Windows
Analysis Report
Wzphku.exe
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Wzphku.exe (PID: 2836 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 3536 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 6480 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 3184 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 5968 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 6208 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 6392 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 4072 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 3772 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 5796 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B) - Wzphku.exe (PID: 5584 cmdline:
C:\Users\u ser\Deskto p\Wzphku.e xe MD5: EFFFB97AA9F53110AB5035C995E7D62B)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Long String: |
Source: | Static PE information: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Static file information: | |||
Source: | Section loaded: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: |
Source: | Static PE information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Windows Management Instrumentation | Path Interception | 11 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Disable or Modify Tools | LSASS Memory | 21 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | 2 Non-Application Layer Protocol | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 21 Virtualization/Sandbox Evasion | Security Account Manager | 12 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 3 Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | 11 Software Packing | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 1 Ingress Tool Transfer | Data Destruction | Virtual Private Server | Employee Names | ||
Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Process Injection | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Scheduled Transfer | Fallback Channels | Data Encrypted for Impact | Server | Gather Victim Network Information | ||
Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Obfuscated Files or Information | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Data Transfer Size Limits | Multiband Communication | Service Stop | Botnet | Domain Properties |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
34% | ReversingLabs | Win32.Trojan.Generic | ||
47% | Virustotal | Browse | ||
100% | Avira | HEUR/AGEN.1323350 | ||
100% | Joe Sandbox ML |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
the.earth.li | 93.93.131.124 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
93.93.131.124 | the.earth.li | United Kingdom | 44684 | MYTHICMythicBeastsLtdGB | false |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1342225 |
Start date and time: | 2023-11-14 11:16:31 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 5m 43s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Run name: | Run with higher sleep bypass |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | Wzphku.exe |
Detection: | MAL |
Classification: | mal68.evad.winEXE@21/1@1/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
93.93.131.124 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
the.earth.li | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | vkeylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AZORult | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MYTHICMythicBeastsLtdGB | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Glupteba, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AveMaria, UACMe | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Process: | C:\Users\user\Desktop\Wzphku.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1153 |
Entropy (8bit): | 5.361204690044335 |
Encrypted: | false |
SSDEEP: | 24:ML9E4KlKDE4KhKiKhRAE4KzeRE4KoE4Ty1KIE4oKNzKoM:MxHKlYHKh3oRAHKzeRHKoH8tHo60 |
MD5: | 047933859FA1F440AA5934FB970A3E6A |
SHA1: | 2DA4BE3C3AEA7272370955BD89B39E659F52D8EA |
SHA-256: | F1BA475E3438897324A9B81BB64278EF1331247896C42D280096EFBC14D3B0C5 |
SHA-512: | 08CC3BA225690029E61C029548E6A39F14812183B4439A55F1E1FCD827B02AC449B6F25D0A9A1376E9BA64FFA66AE3478BC276DD5895BF896A5A7D9207AC1100 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.0517663565587645 |
TrID: |
|
File name: | Wzphku.exe |
File size: | 425'472 bytes |
MD5: | efffb97aa9f53110ab5035c995e7d62b |
SHA1: | 8594e94f8991efba6cad2b90d44ba0a8176ce941 |
SHA256: | aa0668633c7c710b0a09adc99362b4a3547307f0b3f1338ae731c35d9b071d88 |
SHA512: | 5641d91f36e34a90854e55f304730c32c19cc22f58f35e3eca1749be51d7b002c53926bf4e05b9690556133341675110d75afe521cc178bbe236c71923a6e1a2 |
SSDEEP: | 12288:iUkdr8MYQ4RB2I3t8tfDkKeXXfmDTh6+:/7t85kFMt |
TLSH: | 14946C26FB93959DE265533EC58F8808836792D0A273E70E7DEC33DA4AC33665E64341 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Ke.................t..........^.... ........@.. ....................................`................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x46935e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x654BD8C7 [Wed Nov 8 18:51:51 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x69310 | 0x4b | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6a000 | 0x560 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6c000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x67364 | 0x67400 | False | 0.6433773456416465 | data | 7.066203079852089 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x6a000 | 0x560 | 0x600 | False | 0.4010416666666667 | data | 3.9358431649315366 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x6c000 | 0xc | 0x200 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x6a0a0 | 0x2d4 | data | 0.43646408839779005 | ||
RT_MANIFEST | 0x6a374 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 14, 2023 11:18:05.346257925 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:05.346297026 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:05.346388102 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:05.360270023 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:05.360291004 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:05.962430954 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:05.962703943 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:05.968910933 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:05.968944073 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:05.969645977 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:06.019258976 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:06.069823980 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:06.117263079 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:06.527664900 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:06.527838945 CET | 443 | 49710 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:06.527956009 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:06.542164087 CET | 49710 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:06.544166088 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:06.544244051 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:06.544387102 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:06.544765949 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:06.544781923 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.141227007 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.143795013 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:07.143821001 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.712625027 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.712660074 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.712788105 