nov 1, 2021 09:43:28.392237902 CET6310823192.168.2.23161.89.115.135
        Nov 1, 2021 09:43:28.392241001 CET6310823192.168.2.234.215.32.161
        Nov 1, 2021 09:43:28.392240047 CET6310823192.168.2.2353.222.122.229
        Nov 1, 2021 09:43:28.392251015 CET6310823192.168.2.23186.217.153.216
        Nov 1, 2021 09:43:28.392265081 CET6310823192.168.2.23126.175.225.244
        Nov 1, 2021 09:43:28.392266989 CET6310823192.168.2.2395.136.38.80
        Nov 1, 2021 09:43:28.392275095 CET6310823192.168.2.2384.23.168.34
        Nov 1, 2021 09:43:28.392281055 CET6310823192.168.2.23149.141.117.70
        Nov 1, 2021 09:43:28.392283916 CET631082323192.168.2.23123.237.191.254
        Nov 1, 2021 09:43:28.392292023 CET6310823192.168.2.23159.45.79.76
        Nov 1, 2021 09:43:28.392294884 CET6310823192.168.2.23118.70.160.208
        Nov 1, 2021 09:43:28.392306089 CET631082323192.168.2.2383.117.106.174
        Nov 1, 2021 09:43:28.392307043 CET6310823192.168.2.23160.130.94.1
        Nov 1, 2021 09:43:28.392307043 CET6310823192.168.2.23188.214.26.137
        Nov 1, 2021 09:43:28.392309904 CET6310823192.168.2.23186.99.167.244
        Nov 1, 2021 09:43:28.392318010 CET6310823192.168.2.23121.69.134.116
        Nov 1, 2021 09:43:28.392318964 CET6310823192.168.2.23148.34.102.50
        Nov 1, 2021 09:43:28.392323971 CET6310823192.168.2.2399.207.115.45
        Nov 1, 2021 09:43:28.392327070 CET6310823192.168.2.23216.90.237.233
        Nov 1, 2021 09:43:28.392332077 CET6310823192.168.2.23212.145.133.178
        Nov 1, 2021 09:43:28.392333031 CET6310823192.168.2.23123.202.34.22
        Nov 1, 2021 09:43:28.392334938 CET6310823192.168.2.2377.125.22.168
        Nov 1, 2021 09:43:28.392340899 CET6310823192.168.2.234.1.161.43
        Nov 1, 2021 09:43:28.392344952 CET6310823192.168.2.23198.35.117.70
        Nov 1, 2021 09:43:28.392348051 CET6310823192.168.2.23190.230.90.182
        Nov 1, 2021 09:43:28.392352104 CET6310823192.168.2.23122.175.224.219
        Nov 1, 2021 09:43:28.392354012 CET6310823192.168.2.23192.48.51.176
        Nov 1, 2021 09:43:28.392357111 CET6310823192.168.2.23191.1.143.85
        Nov 1, 2021 09:43:28.392358065 CET6310823192.168.2.23158.50.209.210
        Nov 1, 2021 09:43:28.392357111 CET6310823192.168.2.2374.221.3.251
        Nov 1, 2021 09:43:28.392362118 CET631082323192.168.2.2397.203.48.33
        Nov 1, 2021 09:43:28.392364025 CET6310823192.168.2.2394.214.56.208
        Nov 1, 2021 09:43:28.392381907 CET631082323192.168.2.23109.40.137.123
        Nov 1, 2021 09:43:28.392385960 CET6310823192.168.2.23176.98.193.48
        Nov 1, 2021 09:43:28.392393112 CET6310823192.168.2.23125.145.255.200
        Nov 1, 2021 09:43:28.393428087 CET6310823192.168.2.23149.122.176.153
        Nov 1, 2021 09:43:28.393454075 CET6310823192.168.2.2385.44.247.148
        Nov 1, 2021 09:43:28.393454075 CET6310823192.168.2.23139.146.180.153
        Nov 1, 2021 09:43:28.393455029 CET631082323192.168.2.2337.52.25.160
        Nov 1, 2021 09:43:28.393455982 CET6310823192.168.2.2340.86.54.101
        Nov 1, 2021 09:43:28.393456936 CET6310823192.168.2.2335.220.219.139
        Nov 1, 2021 09:43:28.393471956 CET631082323192.168.2.23203.161.129.188
        Nov 1, 2021 09:43:28.393481970 CET6310823192.168.2.23220.146.253.173
        Nov 1, 2021 09:43:28.393484116 CET6310823192.168.2.23125.202.19.188
        Nov 1, 2021 09:43:28.393484116 CET6310823192.168.2.23126.102.158.248
        Nov 1, 2021 09:43:28.393491030 CET6310823192.168.2.2380.31.101.77
        Nov 1, 2021 09:43:28.393491983 CET6310823192.168.2.23106.159.75.32
        Nov 1, 2021 09:43:28.393493891 CET6310823192.168.2.2370.157.219.236
        Nov 1, 2021 09:43:28.393496037 CET6310823192.168.2.23179.65.55.26
        Nov 1, 2021 09:43:28.393498898 CET6310823192.168.2.235.137.107.55
        Nov 1, 2021 09:43:28.393502951 CET6310823192.168.2.2331.125.138.5
        Nov 1, 2021 09:43:28.393507004 CET6310823192.168.2.2365.207.252.26
        Nov 1, 2021 09:43:28.393510103 CET6310823192.168.2.2393.157.224.194
        Nov 1, 2021 09:43:28.393513918 CET6310823192.168.2.2344.166.252.183
        Nov 1, 2021 09:43:28.393515110 CET6310823192.168.2.23118.89.92.173
        Nov 1, 2021 09:43:28.393524885 CET6310823192.168.2.2353.165.234.253
        Nov 1, 2021 09:43:28.393529892 CET6310823192.168.2.234.246.182.218
        Nov 1, 2021 09:43:28.393547058 CET6310823192.168.2.2346.67.218.96
        Nov 1, 2021 09:43:28.393558979 CET6310823192.168.2.23176.86.7.178
        Nov 1, 2021 09:43:28.393567085 CET6310823192.168.2.2367.64.173.71
        Nov 1, 2021 09:43:28.393568993 CET6310823192.168.2.2366.165.41.101
        Nov 1, 2021 09:43:28.393569946 CET6310823192.168.2.23119.132.178.213
        Nov 1, 2021 09:43:28.393570900 CET6310823192.168.2.2376.85.24.35
        Nov 1, 2021 09:43:28.393570900 CET6310823192.168.2.23163.103.10.168
        Nov 1, 2021 09:43:28.393573999 CET6310823192.168.2.23123.236.171.176
        Nov 1, 2021 09:43:28.393579006 CET631082323192.168.2.23196.2.10.111
        Nov 1, 2021 09:43:28.393585920 CET6310823192.168.2.2358.187.239.49
        Nov 1, 2021 09:43:28.393591881 CET6310823192.168.2.23171.42.68.154
        Nov 1, 2021 09:43:28.393598080 CET631082323192.168.2.23218.131.219.131
        Nov 1, 2021 09:43:28.393600941 CET631082323192.168.2.23202.79.107.76
        Nov 1, 2021 09:43:28.393601894 CET6310823192.168.2.2334.15.13.148
        Nov 1, 2021 09:43:28.393604040 CET6310823192.168.2.2339.112.89.36
        Nov 1, 2021 09:43:28.393610001 CET6310823192.168.2.23118.200.253.176
        Nov 1, 2021 09:43:28.393611908 CET6310823192.168.2.23200.208.76.140
        Nov 1, 2021 09:43:28.393619061 CET6310823192.168.2.2389.41.212.167
        Nov 1, 2021 09:43:28.393624067 CET6310823192.168.2.23148.17.17.112
        Nov 1, 2021 09:43:28.393631935 CET6310823192.168.2.2338.235.34.123
        Nov 1, 2021 09:43:28.393634081 CET6310823192.168.2.2337.54.211.4
        Nov 1, 2021 09:43:28.393645048 CET6310823192.168.2.23154.198.168.159

