Windows
Analysis Report
1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe (PID: 6768 cmdline:
"C:\Users\ user\Deskt op\1c47eba 374d49cd0a 1a90cbd166 8854b0fff5 dc9b774db1 90acfc6d15 f753dec_du mp.exe" MD5: 1022EEE3D28A81920664B590983AAFAA)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"C2 url": "https://api.telegram.org/bot6937426667:AAH5h4aXvUjmlMFV8im9A9lKn7JS7MyNHLA/sendMessage"}
{"Exfil Mode": "Telegram", "Telegram Url": "https://api.telegram.org/bot6937426667:AAH5h4aXvUjmlMFV8im9A9lKn7JS7MyNHLA/sendMessage?chat_id=1165128482"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
Click to see the 4 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
|
Timestamp: | 05/18/24-01:35:57.911306 |
SID: | 2851779 |
Source Port: | 49730 |
Destination Port: | 443 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: | ||
Source: | Malware Configuration Extractor: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | Snort IDS: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
Source: | Windows user hook set: | Jump to behavior |
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_032141A0 | |
Source: | Code function: | 0_2_0321A1DB | |
Source: | Code function: | 0_2_0321D480 | |
Source: | Code function: | 0_2_03214A70 | |
Source: | Code function: | 0_2_03213E58 | |
Source: | Code function: | 0_2_06733678 | |
Source: | Code function: | 0_2_06735E38 | |
Source: | Code function: | 0_2_067346B0 | |
Source: | Code function: | 0_2_06739700 | |
Source: | Code function: | 0_2_0673C450 | |
Source: | Code function: | 0_2_0673A240 | |
Source: | Code function: | 0_2_067392E3 | |
Source: | Code function: | 0_2_06730040 | |
Source: | Code function: | 0_2_0673E0D8 | |
Source: | Code function: | 0_2_06735758 | |
Source: | Code function: | 0_2_06733DA7 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Binary string: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 1 Query Registry | Remote Services | 1 Email Collection | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 141 Virtualization/Sandbox Evasion | 21 Input Capture | 111 Security Software Discovery | Remote Desktop Protocol | 21 Input Capture | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Deobfuscate/Decode Files or Information | 1 Credentials in Registry | 1 Process Discovery | SMB/Windows Admin Shares | 11 Archive Collected Data | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 141 Virtualization/Sandbox Evasion | Distributed Component Object Model | 2 Data from Local System | 3 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 1 Application Window Discovery | SSH | 1 Clipboard Data | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 24 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1305739 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.telegram.org | 149.154.167.220 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
true |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | true |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1443568 |
Start date and time: | 2024-05-18 01:35:04 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 46s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@1/0@2/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: 1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe
Time | Type | Description |
---|---|---|
19:35:57 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
149.154.167.220 | Get hash | malicious | AgentTesla, PureLog Stealer | Browse | ||
Get hash | malicious | Babuk, CORNY Ransomware, Chaos, Ragnarok, TrojanRansom | Browse | |||
Get hash | malicious | PureLog Stealer, RedLine, XWorm | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | PureLog Stealer | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | Nightingale Stealer | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.telegram.org | Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| |
Get hash | malicious | Babuk, CORNY Ransomware, Chaos, Ragnarok, TrojanRansom | Browse |
| ||
Get hash | malicious | PureLog Stealer, RedLine, XWorm | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Nightingale Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TELEGRAMRU | Get hash | malicious | CryptOne, Vidar | Browse |
| |
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | Babuk, CORNY Ransomware, Chaos, Ragnarok, TrojanRansom | Browse |
| ||
Get hash | malicious | PureLog Stealer, RedLine, XWorm | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
|
File type: | |
Entropy (8bit): | 5.0093351523926 |
TrID: |
|
File name: | 1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
File size: | 249'856 bytes |
MD5: | 1022eee3d28a81920664b590983aafaa |
SHA1: | 002c1889f8e8ebbf781e3a1edb0985068b2a5b96 |
SHA256: | ccd022fa7f9a0ee0928a7736faed2f9d9123234d209c7fdf9b436776669c4644 |
SHA512: | b2bc0d955f356596f939c0457c367fa79b192237e6a27591e02cf315076afab1908ed3093dda53bd2bcb7dfe20604779b72255e97c52c4c8487c8a50c40d6d4b |
SSDEEP: | 3072:DsUqShjy6yaCYHb+lDzVuXn9Phn755rh4xsnD:DsUqcy6yaCY7+lDzV4PhnTh4e |
TLSH: | E8340F027E88EB15E5A83E3792EF6D2413B2B0C70633C60B6F49AF5528517825D7E72D |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L... ..f................................. ........@.. .......................@............@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x43e52e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x661CD820 [Mon Apr 15 07:32:48 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3e4d8 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x40000 | 0x546 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x42000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x3c534 | 0x3c600 | 011624d87e0649a90b3b1bf2e00ef64b | False | 0.35819827251552794 | data | 5.020453521983489 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x40000 | 0x546 | 0x600 | 13710f083c5f6d693011c99ff53d1b71 | False | 0.3971354166666667 | data | 3.993854391184784 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x42000 | 0xc | 0x200 | 8275738e2c8d184d08335f3833a97f65 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x400a0 | 0x2bc | data | 0.43714285714285717 | ||
RT_MANIFEST | 0x4035c | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