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:07.712804079 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.753572941 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:07.997916937 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.997957945 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.998001099 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:07.998039007 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:07.998171091 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.998231888 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:07.998436928 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:07.998492956 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.083158970 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.083368063 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.283998013 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.284147978 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.284158945 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.284166098 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.284257889 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.284931898 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.285002947 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.285052061 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.285105944 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.326896906 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.327061892 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.327266932 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.327342033 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.368771076 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.368942022 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.570547104 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.570700884 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.570842028 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.570888996 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.570924997 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.570944071 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.570957899 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.570988894 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.571413040 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.571499109 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.571976900 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.572057962 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.572254896 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.572338104 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.572520018 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.572626114 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.573132992 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.573220968 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.573611021 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.573712111 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.612788916 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.612941980 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.613059044 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.613156080 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.613349915 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.613406897 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.654445887 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.654551983 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.654655933 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.654690981 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.654783964 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.856672049 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.856764078 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.856899977 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.856969118 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.857633114 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.857707977 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.858056068 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.858127117 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.858599901 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.858669043 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.859008074 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.859126091 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.859380960 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.859447002 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.859716892 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.859787941 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.860215902 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.860285044 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.860620022 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.860683918 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.861007929 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.861082077 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.861442089 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.861520052 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.861850023 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.861921072 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.862330914 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.862395048 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.862696886 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.862766027 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.863049984 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.863120079 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.863498926 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.863569021 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.863931894 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.864008904 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.898699999 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.898814917 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.898911953 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.898997068 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.899137974 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.899226904 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.899518013 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.899579048 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.899782896 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.899843931 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.900330067 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.900397062 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.939506054 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.939675093 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.940602064 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.940697908 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.940814018 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.940882921 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:08.941396952 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:08.941517115 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.142728090 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.142813921 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.142878056 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.142940998 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.143238068 