        DNS Queries

        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
        Nov 1, 2021 09:43:28.390194893 CET192.168.2.238.8.8.80x4f2dStandard query (0)z0x3n.cfA (IP address)IN (0x0001)

        DNS Answers

        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
        Nov 1, 2021 09:43:28.426201105 CET8.8.8.8192.168.2.230x4f2dNo error (0)z0x3n.cf37.0.10.67A (IP address)IN (0x0001)

        System Behavior

        General

        Start time:09:43:27
        Start date:01/11/2021
        Path:/tmp/V2WzER53Tt
        Arguments:/tmp/V2WzER53Tt
        File size:71312 bytes
        MD5 hash:4b0259083c8800d18cb941c66639a2e6

        General

        Start time:09:43:27
        Start date:01/11/2021
        Path:/tmp/V2WzER53Tt
        Arguments:n/a
        File size:71312 bytes
        MD5 hash:4b0259083c8800d18cb941c66639a2e6

        General

        Start time:09:43:27
        Start date:01/11/2021
        Path:/tmp/V2WzER53Tt
        Arguments:n/a
        File size:71312 bytes
        MD5 hash:4b0259083c8800d18cb941c66639a2e6

        General

        Start time:09:43:27
        Start date:01/11/2021
        Path:/tmp/V2WzER53Tt
        Arguments:n/a
        File size:71312 bytes
        MD5 hash:4b0259083c8800d18cb941c66639a2e6

        General

        Start time:09:43:27
        Start date:01/11/2021
        Path:/tmp/V2WzER53Tt
        Arguments:n/a
        File size:71312 bytes
        MD5 hash:4b0259083c8800d18cb941c66639a2e6

        General

        Start time:09:43:27
        Start date:01/11/2021
        Path:/tmp/V2WzER53Tt
        Arguments:n/a
        File size:71312 bytes
        MD5 hash:4b0259083c8800d18cb941c66639a2e6