05/18/24-01:35:57.911306 | TCP | 2851779 | ETPRO TROJAN Agent Tesla Telegram Exfil | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 18, 2024 01:35:56.266114950 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:56.266156912 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:56.266324043 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:56.275564909 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:56.275609016 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:57.437931061 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:57.438057899 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:57.442511082 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:57.442538977 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:57.443062067 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:57.488246918 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:57.563107014 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:57.608119965 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:57.911007881 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:57.911043882 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:57.981451988 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:58.035314083 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:58.234256029 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:58.239382029 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:58.239483118 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:58.243407011 CEST | 49730 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:58.284511089 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:58.284598112 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:58.284692049 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:58.284951925 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:58.284991026 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:59.386918068 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:59.388540030 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:59.388607025 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:59.738347054 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:35:59.738385916 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:59.903084993 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:35:59.956988096 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:36:00.097383976 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:36:00.098078966 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:36:00.098280907 CEST | 443 | 49731 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:36:00.098357916 CEST | 49731 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:41.886121988 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:41.886161089 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:41.886223078 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:41.886594057 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:41.886615992 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:42.993087053 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:42.993165970 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:42.994976997 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:42.994983912 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:42.995604992 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.006150961 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:43.048141956 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.363490105 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:43.363529921 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.363600969 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:43.363616943 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.363869905 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:43.364052057 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.523284912 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.660078049 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:43.989321947 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.989963055 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:37:43.990250111 CEST | 443 | 49739 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:37:43.990326881 CEST | 49739 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:03.327594995 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:03.327666044 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:03.332549095 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:03.332828045 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:03.332859993 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.447238922 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.447329998 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:04.449331045 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:04.449358940 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.450180054 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.451714039 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:04.496123075 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.801506996 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:04.801573038 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.805557013 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:04.805593967 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.809521914 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:04.809545040 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:04.973138094 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:05.021465063 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:05.443814993 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:05.448483944 CEST | 443 | 49740 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:05.448762894 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:05.449410915 CEST | 49740 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:08.765634060 CEST | 49741 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:08.765688896 CEST | 443 | 49741 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:08.768255949 CEST | 49741 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:08.772140980 CEST | 49741 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:08.772176027 CEST | 443 | 49741 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:09.594235897 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:09.594266891 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:09.594319105 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:09.594635963 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:09.594647884 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:09.602449894 CEST | 49741 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:09.648118973 CEST | 443 | 49741 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:09.873923063 CEST | 443 | 49741 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:09.874085903 CEST | 443 | 49741 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:09.874119997 CEST | 49741 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:09.874192953 CEST | 49741 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:10.696079969 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:10.696161985 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:10.697762012 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:10.697767973 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:10.697985888 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:10.701443911 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:10.744157076 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:11.050894976 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:11.050934076 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:11.051302910 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:11.051328897 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:11.051632881 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:11.051651955 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:11.214653969 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:11.269464970 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:11.680713892 