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.143309116 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.143696070 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.143762112 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.144237995 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.144306898 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.144887924 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.144948959 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.145446062 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.145507097 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.145806074 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.145865917 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.146212101 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.146276951 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.146588087 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.146660089 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.146976948 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.147102118 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.147322893 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.147384882 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.147797108 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.147866011 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.148222923 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.148294926 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.148720026 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.148792028 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.148940086 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.148997068 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.149435997 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.149517059 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.149781942 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.149846077 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.150223970 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.150295973 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.150609016 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.150666952 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.150841951 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.150902033 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.151177883 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.151236057 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.151727915 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.151793003 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.152059078 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.152122974 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.152388096 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.152446032 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.152899027 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.152960062 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.153028011 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.153094053 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.153532028 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.153603077 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.153902054 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.153968096 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.154370070 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.154452085 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.154817104 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.154880047 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.155215979 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.155354023 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.155574083 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.155651093 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.155956030 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.156013966 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.156399965 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.156459093 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.156682968 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.156738997 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.185154915 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.185226917 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.185394049 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.185482979 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.185710907 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.185781002 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.186048031 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.186162949 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.186527014 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.186644077 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.187069893 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.187129021 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.187521935 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.187583923 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.188050032 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.188107967 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.188648939 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.188714981 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.188883066 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.188941002 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.189358950 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.189439058 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.189668894 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.189723015 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.225354910 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.225461006 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.225589991 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.225589991 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.225605965 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.225665092 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.227118969 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.227196932 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.228234053 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.228271961 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.228307009 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.228315115 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.228327990 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.228358030 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.228482008 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.228526115 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.228539944 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.228545904 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.228585005 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.228734016 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.228797913 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.429135084 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.429251909 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.429358959 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.429435015 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.429728031 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.429807901 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.430079937 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.430152893 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.430634975 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.430706024 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.430877924 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.430953026 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.431266069 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.431337118 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.431847095 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.431917906 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.432147980 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.432215929 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.432518959 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.432596922 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.432998896 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.433065891 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.433260918 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.433329105 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.433552980 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.433623075 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.434165001 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.434235096 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.434519053 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.434587002 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.434871912 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.434942961 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.435298920 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.435368061 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.435776949 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.435842037 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.435880899 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.435946941 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.436199903 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.436275959 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.436384916 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.436455011 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.436686993 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.436774969 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.436969042 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.437036991 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.437164068 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.437232018 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.437465906 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.437537909 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.437882900 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.437958002 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.438167095 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.438235998 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.438374043 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.438452959 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.438574076 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.438642025 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.438991070 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.439068079 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.439301968 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.439374924 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.439426899 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.439492941 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.439773083 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.439840078 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.439982891 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.440052986 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.440548897 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.440587044 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.440617085 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.440644026 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.440656900 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.440692902 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.440876961 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.440949917 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.440993071 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.441066980 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.441133022 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.441272020 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.441343069 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.441514969 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.441584110 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.441808939 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.441873074 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.442048073 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.442122936 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.442291975 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.442372084 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.442575932 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.442647934 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.442789078 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.442852974 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.443126917 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.443195105 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.443444967 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.443511963 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.443764925 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.443835020 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.444013119 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.444078922 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.444282055 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.444345951 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.444608927 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.444678068 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.444977045 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.445041895 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.445044041 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.445054054 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.445095062 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.445339918 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.445410013 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.445563078 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.445625067 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.445962906 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.446033001 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.446197033 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.446266890 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.446453094 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.446532011 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.446805000 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.446883917 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.447062016 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.447129011 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.447283983 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.447350025 