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:11.681246996 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:11.681308031 CEST | 443 | 49742 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:11.681355953 CEST | 49742 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:14.276774883 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:14.276874065 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:14.276952028 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:14.277420044 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:14.277456999 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.408919096 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.409046888 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:15.413459063 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:15.413501978 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.413889885 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.417454958 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:15.460177898 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.769750118 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:15.769825935 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.769956112 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:15.769989014 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.770087004 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:15.770128965 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.934396982 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:15.988194942 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:16.398982048 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:16.399588108 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:16.399673939 CEST | 443 | 49743 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:16.399739027 CEST | 49743 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:21.571974039 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:21.572073936 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:21.577538013 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:21.579458952 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:21.579498053 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:22.720604897 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:22.720720053 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:23.430300951 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:23.430330038 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:23.430779934 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:23.432477951 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:23.480132103 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:23.744798899 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:23.745163918 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:23.745256901 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:23.745388031 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:23.745482922 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:23.745623112 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:23.745683908 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:24.408597946 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:24.409166098 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:24.409229994 CEST | 443 | 49744 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:24.409285069 CEST | 49744 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:36.071331024 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:36.071367025 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:36.071439981 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:36.071777105 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:36.071789026 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.184807062 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.184884071 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:37.186904907 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:37.186913013 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.187129021 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.189433098 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:37.236131907 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.539403915 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:37.539441109 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.539604902 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:37.539627075 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.539753914 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:37.539772987 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.697925091 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:37.738277912 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:38.173115015 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:38.173702002 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:38.173831940 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:38.174245119 CEST | 443 | 49745 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:38.174258947 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:38.174329042 CEST | 49745 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:44.673496962 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:44.673583031 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:44.674066067 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:44.677541018 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:44.677615881 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:45.804384947 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:45.804491043 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:45.806083918 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:45.806117058 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:45.806448936 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:45.807766914 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:45.848189116 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:46.160444975 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:46.160501003 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:46.160758972 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:46.160798073 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:46.161078930 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:46.161319971 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:46.326735020 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:46.378937006 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:46.791660070 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:46.793534040 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:46.793662071 CEST | 443 | 49746 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:46.793997049 CEST | 49746 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:48.464720964 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:48.464812040 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:48.464899063 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:48.465337038 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:48.465367079 