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.447700024 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.447796106 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.447964907 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.448040009 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.448297977 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.448369026 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.448551893 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.448632002 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.448910952 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.448976040 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.449120998 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.449183941 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.449414015 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.449484110 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.449701071 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.449769020 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.449902058 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.449971914 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.450172901 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.450244904 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.450404882 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.450530052 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.470967054 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.471056938 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.471167088 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.471242905 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.471780062 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.471858978 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.472067118 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.472137928 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.472273111 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.472340107 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.472417116 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.472479105 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.472668886 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.472737074 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.472831011 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.472902060 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.473026991 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.473100901 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.473277092 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.473342896 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.473480940 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.473548889 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.473675966 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.473747969 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.473895073 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.473961115 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.474086046 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.474149942 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.474280119 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.474344969 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.474471092 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.474534988 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.474706888 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.474773884 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.474901915 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.474981070 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.475099087 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.475162983 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.475337982 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.475400925 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.475529909 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.475599051 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.475730896 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.475801945 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.475900888 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.475964069 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.476128101 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.476193905 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.511440039 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.511507988 CET | 443 | 49711 | 93.93.131.124 | 192.168.2.5 |
Nov 14, 2023 11:18:09.511558056 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.511581898 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Nov 14, 2023 11:18:09.512085915 CET | 49711 | 443 | 192.168.2.5 | 93.93.131.124 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 14, 2023 11:18:05.062855959 CET | 58469 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 14, 2023 11:18:05.333606958 CET | 53 | 58469 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 14, 2023 11:18:05.062855959 CET | 192.168.2.5 | 1.1.1.1 | 0x1fd2 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 14, 2023 11:18:05.333606958 CET | 1.1.1.1 | 192.168.2.5 | 0x1fd2 | No error (0) | 93.93.131.124 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.5 | 49710 | 93.93.131.124 | 443 | C:\Users\user\Desktop\Wzphku.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-11-14 10:18:06 UTC | 0 | OUT | |
2023-11-14 10:18:06 UTC | 0 | IN | |
2023-11-14 10:18:06 UTC | 0 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.5 | 49711 | 93.93.131.124 | 443 | C:\Users\user\Desktop\Wzphku.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
2023-11-14 10:18:07 UTC | 0 | OUT | |
2023-11-14 10:18:07 UTC | 0 | IN | |
2023-11-14 10:18:07 UTC | 0 | IN | |
2023-11-14 10:18:07 UTC | 8 | IN | |
2023-11-14 10:18:07 UTC | 16 | IN | |
2023-11-14 10:18:07 UTC | 24 | IN | |
2023-11-14 10:18:08 UTC | 32 | IN | |
2023-11-14 10:18:08 UTC | 39 | IN | |
2023-11-14 10:18:08 UTC | 47 | IN | |
2023-11-14 10:18:08 UTC | 55 | IN | |
2023-11-14 10:18:08 UTC | 63 | IN | |
2023-11-14 10:18:08 UTC | 71 | IN | |
2023-11-14 10:18:08 UTC | 78 | IN | |
2023-11-14 10:18:08 UTC | 86 | IN | |
2023-11-14 10:18:08 UTC | 94 | IN | |
2023-11-14 10:18:08 UTC | 102 | IN | |
2023-11-14 10:18:08 UTC | 110 | IN | |
2023-11-14 10:18:08 UTC | 118 | IN | |
2023-11-14 10:18:08 UTC | 125 | IN | |
2023-11-14 10:18:08 UTC | 133 | IN | |
2023-11-14 10:18:08 UTC | 141 | IN | |
2023-11-14 10:18:08 UTC | 149 | IN | |
2023-11-14 10:18:08 UTC | 157 | IN | |
2023-11-14 10:18:08 UTC | 164 | IN | |
2023-11-14 10:18:08 UTC | 172 | IN | |
2023-11-14 10:18:08 UTC | 180 | IN | |
2023-11-14 10:18:08 UTC | 188 | IN | |
2023-11-14 10:18:08 UTC | 196 | IN | |
2023-11-14 10:18:08 UTC | 203 | IN | |
2023-11-14 10:18:08 UTC | 211 | IN | |
2023-11-14 10:18:08 UTC | 219 | IN | |
2023-11-14 10:18:08 UTC | 227 | IN | |
2023-11-14 10:18:08 UTC | 235 | IN | |
2023-11-14 10:18:08 UTC | 243 | IN | |
2023-11-14 10:18:08 UTC | 250 | IN | |
2023-11-14 10:18:08 UTC | 258 | IN | |
2023-11-14 10:18:08 UTC | 266 | IN | |
2023-11-14 10:18:08 UTC | 274 | IN | |
2023-11-14 10:18:08 UTC | 282 | IN | |
2023-11-14 10:18:08 UTC | 289 | IN | |
2023-11-14 10:18:08 UTC | 297 | IN | |
2023-11-14 10:18:08 UTC | 305 | IN | |
2023-11-14 10:18:08 UTC | 313 | IN | |
2023-11-14 10:18:08 UTC | 321 | IN | |
2023-11-14 10:18:08 UTC | 328 | IN | |
2023-11-14 10:18:08 UTC | 336 | IN | |
2023-11-14 10:18:08 UTC | 344 | IN | |