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:49.547055006 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:49.547207117 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:49.549500942 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:49.549554110 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:49.549917936 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:49.557539940 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:49.604125023 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:49.910444021 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:49.910530090 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:49.910826921 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:49.910913944 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:49.911259890 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:49.911329985 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:50.061837912 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:50.113317966 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:50.523686886 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:50.524452925 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:50.524566889 CEST | 443 | 49747 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:50.524779081 CEST | 49747 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:56.956126928 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:56.956176043 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:56.956365108 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:56.959417105 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:56.959434032 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.066082954 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.066143036 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:58.068530083 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:58.068540096 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.068789959 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.070900917 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:58.116128922 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.425928116 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:58.425956011 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.426037073 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:58.426044941 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.426125050 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:58.426140070 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.936476946 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:58.989415884 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:59.245271921 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:59.248157978 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:59.248215914 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:59.248452902 CEST | 443 | 49748 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:38:59.248693943 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:38:59.248693943 CEST | 49748 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:03.393627882 CEST | 49749 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:03.393665075 CEST | 443 | 49749 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:03.393989086 CEST | 49749 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:03.394212961 CEST | 49749 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:03.394222975 CEST | 443 | 49749 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:04.293181896 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:04.293236017 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:04.293292046 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:04.295393944 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:04.295411110 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:04.301446915 CEST | 49749 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:04.348120928 CEST | 443 | 49749 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:04.532150984 CEST | 443 | 49749 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:04.532207012 CEST | 49749 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:04.532218933 CEST | 49749 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:05.516967058 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:05.517059088 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:05.518656969 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:05.518667936 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:05.518867970 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:05.520809889 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:05.568110943 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:05.878987074 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:05.879020929 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:05.879091978 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:05.879106045 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:05.879179955 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:05.879273891 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:06.037580013 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:06.081942081 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:06.498903036 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:06.499470949 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:06.499521971 CEST | 443 | 49750 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:06.499588966 CEST | 49750 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:22.015482903 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:22.015512943 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:22.015706062 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:22.019402027 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:22.019417048 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.130584002 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.130657911 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:23.132775068 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:23.132785082 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.133117914 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.134525061 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:23.180104971 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.488487005 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:23.488534927 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.488703966 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:23.488725901 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.488795996 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:23.488889933 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.633981943 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:23.738217115 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:24.109774113 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:24.110265017 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:24.110327005 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:24.110637903 CEST | 443 | 49751 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:24.111953974 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:24.111953974 CEST | 49751 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:27.678694010 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:27.678778887 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:27.679018021 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:27.679343939 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:27.679416895 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:28.771625996 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:28.771852016 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:28.773766994 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:28.773821115 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:28.774174929 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:28.775948048 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:28.816200972 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.129134893 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.129220963 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.129431009 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.129462957 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.129863024 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.129982948 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.266002893 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.266006947 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.266084909 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.266279936 CEST | 443 | 49752 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.266346931 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.266525030 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.266556978 CEST | 49752 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.266585112 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.566423893 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.566507101 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:29.566641092 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.566956997 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:29.566981077 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.410002947 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.410187960 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.411886930 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.411938906 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.412192106 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.413441896 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.460108042 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.640496969 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.640568972 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.642040014 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.642052889 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.642504930 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.643656969 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.688116074 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.769951105 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.770036936 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.770654917 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.770750999 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.770981073 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.771020889 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.930491924 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.988389015 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.988481998 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.988938093 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.988962889 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:30.989314079 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:30.989476919 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:31.128941059 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:31.179101944 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:31.238207102 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:31.398756027 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:31.401936054 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:31.402014017 CEST | 443 | 49753 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:31.402122021 CEST | 49753 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:31.603620052 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:31.604223967 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:31.604273081 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:31.604461908 CEST | 443 | 49754 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:31.604530096 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:31.604530096 CEST | 49754 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:40.045926094 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:40.045968056 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:40.046037912 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:40.046339035 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:40.046355963 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.170532942 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.170945883 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:41.173388004 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:41.173398972 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.173803091 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.175162077 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:41.216190100 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.519629002 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:41.519676924 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.519821882 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:41.519867897 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.520699978 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:41.520761013 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.685163975 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:41.740149021 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:42.147763968 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:42.148614883 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:39:42.148736954 CEST | 443 | 49755 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:39:42.148789883 CEST | 49755 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:00.764022112 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:00.764117956 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:00.764214993 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:00.764417887 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:00.764441013 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:01.973586082 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:01.973663092 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:01.975150108 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:01.975158930 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:01.975649118 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:01.976957083 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:02.024113894 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.332149029 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:02.332182884 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.332269907 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:02.332281113 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.332365036 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:02.332498074 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.492197037 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.535063028 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:02.947458982 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.948128939 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:02.948227882 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.948700905 CEST | 443 | 49756 | 149.154.167.220 | 192.168.2.4 |
May 18, 2024 01:40:02.952178955 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
May 18, 2024 01:40:02.952178955 CEST | 49756 | 443 | 192.168.2.4 | 149.154.167.220 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 18, 2024 01:35:56.250650883 CEST | 56042 | 53 | 192.168.2.4 | 1.1.1.1 |
May 18, 2024 01:35:56.261547089 CEST | 53 | 56042 | 1.1.1.1 | 192.168.2.4 |
May 18, 2024 01:38:36.064038038 CEST | 51963 | 53 | 192.168.2.4 | 1.1.1.1 |
May 18, 2024 01:38:36.070816040 CEST | 53 | 51963 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
May 18, 2024 01:35:56.250650883 CEST | 192.168.2.4 | 1.1.1.1 | 0x25a4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 18, 2024 01:38:36.064038038 CEST | 192.168.2.4 | 1.1.1.1 | 0x3b37 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
May 18, 2024 01:35:56.261547089 CEST | 1.1.1.1 | 192.168.2.4 | 0x25a4 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false | ||
May 18, 2024 01:38:36.070816040 CEST | 1.1.1.1 | 192.168.2.4 | 0x3b37 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:35:57 UTC | 260 | OUT | |
2024-05-17 23:35:57 UTC | 915 | OUT | |
2024-05-17 23:35:57 UTC | 25 | IN | |
2024-05-17 23:35:58 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49731 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:35:59 UTC | 237 | OUT | |
2024-05-17 23:35:59 UTC | 1024 | OUT | |
2024-05-17 23:35:59 UTC | 2877 | OUT | |
2024-05-17 23:35:59 UTC | 50 | OUT | |
2024-05-17 23:35:59 UTC | 25 | IN | |
2024-05-17 23:36:00 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49739 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:37:43 UTC | 262 | OUT | |
2024-05-17 23:37:43 UTC | 1024 | OUT | |
2024-05-17 23:37:43 UTC | 16355 | OUT | |
2024-05-17 23:37:43 UTC | 16355 | OUT | |
2024-05-17 23:37:43 UTC | 16355 | OUT | |
2024-05-17 23:37:43 UTC | 15447 | OUT | |
2024-05-17 23:37:43 UTC | 1407 | OUT | |
2024-05-17 23:37:43 UTC | 50 | OUT | |
2024-05-17 23:37:43 UTC | 25 | IN | |
2024-05-17 23:37:43 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49740 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:04 UTC | 238 | OUT | |
2024-05-17 23:38:04 UTC | 1024 | OUT | |
2024-05-17 23:38:04 UTC | 16355 | OUT | |
2024-05-17 23:38:04 UTC | 16355 | OUT | |
2024-05-17 23:38:04 UTC | 16355 | OUT | |
2024-05-17 23:38:04 UTC | 15447 | OUT | |
2024-05-17 23:38:04 UTC | 1409 | OUT | |
2024-05-17 23:38:04 UTC | 50 | OUT | |
2024-05-17 23:38:04 UTC | 25 | IN | |
2024-05-17 23:38:05 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49742 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:10 UTC | 262 | OUT | |
2024-05-17 23:38:11 UTC | 1024 | OUT | |
2024-05-17 23:38:11 UTC | 16355 | OUT | |
2024-05-17 23:38:11 UTC | 16355 | OUT | |
2024-05-17 23:38:11 UTC | 16355 | OUT | |
2024-05-17 23:38:11 UTC | 15447 | OUT | |
2024-05-17 23:38:11 UTC | 1409 | OUT | |
2024-05-17 23:38:11 UTC | 50 | OUT | |
2024-05-17 23:38:11 UTC | 25 | IN | |
2024-05-17 23:38:11 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49743 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:15 UTC | 238 | OUT | |
2024-05-17 23:38:15 UTC | 1024 | OUT | |
2024-05-17 23:38:15 UTC | 16355 | OUT | |
2024-05-17 23:38:15 UTC | 16355 | OUT | |
2024-05-17 23:38:15 UTC | 16355 | OUT | |
2024-05-17 23:38:15 UTC | 15447 | OUT | |
2024-05-17 23:38:15 UTC | 1409 | OUT | |
2024-05-17 23:38:15 UTC | 50 | OUT | |
2024-05-17 23:38:15 UTC | 25 | IN | |
2024-05-17 23:38:16 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49744 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:23 UTC | 262 | OUT | |
2024-05-17 23:38:23 UTC | 25 | IN | |
2024-05-17 23:38:23 UTC | 1024 | OUT | |
2024-05-17 23:38:23 UTC | 16355 | OUT | |
2024-05-17 23:38:23 UTC | 16355 | OUT | |
2024-05-17 23:38:23 UTC | 16355 | OUT | |
2024-05-17 23:38:23 UTC | 15447 | OUT | |
2024-05-17 23:38:23 UTC | 1409 | OUT | |
2024-05-17 23:38:23 UTC | 50 | OUT | |
2024-05-17 23:38:24 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49745 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:37 UTC | 262 | OUT | |
2024-05-17 23:38:37 UTC | 1024 | OUT | |
2024-05-17 23:38:37 UTC | 16355 | OUT | |
2024-05-17 23:38:37 UTC | 16355 | OUT | |
2024-05-17 23:38:37 UTC | 16355 | OUT | |
2024-05-17 23:38:37 UTC | 15447 | OUT | |
2024-05-17 23:38:37 UTC | 1409 | OUT | |
2024-05-17 23:38:37 UTC | 50 | OUT | |
2024-05-17 23:38:37 UTC | 25 | IN | |
2024-05-17 23:38:38 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49746 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:45 UTC | 262 | OUT | |
2024-05-17 23:38:46 UTC | 1024 | OUT | |
2024-05-17 23:38:46 UTC | 16355 | OUT | |
2024-05-17 23:38:46 UTC | 16355 | OUT | |
2024-05-17 23:38:46 UTC | 16355 | OUT | |
2024-05-17 23:38:46 UTC | 15447 | OUT | |
2024-05-17 23:38:46 UTC | 1409 | OUT | |
2024-05-17 23:38:46 UTC | 50 | OUT | |
2024-05-17 23:38:46 UTC | 25 | IN | |
2024-05-17 23:38:46 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49747 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:49 UTC | 262 | OUT | |
2024-05-17 23:38:49 UTC | 1024 | OUT | |
2024-05-17 23:38:49 UTC | 16355 | OUT | |
2024-05-17 23:38:49 UTC | 16355 | OUT | |
2024-05-17 23:38:49 UTC | 16355 | OUT | |
2024-05-17 23:38:49 UTC | 15447 | OUT | |
2024-05-17 23:38:49 UTC | 1409 | OUT | |
2024-05-17 23:38:49 UTC | 50 | OUT | |
2024-05-17 23:38:50 UTC | 25 | IN | |
2024-05-17 23:38:50 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49748 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:38:58 UTC | 262 | OUT | |
2024-05-17 23:38:58 UTC | 1024 | OUT | |
2024-05-17 23:38:58 UTC | 16355 | OUT | |
2024-05-17 23:38:58 UTC | 16355 | OUT | |
2024-05-17 23:38:58 UTC | 16355 | OUT | |
2024-05-17 23:38:58 UTC | 15447 | OUT | |
2024-05-17 23:38:58 UTC | 1409 | OUT | |
2024-05-17 23:38:58 UTC | 50 | OUT | |
2024-05-17 23:38:58 UTC | 25 | IN | |
2024-05-17 23:38:59 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49750 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:39:05 UTC | 262 | OUT | |
2024-05-17 23:39:05 UTC | 1024 | OUT | |
2024-05-17 23:39:05 UTC | 16355 | OUT | |
2024-05-17 23:39:05 UTC | 16355 | OUT | |
2024-05-17 23:39:05 UTC | 16355 | OUT | |
2024-05-17 23:39:05 UTC | 15447 | OUT | |
2024-05-17 23:39:05 UTC | 1414 | OUT | |
2024-05-17 23:39:05 UTC | 50 | OUT | |
2024-05-17 23:39:06 UTC | 25 | IN | |
2024-05-17 23:39:06 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49751 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:39:23 UTC | 238 | OUT | |
2024-05-17 23:39:23 UTC | 1024 | OUT | |
2024-05-17 23:39:23 UTC | 16355 | OUT | |
2024-05-17 23:39:23 UTC | 16355 | OUT | |
2024-05-17 23:39:23 UTC | 16355 | OUT | |
2024-05-17 23:39:23 UTC | 15447 | OUT | |
2024-05-17 23:39:23 UTC | 1414 | OUT | |
2024-05-17 23:39:23 UTC | 50 | OUT | |
2024-05-17 23:39:23 UTC | 25 | IN | |
2024-05-17 23:39:24 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49752 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:39:28 UTC | 262 | OUT | |
2024-05-17 23:39:29 UTC | 1024 | OUT | |
2024-05-17 23:39:29 UTC | 16355 | OUT | |
2024-05-17 23:39:29 UTC | 16355 | OUT | |
2024-05-17 23:39:29 UTC | 16355 | OUT | |
2024-05-17 23:39:29 UTC | 15447 | OUT | |
2024-05-17 23:39:29 UTC | 6381 | OUT | |
2024-05-17 23:39:29 UTC | 50 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49753 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:39:30 UTC | 262 | OUT | |
2024-05-17 23:39:30 UTC | 1024 | OUT | |
2024-05-17 23:39:30 UTC | 16355 | OUT | |
2024-05-17 23:39:30 UTC | 16355 | OUT | |
2024-05-17 23:39:30 UTC | 16355 | OUT | |
2024-05-17 23:39:30 UTC | 15447 | OUT | |
2024-05-17 23:39:30 UTC | 1414 | OUT | |
2024-05-17 23:39:30 UTC | 50 | OUT | |
2024-05-17 23:39:30 UTC | 25 | IN | |
2024-05-17 23:39:31 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49754 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:39:30 UTC | 262 | OUT | |
2024-05-17 23:39:30 UTC | 1024 | OUT | |
2024-05-17 23:39:30 UTC | 16355 | OUT | |
2024-05-17 23:39:30 UTC | 16355 | OUT | |
2024-05-17 23:39:30 UTC | 16355 | OUT | |
2024-05-17 23:39:30 UTC | 15447 | OUT | |
2024-05-17 23:39:30 UTC | 1414 | OUT | |
2024-05-17 23:39:30 UTC | 50 | OUT | |
2024-05-17 23:39:31 UTC | 25 | IN | |
2024-05-17 23:39:31 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49755 | 149.154.167.220 | 443 | 6768 | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:39:41 UTC | 238 | OUT | |
2024-05-17 23:39:41 UTC | 1024 | OUT | |
2024-05-17 23:39:41 UTC | 16355 | OUT | |
2024-05-17 23:39:41 UTC | 16355 | OUT | |
2024-05-17 23:39:41 UTC | 16355 | OUT | |
2024-05-17 23:39:41 UTC | 15447 | OUT | |
2024-05-17 23:39:41 UTC | 1414 | OUT | |
2024-05-17 23:39:41 UTC | 50 | OUT | |
2024-05-17 23:39:41 UTC | 25 | IN | |
2024-05-17 23:39:42 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
17 | 192.168.2.4 | 49756 | 149.154.167.220 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-17 23:40:01 UTC | 262 | OUT | |
2024-05-17 23:40:02 UTC | 1024 | OUT | |
2024-05-17 23:40:02 UTC | 16355 | OUT | |
2024-05-17 23:40:02 UTC | 16355 | OUT | |
2024-05-17 23:40:02 UTC | 16355 | OUT | |
2024-05-17 23:40:02 UTC | 15447 | OUT | |
2024-05-17 23:40:02 UTC | 1414 | OUT | |
2024-05-17 23:40:02 UTC | 50 | OUT | |
2024-05-17 23:40:02 UTC | 25 | IN | |
2024-05-17 23:40:02 UTC | 402 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 19:35:54 |
Start date: | 17/05/2024 |
Path: | C:\Users\user\Desktop\1c47eba374d49cd0a1a90cbd1668854b0fff5dc9b774db190acfc6d15f753dec_dump.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfe0000 |
File size: | 249'856 bytes |
MD5 hash: | 1022EEE3D28A81920664B590983AAFAA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 13.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 26 |
Total number of Limit Nodes: | 2 |
Graph
Function 06730040 Relevance: 9.0, Strings: 6, Instructions: 1480COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06739700 Relevance: 8.0, Strings: 6, Instructions: 467COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0673C450 Relevance: 4.3, Strings: 3, Instructions: 564COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06735E38 Relevance: 3.0, Strings: 2, Instructions: 474COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0673E0D8 Relevance: 2.8, Strings: 2, Instructions: 334COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0321A1DB Relevance: 2.8, Instructions: 2763COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0321D480 Relevance: 2.3, Instructions: 2300COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06733678 Relevance: 1.8, Strings: 1, Instructions: 589COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 032141A0 Relevance: 1.5, Strings: 1, Instructions: 281COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03213E58 Relevance: 1.5, Strings: 1, Instructions: 238COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067346B0 Relevance: .8, Instructions: 819COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0673A240 Relevance: .7, Instructions: 652COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067392E3 Relevance: .6, Instructions: 568COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03214A70 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0321675C Relevance: 1.6, APIs: 1, Instructions: 65fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03217458 Relevance: 1.6, APIs: 1, Instructions: 64fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0673E650 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0673E658 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01972BE6 Relevance: 1.4, Strings: 1, Instructions: 150COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01972937 Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01972C84 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0171D3BC Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0171D044 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0171D20C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01972C90 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01970B28 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0197050F Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01970B38 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0171D3B7 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0171D03F Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0171D207 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 019706C2 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01972462 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 019706C8 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01972468 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01973292 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01970BEF Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01973168 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 019732A0 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01973238 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 019707BA Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01973330 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01973248 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 019707C0 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01970CCF Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01970B18 Relevance: .0, Instructions: 8COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06735758 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06733DA7 Relevance: 2.9, Strings: 2, Instructions: 427COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|