2023-11-14 10:18:08 UTC | 352 | IN | |
2023-11-14 10:18:08 UTC | 360 | IN | |
2023-11-14 10:18:08 UTC | 368 | IN | |
2023-11-14 10:18:08 UTC | 375 | IN | |
2023-11-14 10:18:08 UTC | 383 | IN | |
2023-11-14 10:18:08 UTC | 391 | IN | |
2023-11-14 10:18:08 UTC | 399 | IN | |
2023-11-14 10:18:08 UTC | 407 | IN | |
2023-11-14 10:18:08 UTC | 414 | IN | |
2023-11-14 10:18:09 UTC | 422 | IN | |
2023-11-14 10:18:09 UTC | 430 | IN | |
2023-11-14 10:18:09 UTC | 438 | IN | |
2023-11-14 10:18:09 UTC | 446 | IN | |
2023-11-14 10:18:09 UTC | 453 | IN | |
2023-11-14 10:18:09 UTC | 461 | IN | |
2023-11-14 10:18:09 UTC | 469 | IN | |
2023-11-14 10:18:09 UTC | 477 | IN | |
2023-11-14 10:18:09 UTC | 485 | IN | |
2023-11-14 10:18:09 UTC | 493 | IN | |
2023-11-14 10:18:09 UTC | 500 | IN | |
2023-11-14 10:18:09 UTC | 508 | IN | |
2023-11-14 10:18:09 UTC | 516 | IN | |
2023-11-14 10:18:09 UTC | 524 | IN | |
2023-11-14 10:18:09 UTC | 532 | IN | |
2023-11-14 10:18:09 UTC | 539 | IN | |
2023-11-14 10:18:09 UTC | 547 | IN | |
2023-11-14 10:18:09 UTC | 555 | IN | |
2023-11-14 10:18:09 UTC | 563 | IN | |
2023-11-14 10:18:09 UTC | 571 | IN | |
2023-11-14 10:18:09 UTC | 578 | IN | |
2023-11-14 10:18:09 UTC | 586 | IN | |
2023-11-14 10:18:09 UTC | 594 | IN | |
2023-11-14 10:18:09 UTC | 602 | IN | |
2023-11-14 10:18:09 UTC | 610 | IN | |
2023-11-14 10:18:09 UTC | 618 | IN | |
2023-11-14 10:18:09 UTC | 625 | IN | |
2023-11-14 10:18:09 UTC | 633 | IN | |
2023-11-14 10:18:09 UTC | 641 | IN | |
2023-11-14 10:18:09 UTC | 649 | IN | |
2023-11-14 10:18:09 UTC | 657 | IN | |
2023-11-14 10:18:09 UTC | 664 | IN | |
2023-11-14 10:18:09 UTC | 672 | IN | |
2023-11-14 10:18:09 UTC | 680 | IN | |
2023-11-14 10:18:09 UTC | 688 | IN | |
2023-11-14 10:18:09 UTC | 696 | IN | |
2023-11-14 10:18:09 UTC | 703 | IN | |
2023-11-14 10:18:09 UTC | 711 | IN | |
2023-11-14 10:18:09 UTC | 719 | IN | |
2023-11-14 10:18:09 UTC | 727 | IN | |
2023-11-14 10:18:09 UTC | 735 | IN | |
2023-11-14 10:18:09 UTC | 743 | IN | |
2023-11-14 10:18:09 UTC | 750 | IN | |
2023-11-14 10:18:09 UTC | 758 | IN | |
2023-11-14 10:18:09 UTC | 766 | IN | |
2023-11-14 10:18:09 UTC | 774 | IN | |
2023-11-14 10:18:09 UTC | 782 | IN | |
2023-11-14 10:18:09 UTC | 789 | IN | |
2023-11-14 10:18:09 UTC | 797 | IN | |
2023-11-14 10:18:09 UTC | 805 | IN | |
2023-11-14 10:18:09 UTC | 813 | IN | |
2023-11-14 10:18:09 UTC | 821 | IN | |
2023-11-14 10:18:09 UTC | 828 | IN | |
2023-11-14 10:18:09 UTC | 836 | IN | |
2023-11-14 10:18:09 UTC | 844 | IN | |
2023-11-14 10:18:09 UTC | 852 | IN | |
2023-11-14 10:18:09 UTC | 860 | IN | |
2023-11-14 10:18:09 UTC | 868 | IN | |
2023-11-14 10:18:09 UTC | 875 | IN | |
2023-11-14 10:18:09 UTC | 883 | IN | |
2023-11-14 10:18:09 UTC | 891 | IN | |
2023-11-14 10:18:09 UTC | 899 | IN | |
2023-11-14 10:18:09 UTC | 907 | IN | |
2023-11-14 10:18:09 UTC | 914 | IN | |
2023-11-14 10:18:09 UTC | 922 | IN | |
2023-11-14 10:18:09 UTC | 930 | IN | |
2023-11-14 10:18:09 UTC | 938 | IN | |
2023-11-14 10:18:09 UTC | 946 | IN | |
2023-11-14 10:18:09 UTC | 953 | IN | |
2023-11-14 10:18:09 UTC | 961 | IN | |
2023-11-14 10:18:09 UTC | 969 | IN | |
2023-11-14 10:18:09 UTC | 977 | IN | |
2023-11-14 10:18:09 UTC | 985 | IN | |
2023-11-14 10:18:09 UTC | 993 | IN | |
2023-11-14 10:18:09 UTC | 1000 | IN | |
2023-11-14 10:18:09 UTC | 1008 | IN | |
2023-11-14 10:18:09 UTC | 1016 | IN | |
2023-11-14 10:18:09 UTC | 1024 | IN | |
2023-11-14 10:18:09 UTC | 1032 | IN | |
2023-11-14 10:18:09 UTC | 1039 | IN | |
2023-11-14 10:18:09 UTC | 1047 | IN | |
2023-11-14 10:18:09 UTC | 1055 | IN | |
2023-11-14 10:18:09 UTC | 1063 | IN | |
2023-11-14 10:18:09 UTC | 1071 | IN | |
2023-11-14 10:18:09 UTC | 1078 | IN | |
2023-11-14 10:18:09 UTC | 1086 | IN | |
2023-11-14 10:18:09 UTC | 1094 | IN | |
2023-11-14 10:18:09 UTC | 1102 | IN | |
2023-11-14 10:18:09 UTC | 1110 | IN | |
2023-11-14 10:18:09 UTC | 1118 | IN | |
2023-11-14 10:18:09 UTC | 1125 | IN | |
2023-11-14 10:18:09 UTC | 1133 | IN | |
2023-11-14 10:18:09 UTC | 1141 | IN | |
2023-11-14 10:18:09 UTC | 1149 | IN | |
2023-11-14 10:18:09 UTC | 1157 | IN | |
2023-11-14 10:18:09 UTC | 1164 | IN | |
2023-11-14 10:18:09 UTC | 1172 | IN | |
2023-11-14 10:18:09 UTC | 1180 | IN | |
2023-11-14 10:18:09 UTC | 1188 | IN | |
2023-11-14 10:18:09 UTC | 1196 | IN | |
2023-11-14 10:18:09 UTC | 1203 | IN | |
2023-11-14 10:18:09 UTC | 1211 | IN | |
2023-11-14 10:18:09 UTC | 1219 | IN | |
2023-11-14 10:18:09 UTC | 1227 | IN | |
2023-11-14 10:18:09 UTC | 1235 | IN | |
2023-11-14 10:18:09 UTC | 1243 | IN | |
2023-11-14 10:18:09 UTC | 1250 | IN | |
2023-11-14 10:18:09 UTC | 1258 | IN | |
2023-11-14 10:18:09 UTC | 1266 | IN | |
2023-11-14 10:18:09 UTC | 1274 | IN | |
2023-11-14 10:18:09 UTC | 1282 | IN | |
2023-11-14 10:18:09 UTC | 1289 | IN | |
2023-11-14 10:18:09 UTC | 1297 | IN | |
2023-11-14 10:18:09 UTC | 1305 | IN | |
2023-11-14 10:18:09 UTC | 1313 | IN | |
2023-11-14 10:18:09 UTC | 1321 | IN | |
2023-11-14 10:18:09 UTC | 1328 | IN | |
2023-11-14 10:18:09 UTC | 1336 | IN | |
2023-11-14 10:18:09 UTC | 1344 | IN | |
2023-11-14 10:18:09 UTC | 1352 | IN | |
2023-11-14 10:18:09 UTC | 1360 | IN | |
2023-11-14 10:18:09 UTC | 1368 | IN | |
2023-11-14 10:18:09 UTC | 1375 | IN | |
2023-11-14 10:18:09 UTC | 1383 | IN | |
2023-11-14 10:18:09 UTC | 1391 | IN | |
2023-11-14 10:18:09 UTC | 1399 | IN | |
2023-11-14 10:18:09 UTC | 1407 | IN | |
2023-11-14 10:18:09 UTC | 1414 | IN | |
2023-11-14 10:18:09 UTC | 1422 | IN | |
2023-11-14 10:18:09 UTC | 1430 | IN | |
2023-11-14 10:18:09 UTC | 1438 | IN | |
2023-11-14 10:18:09 UTC | 1446 | IN | |
2023-11-14 10:18:09 UTC | 1453 | IN | |
2023-11-14 10:18:09 UTC | 1461 | IN | |
2023-11-14 10:18:09 UTC | 1469 | IN | |
2023-11-14 10:18:09 UTC | 1477 | IN | |
2023-11-14 10:18:09 UTC | 1485 | IN | |
2023-11-14 10:18:09 UTC | 1493 | IN | |
2023-11-14 10:18:09 UTC | 1500 | IN | |
2023-11-14 10:18:09 UTC | 1508 | IN | |
2023-11-14 10:18:09 UTC | 1516 | IN | |
2023-11-14 10:18:09 UTC | 1524 | IN | |
2023-11-14 10:18:09 UTC | 1532 | IN | |
2023-11-14 10:18:09 UTC | 1539 | IN | |
2023-11-14 10:18:09 UTC | 1547 | IN | |
2023-11-14 10:18:09 UTC | 1555 | IN | |
2023-11-14 10:18:09 UTC | 1563 | IN | |
2023-11-14 10:18:09 UTC | 1571 | IN | |
2023-11-14 10:18:09 UTC | 1578 | IN | |
2023-11-14 10:18:09 UTC | 1586 | IN | |
2023-11-14 10:18:09 UTC | 1594 | IN | |
2023-11-14 10:18:09 UTC | 1602 | IN | |
2023-11-14 10:18:09 UTC | 1610 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:17:28 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5e0000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xf10000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x5a0000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x840000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xdb0000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xd40000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 9 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xd10000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 10 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x210000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 11 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xda0000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 12 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xf50000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 13 |
Start time: | 11:18:08 |
Start date: | 14/11/2023 |
Path: | C:\Users\user\Desktop\Wzphku.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xa90000 |
File size: | 425'472 bytes |
MD5 hash: | EFFFB97AA9F53110AB5035C995E7D62B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |