Edit tour
Windows
Analysis Report
RFQ-T56797W_1.xlsx
Overview
General Information
Detection
FormBook, NSISDropper
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Sigma detected: EQNEDT32.EXE connecting to internet
Yara detected NSISDropper
System process connects to network (likely due to code injection or exploit)
Detected unpacking (changes PE section rights)
Antivirus detection for URL or domain
Snort IDS alert for network traffic
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected FormBook
Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Sigma detected: File Dropped By EQNEDT32EXE
Multi AV Scanner detection for domain / URL
Maps a DLL or memory area into another process
Shellcode detected
Office equation editor drops PE file
Tries to detect virtualization through RDTSC time measurements
Sample uses process hollowing technique
Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802)
Modifies the prolog of user mode functions (user mode inline hooks)
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Queues an APC in another process (thread injection)
Machine Learning detection for dropped file
Modifies the context of a thread in another process (thread injection)
C2 URLs / IPs found in malware configuration
Office equation editor establishes network connection
Found decision node followed by non-executed suspicious APIs
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Sample execution stops while process was sleeping (likely an evasion)
HTTP GET or POST without a user agent
Document misses a certain OLE stream usually present in this Microsoft Office document type
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Potential document exploit detected (unknown TCP traffic)
Drops PE files
Contains functionality to read the PEB
Uses a known web browser user agent for HTTP communication
Checks if the current process is being debugged
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Creates a process in suspended mode (likely to inject code)
Contains functionality for read data from the clipboard
Yara signature match
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to shutdown / reboot the system
Internet Provider seen in connection with other malware
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Contains functionality to call native functions
Potential document exploit detected (performs DNS queries)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
IP address seen in connection with other malware
Contains functionality for execution timing, often used to detect debuggers
Enables debug privileges
Found inlined nop instructions (likely shell or obfuscated code)
Extensive use of GetProcAddress (often used to hide API calls)
Office Equation Editor has been started
Potential document exploit detected (performs HTTP gets)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Classification
- System is w7x64
- EXCEL.EXE (PID: 2028 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\EXCEL. EXE" /auto mation -Em bedding MD5: D53B85E21886D2AF9815C377537BCAC3)
- EQNEDT32.EXE (PID: 260 cmdline:
"C:\Progra m Files\Co mmon Files \Microsoft Shared\EQ UATION\EQN EDT32.EXE" -Embeddin g MD5: A87236E214F6D42A65F5DEDAC816AEC8) - word.exe (PID: 2204 cmdline:
C:\Users\u ser\AppDat a\Roaming\ word.exe MD5: AFFC03992E31B5D4324B41CBD40D911E) - oktuxvhtsq.exe (PID: 1784 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\oktuxv htsq.exe" MD5: CF92A3EC74E407574A58BCF121BEC4F1) - oktuxvhtsq.exe (PID: 1516 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\oktuxvh tsq.exe MD5: CF92A3EC74E407574A58BCF121BEC4F1) - explorer.exe (PID: 1244 cmdline:
C:\Windows \Explorer. EXE MD5: 38AE1B3C38FAEF56FE4907922F0385BA) - autochk.exe (PID: 2148 cmdline:
C:\Windows \SysWOW64\ autochk.ex e MD5: F88A52EB62019D6A62FDD9E08034DBD8) - chkdsk.exe (PID: 2052 cmdline:
C:\Windows \SysWOW64\ chkdsk.exe MD5: A01E18A156825557A24A643A2547AA8C) - cmd.exe (PID: 1932 cmdline:
/c del "C: \Users\use r\AppData\ Local\Temp \oktuxvhts q.exe" MD5: AD7B9C14083B52BC532FBA5948342B98)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Formbook, Formbo | FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware. |
{"C2 list": ["www.fakeittilyoumakeitfinance.com/ge06/"], "decoy": ["azaharparis.com", "nationaleventsafety.com", "covesstudy.com", "quinshon4.com", "moderco.net", "trailblazerbaby.com", "time-edu.net", "azeemtourism.com", "anakmedan3.click", "bookinternationaltours.com", "ulksht.top", "newswirex.com", "dingg.net", "waveoflife.pro", "miamirealestatecommercial.com", "rtplive77.xyz", "bowllywood.com", "automation-tools-84162.bond", "booptee.com", "ebx.lat", "gdlongzhong.icu", "seoulbeautytw.com", "bulgarianarchive.com", "pojipoji.com", "mochibees-wylie.com", "ecoboat.world", "eroyfw.top", "centralngs.com", "youtube-manager.site", "eatlust.com", "geutik.cfd", "credit-cards-16215.bond", "lodsoab.com", "jon188.ink", "52iwin.win", "juanmafit.com", "gamemuggaz.com", "oneresi.com", "pj69vip12.cyou", "west-paws.com", "chaineccn.com", "mentiti.com", "modeparisiennefr.com", "skyboxpro.net", "versebuild.xyz", "luxpsy.com", "nivaarnalawgroup.com", "c091627.com", "preppal.shop", "narrativepages.com", "yqsoysy.com", "diverseindiatours.com", "batcavela.com", "ayyp300.top", "daqtpt.cfd", "livers-guardplus.com", "chucobuilt.net", "qianxz109.xyz", "carat-automotive.com", "hndswicco.best", "workwithray.live", "sxchenggu.com", "sanpan010.com", "fufe066.xyz"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_XML_LegacyDrawing_AutoLoad_Document | detects AutoLoad documents using LegacyDrawing | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FormBook | Yara detected FormBook | Joe Security | ||
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
| |
Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com |
| |
Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group |
| |
Click to see the 35 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FormBook | Yara detected FormBook | Joe Security | ||
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
| |
Formbook_1 | autogenerated rule brought to you by yara-signator | Felix Bilstein - yara-signator at cocacoding dot com |
| |
Formbook | detect Formbook in memory | JPCERT/CC Incident Response Group |
| |
Click to see the 15 entries |
Exploits |
---|
Source: | Author: Joe Security: |
Source: | Author: Joe Security: |
Timestamp: | 192.168.2.2238.11.36.6849167802031412 11/14/23-13:28:23.777818 |
SID: | 2031412 |
Source Port: | 49167 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.2291.195.240.1949166802031412 11/14/23-13:28:02.320328 |
SID: | 2031412 |
Source Port: | 49166 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.22103.224.212.21249164802031412 11/14/23-13:27:01.556896 |
SID: | 2031412 |
Source Port: | 49164 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.223.33.130.19049168802031412 11/14/23-13:28:45.165462 |
SID: | 2031412 |
Source Port: | 49168 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.2234.149.87.4549169802031412 11/14/23-13:29:05.883659 |
SID: | 2031412 |
Source Port: | 49169 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.2241.185.64.15549162802021697 11/14/23-13:26:24.263209 |
SID: | 2021697 |
Source Port: | 49162 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Exploits |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Network connect: | Jump to behavior |
Source: | Process created: |
Source: | File opened: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 5_2_00405E93 | |
Source: | Code function: | 5_2_004054BD | |
Source: | Code function: | 5_2_00402671 | |
Source: | Code function: | 6_2_004016D0 | |
Source: | Code function: | 6_2_0042478A |
Software Vulnerabilities |
---|
Source: | Code function: | 2_2_036BBABB | |
Source: | Code function: | 2_2_036BBA9B | |
Source: | Code function: | 2_2_036BB92B | |
Source: | Code function: | 2_2_036BBA50 | |
Source: | Code function: | 2_2_036BB953 |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Code function: | 7_2_00417D74 | |
Source: | Code function: | 10_2_000D7D74 |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Networking |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | URLs: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | IP Address: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File created: | Jump to behavior |
Source: | DNS traffic detected: |
Source: | Code function: | 2_2_036BB92B |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | Code function: | 5_2_00404FC2 |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Code function: | 5_2_004047D3 | |
Source: | Code function: | 5_2_004061D4 | |
Source: | Code function: | 6_2_0040F085 | |
Source: | Code function: | 6_2_00413366 | |
Source: | Code function: | 6_2_004194C0 | |
Source: | Code function: | 6_2_00412570 | |
Source: | Code function: | 6_2_00417514 | |
Source: | Code function: | 6_2_0041261D | |
Source: | Code function: | 6_2_0041379B | |
Source: | Code function: | 6_2_0041D8DE | |
Source: | Code function: | 6_2_00412B19 | |
Source: | Code function: | 6_2_00426BA1 | |
Source: | Code function: | 6_2_00422EC9 | |
Source: | Code function: | 6_2_00412F31 | |
Source: | Code function: | 6_2_00428FBD | |
Source: | Code function: | 6_2_002408B7 | |
Source: | Code function: | 6_2_00240A42 | |
Source: | Code function: | 7_2_0041D810 | |
Source: | Code function: | 7_2_00401030 | |
Source: | Code function: | 7_2_0041EB0E | |
Source: | Code function: | 7_2_0041C3A7 | |
Source: | Code function: | 7_2_0041E4C5 | |
Source: | Code function: | 7_2_0041DDD4 | |
Source: | Code function: | 7_2_00402D89 | |
Source: | Code function: | 7_2_00402D90 | |
Source: | Code function: | 7_2_00409E4D | |
Source: | Code function: | 7_2_00409E50 | |
Source: | Code function: | 7_2_00402FB0 | |
Source: | Code function: | 7_2_0073E0C6 | |
Source: | Code function: | 7_2_0073E2E9 | |
Source: | Code function: | 7_2_0078A37B | |
Source: | Code function: | 7_2_00742305 | |
Source: | Code function: | 7_2_007663DB | |
Source: | Code function: | 7_2_007E63BF | |
Source: | Code function: | 7_2_007C443E | |
Source: | Code function: | 7_2_00786540 | |
Source: | Code function: | 7_2_0075C5F0 | |
Source: | Code function: | 7_2_007C05E3 | |
Source: | Code function: | 7_2_0078A634 | |
Source: | Code function: | 7_2_007E2622 | |
Source: | Code function: | 7_2_0074E6C1 | |
Source: | Code function: | 7_2_00744680 | |
Source: | Code function: | 7_2_0074C7BC | |
Source: | Code function: | 7_2_0076286D | |
Source: | Code function: | 7_2_0074C85C | |
Source: | Code function: | 7_2_0078C920 | |
Source: | Code function: | 7_2_007D49F5 | |
Source: | Code function: | 7_2_007569FE | |
Source: | Code function: | 7_2_007429B2 | |
Source: | Code function: | 7_2_007E098E | |
Source: | Code function: | 7_2_007C6BCB | |
Source: | Code function: | 7_2_007ECBA4 | |
Source: | Code function: | 7_2_007CAC5E | |
Source: | Code function: | 7_2_007E2C9C | |
Source: | Code function: | 7_2_0074CD5B | |
Source: | Code function: | 7_2_00770D3B | |
Source: | Code function: | 7_2_0075EE4C | |
Source: | Code function: | 7_2_00772E2F | |
Source: | Code function: | 7_2_00750F3F | |
Source: | Code function: | 7_2_007B2FDC | |
Source: | Code function: | 7_2_007DCFB1 | |
Source: | Code function: | 7_2_007BD06D | |
Source: | Code function: | 7_2_0075905A | |
Source: | Code function: | 7_2_00743040 | |
Source: | Code function: | 7_2_0076D005 | |
Source: | Code function: | 7_2_007CD13F | |
Source: | Code function: | 7_2_007E1238 | |
Source: | Code function: | 7_2_00747353 | |
Source: | Code function: | 7_2_0073F3CF | |
Source: | Code function: | 7_2_0077D47D | |
Source: | Code function: | 7_2_00775485 | |
Source: | Code function: | 7_2_00751489 | |
Source: | Code function: | 7_2_0074351F | |
Source: | Code function: | 7_2_007E35DA | |
Source: | Code function: | 7_2_007D771D | |
Source: | Code function: | 7_2_007757C3 | |
Source: | Code function: | 7_2_007C579A | |
Source: | Code function: | 7_2_007DF8EE | |
Source: | Code function: | 7_2_007BF8C4 | |
Source: | Code function: | 7_2_007C5955 | |
Source: | Code function: | 7_2_007C394B | |
Source: | Code function: | 7_2_007F3A83 | |
Source: | Code function: | 7_2_00767B00 | |
Source: | Code function: | 7_2_0073FBD7 | |
Source: | Code function: | 7_2_007CDBDA | |
Source: | Code function: | 7_2_007DFDDD | |
Source: | Code function: | 7_2_0076DF7C | |
Source: | Code function: | 7_2_007CBF14 | |
Source: | Code function: | 8_2_07D80B30 | |
Source: | Code function: | 8_2_07D80B32 | |
Source: | Code function: | 8_2_07D86232 | |
Source: | Code function: | 8_2_07D895CD | |
Source: | Code function: | 8_2_07D83912 | |
Source: | Code function: | 8_2_07D7DD02 | |
Source: | Code function: | 8_2_07D7C082 | |
Source: | Code function: | 8_2_07D85036 | |
Source: | Code function: | 8_2_0807F232 | |
Source: | Code function: | 8_2_0807E036 | |
Source: | Code function: | 8_2_08075082 | |
Source: | Code function: | 8_2_08076D02 | |
Source: | Code function: | 8_2_0807C912 | |
Source: | Code function: | 8_2_08079B32 | |
Source: | Code function: | 8_2_08079B30 | |
Source: | Code function: | 8_2_080825CD | |
Source: | Code function: | 10_2_0201E2E9 | |
Source: | Code function: | 10_2_02022305 | |
Source: | Code function: | 10_2_0206A37B | |
Source: | Code function: | 10_2_020C63BF | |
Source: | Code function: | 10_2_020463DB | |
Source: | Code function: | 10_2_0201E0C6 | |
Source: | Code function: | 10_2_020C2622 | |
Source: | Code function: | 10_2_0206A634 | |
Source: | Code function: | 10_2_02024680 | |
Source: | Code function: | 10_2_0202E6C1 | |
Source: | Code function: | 10_2_0202C7BC | |
Source: | Code function: | 10_2_020A443E | |
Source: | Code function: | 10_2_02066540 | |
Source: | Code function: | 10_2_020A05E3 | |
Source: | Code function: | 10_2_0203C5F0 | |
Source: | Code function: | 10_2_020CCBA4 | |
Source: | Code function: | 10_2_020A6BCB | |
Source: | Code function: | 10_2_0202C85C | |
Source: | Code function: | 10_2_0204286D | |
Source: | Code function: | 10_2_0206C920 | |
Source: | Code function: | 10_2_020C098E | |
Source: | Code function: | 10_2_020229B2 | |
Source: | Code function: | 10_2_020369FE | |
Source: | Code function: | 10_2_020B49F5 | |
Source: | Code function: | 10_2_02052E2F | |
Source: | Code function: | 10_2_0203EE4C | |
Source: | Code function: | 10_2_02030F3F | |
Source: | Code function: | 10_2_020BCFB1 | |
Source: | Code function: | 10_2_02092FDC | |
Source: | Code function: | 10_2_020AAC5E | |
Source: | Code function: | 10_2_020C2C9C | |
Source: | Code function: | 10_2_02050D3B | |
Source: | Code function: | 10_2_0202CD5B | |
Source: | Code function: | 10_2_020C1238 | |
Source: | Code function: | 10_2_02027353 | |
Source: | Code function: | 10_2_0201F3CF | |
Source: | Code function: | 10_2_0204D005 | |
Source: | Code function: | 10_2_02023040 | |
Source: | Code function: | 10_2_0203905A | |
Source: | Code function: | 10_2_0209D06D | |
Source: | Code function: | 10_2_020AD13F | |
Source: | Code function: | 10_2_020B771D | |
Source: | Code function: | 10_2_020A579A | |
Source: | Code function: | 10_2_020557C3 | |
Source: | Code function: | 10_2_0205D47D | |
Source: | Code function: | 10_2_02055485 | |
Source: | Code function: | 10_2_02031489 | |
Source: | Code function: | 10_2_0202351F | |
Source: | Code function: | 10_2_020C35DA | |
Source: | Code function: | 10_2_020D3A83 | |
Source: | Code function: | 10_2_02047B00 | |
Source: | Code function: | 10_2_020ADBDA | |
Source: | Code function: | 10_2_0201FBD7 | |
Source: | Code function: | 10_2_0209F8C4 | |
Source: | Code function: | 10_2_020BF8EE | |
Source: | Code function: | 10_2_020A394B | |
Source: | Code function: | 10_2_020A5955 | |
Source: | Code function: | 10_2_020ABF14 | |
Source: | Code function: | 10_2_0204DF7C | |
Source: | Code function: | 10_2_020BFDDD | |
Source: | Code function: | 10_2_000DC3A7 | |
Source: | Code function: | 10_2_000DE4C5 | |
Source: | Code function: | 10_2_000DEB0E | |
Source: | Code function: | 10_2_000C2D89 | |
Source: | Code function: | 10_2_000C2D90 | |
Source: | Code function: | 10_2_000C9E4D | |
Source: | Code function: | 10_2_000C9E50 | |
Source: | Code function: | 10_2_000C2FB0 |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 5_2_004030FB |
Source: | Code function: | 7_2_0041A320 | |
Source: | Code function: | 7_2_0041A3D0 | |
Source: | Code function: | 7_2_0041A450 | |
Source: | Code function: | 7_2_0041A500 | |
Source: | Code function: | 7_2_0041A3CA | |
Source: | Code function: | 7_2_0041A44B | |
Source: | Code function: | 7_2_00730078 | |
Source: | Code function: | 7_2_00730048 | |
Source: | Code function: | 7_2_007300C4 | |
Source: | Code function: | 7_2_0072F900 | |
Source: | Code function: | 7_2_0072F9F0 | |
Source: | Code function: | 7_2_0072FAE8 | |
Source: | Code function: | 7_2_0072FAD0 | |
Source: | Code function: | 7_2_0072FB68 | |
Source: | Code function: | 7_2_0072FBB8 | |
Source: | Code function: | 7_2_0072FC60 | |
Source: | Code function: | 7_2_0072FC90 | |
Source: | Code function: | 7_2_0072FDC0 | |
Source: | Code function: | 7_2_0072FD8C | |
Source: | Code function: | 7_2_0072FED0 | |
Source: | Code function: | 7_2_0072FEA0 | |
Source: | Code function: | 7_2_0072FFB4 | |
Source: | Code function: | 7_2_00730060 | |
Source: | Code function: | 7_2_0073010C | |
Source: | Code function: | 7_2_007301D4 | |
Source: | Code function: | 7_2_007307AC | |
Source: | Code function: | 7_2_00730C40 | |
Source: | Code function: | 7_2_007310D0 | |
Source: | Code function: | 7_2_00731148 | |
Source: | Code function: | 7_2_0072F8CC | |
Source: | Code function: | 7_2_00731930 | |
Source: | Code function: | 7_2_0072F938 | |
Source: | Code function: | 7_2_0072FA50 | |
Source: | Code function: | 7_2_0072FA20 | |
Source: | Code function: | 7_2_0072FAB8 | |
Source: | Code function: | 7_2_0072FB50 | |
Source: | Code function: | 7_2_0072FBE8 | |
Source: | Code function: | 7_2_0072FC48 | |
Source: | Code function: | 7_2_0072FC30 | |
Source: | Code function: | 7_2_0072FD5C | |
Source: | Code function: | 7_2_00731D80 | |
Source: | Code function: | 7_2_0072FE24 | |
Source: | Code function: | 7_2_0072FF34 | |
Source: | Code function: | 7_2_0072FFFC | |
Source: | Code function: | 8_2_08080E12 | |
Source: | Code function: | 8_2_0807F232 | |
Source: | Code function: | 8_2_08080E0A | |
Source: | Code function: | 10_2_020100C4 | |
Source: | Code function: | 10_2_020107AC | |
Source: | Code function: | 10_2_0200FAB8 | |
Source: | Code function: | 10_2_0200FAD0 | |
Source: | Code function: | 10_2_0200FAE8 | |
Source: | Code function: | 10_2_0200FB50 | |
Source: | Code function: | 10_2_0200FB68 | |
Source: | Code function: | 10_2_0200FBB8 | |
Source: | Code function: | 10_2_0200F900 | |
Source: | Code function: | 10_2_0200F9F0 | |
Source: | Code function: | 10_2_0200FED0 | |
Source: | Code function: | 10_2_0200FFB4 | |
Source: | Code function: | 10_2_0200FC60 | |
Source: | Code function: | 10_2_0200FD8C | |
Source: | Code function: | 10_2_0200FDC0 | |
Source: | Code function: | 10_2_02010048 | |
Source: | Code function: | 10_2_02010060 | |
Source: | Code function: | 10_2_02010078 | |
Source: | Code function: | 10_2_0201010C | |
Source: | Code function: | 10_2_020101D4 | |
Source: | Code function: | 10_2_02010C40 | |
Source: | Code function: | 10_2_020110D0 | |
Source: | Code function: | 10_2_02011148 | |
Source: | Code function: | 10_2_0200FA20 | |
Source: | Code function: | 10_2_0200FA50 | |
Source: | Code function: | 10_2_0200FBE8 | |
Source: | Code function: | 10_2_0200F8CC | |
Source: | Code function: | 10_2_02011930 | |
Source: | Code function: | 10_2_0200F938 | |
Source: | Code function: | 10_2_0200FE24 | |
Source: | Code function: | 10_2_0200FEA0 | |
Source: | Code function: | 10_2_0200FF34 | |
Source: | Code function: | 10_2_0200FFFC | |
Source: | Code function: | 10_2_0200FC30 | |
Source: | Code function: | 10_2_0200FC48 | |
Source: | Code function: | 10_2_0200FC90 | |
Source: | Code function: | 10_2_0200FD5C | |
Source: | Code function: | 10_2_02011D80 | |
Source: | Code function: | 10_2_000DA320 | |
Source: | Code function: | 10_2_000DA3D0 | |
Source: | Code function: | 10_2_000DA450 | |
Source: | Code function: | 10_2_000DA500 | |
Source: | Code function: | 10_2_000DA3CA | |
Source: | Code function: | 10_2_000DA44B |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | OLE indicator, Workbook stream: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Code function: | 5_2_00402053 |
Source: | Code function: | 5_2_00404292 |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static file information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Initial sample: |
Data Obfuscation |
---|
Source: | Unpacked PE file: |
Source: | Code function: | 6_2_00410309 | |
Source: | Code function: | 6_2_0040FD1D | |
Source: | Code function: | 7_2_0041E213 | |
Source: | Code function: | 7_2_0041D4C8 | |
Source: | Code function: | 7_2_0041D4C8 | |
Source: | Code function: | 7_2_0041D532 | |
Source: | Code function: | 7_2_0041D532 | |
Source: | Code function: | 7_2_0041868A | |
Source: | Code function: | 7_2_0073DFB4 | |
Source: | Code function: | 8_2_07D89B1F | |
Source: | Code function: | 8_2_07D89B03 | |
Source: | Code function: | 8_2_07D89AE7 | |
Source: | Code function: | 8_2_08082B03 | |
Source: | Code function: | 8_2_08082B1F | |
Source: | Code function: | 8_2_08082AE7 | |
Source: | Code function: | 10_2_0201DFB4 | |
Source: | Code function: | 10_2_000DE213 | |
Source: | Code function: | 10_2_000DD4C8 | |
Source: | Code function: | 10_2_000DD532 | |
Source: | Code function: | 10_2_000DD4C8 | |
Source: | Code function: | 10_2_000DD532 | |
Source: | Code function: | 10_2_000D868A |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | User mode code has changed: |
Source: | Code function: | 6_2_0040F085 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: |
Source: | Evasive API call chain: | graph_2-178 | ||
Source: | Evasive API call chain: | graph_6-22967 |
Source: | Decision node followed by non-executed suspicious API: | graph_8-13950 |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Code function: | 7_2_00409AA0 |
Source: | API call chain: | graph_5-3463 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 6_2_002407DA |
Source: | Code function: | 5_2_00405E93 | |
Source: | Code function: | 5_2_004054BD | |
Source: | Code function: | 5_2_00402671 | |
Source: | Code function: | 6_2_004016D0 | |
Source: | Code function: | 6_2_0042478A |
Source: | Code function: | 2_2_036BBABB | |
Source: | Code function: | 6_2_0024005F | |
Source: | Code function: | 6_2_0024013E | |
Source: | Code function: | 6_2_00240109 | |
Source: | Code function: | 6_2_0024017B | |
Source: | Code function: | 7_2_007200EA | |
Source: | Code function: | 7_2_00720080 | |
Source: | Code function: | 7_2_007426F8 | |
Source: | Code function: | 10_2_02000080 | |
Source: | Code function: | 10_2_020000EA | |
Source: | Code function: | 10_2_020226F8 |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 6_2_004100BC |
Source: | Code function: | 6_2_0042194B |
Source: | Code function: | 7_2_00409AA0 |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 7_2_0040ACE0 |
Source: | Code function: | 6_2_0041024E | |
Source: | Code function: | 6_2_004100BC | |
Source: | Code function: | 6_2_0041046C | |
Source: | Code function: | 6_2_00414847 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Section unmapped: | Jump to behavior |
Source: | Thread APC queued: | Jump to behavior |
Source: | Thread register set: | Jump to behavior | ||
Source: | Thread register set: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 6_2_004270EB | |
Source: | Code function: | 6_2_004273E2 | |
Source: | Code function: | 6_2_00427397 | |
Source: | Code function: | 6_2_0042747D | |
Source: | Code function: | 6_2_0041E421 | |
Source: | Code function: | 6_2_00427508 | |
Source: | Code function: | 6_2_0042775B | |
Source: | Code function: | 6_2_00427884 | |
Source: | Code function: | 6_2_0042798A | |
Source: | Code function: | 6_2_00427A60 | |
Source: | Code function: | 6_2_0041DF33 |
Source: | Code function: | 6_2_0040FF08 |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 6_2_0041030B |
Source: | Code function: | 5_2_004030FB |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 1 Scripting | Path Interception | 512 Process Injection | 1 Deobfuscate/Decode Files or Information | 1 Credential API Hooking | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | Exfiltration Over Other Network Medium | 5 Ingress Tool Transfer | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | 1 System Shutdown/Reboot | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | 1 Native API | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Scripting | LSASS Memory | 2 File and Directory Discovery | Remote Desktop Protocol | 1 Credential API Hooking | Exfiltration Over Bluetooth | 1 Encrypted Channel | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | 1 Shared Modules | Logon Script (Windows) | Logon Script (Windows) | 3 Obfuscated Files or Information | Security Account Manager | 127 System Information Discovery | SMB/Windows Admin Shares | 1 Clipboard Data | Automated Exfiltration | 3 Non-Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | 23 Exploitation for Client Execution | Login Hook | Login Hook | 1 Software Packing | NTDS | 141 Security Software Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 113 Application Layer Protocol | Data Destruction | Virtual Private Server | Employee Names | ||
Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Rootkit | LSA Secrets | 2 Virtualization/Sandbox Evasion | SSH | Keylogging | Scheduled Transfer | Fallback Channels | Data Encrypted for Impact | Server | Gather Victim Network Information | ||
Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 2 Process Discovery | VNC | GUI Input Capture | Data Transfer Size Limits | Multiband Communication | Service Stop | Botnet | Domain Properties | ||
External Remote Services | Systemd Timers | Startup Items | Startup Items | 2 Virtualization/Sandbox Evasion | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over C2 Channel | Commonly Used Port | Inhibit System Recovery | Web Services | DNS | ||
Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 512 Process Injection | Proc Filesystem | 1 Remote System Discovery | Cloud Services | Credential API Hooking | Exfiltration Over Alternative Protocol | Application Layer Protocol | Defacement | Serverless | Network Trust Dependencies |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | ReversingLabs | Document-Office.Exploit.CVE-2017-11882 | ||
55% | Virustotal | Browse | ||
100% | Avira | EXP/CVE-2017-11882.Gen |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML |
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
14% | Virustotal | Browse | ||
18% | Virustotal | Browse | ||
12% | Virustotal | Browse | ||
13% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
12% | Virustotal | Browse | ||
13% | Virustotal | Browse | ||
13% | Virustotal | Browse | ||
12% | Virustotal | Browse | ||
11% | Virustotal | Browse | ||
11% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing | ||
13% | Virustotal | Browse | ||
9% | Virustotal | Browse | ||
6% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
3% | Virustotal | Browse | ||
13% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
13% | Virustotal | Browse | ||
1% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing | ||
13% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
11% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
12% | Virustotal | Browse | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
centralngs.com | 3.33.130.190 | true | true |
| unknown |
mail.treeoflifeadventures.com | 41.185.64.155 | true | true |
| unknown |
parkingpage.namecheap.com | 91.195.240.19 | true | false | high | |
www.narrativepages.com | 103.224.212.212 | true | true |
| unknown |
www.miamirealestatecommercial.com | 206.188.193.211 | true | true |
| unknown |
td-ccm-neg-87-45.wixdns.net | 34.149.87.45 | true | true |
| unknown |
www.sxchenggu.com | 38.11.36.68 | true | true |
| unknown |
windowsupdatebg.s.llnwi.net | 69.164.40.8 | true | false |
| unknown |
www.credit-cards-16215.bond | unknown | unknown | true |
| unknown |
www.luxpsy.com | unknown | unknown | true |
| unknown |
www.centralngs.com | unknown | unknown | true |
| unknown |
www.west-paws.com | unknown | unknown | true |
| unknown |
www.pj69vip12.cyou | unknown | unknown | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| low |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
41.185.64.155 | mail.treeoflifeadventures.com | South Africa | 36943 | GridhostZA | true | |
103.224.212.212 | www.narrativepages.com | Australia | 133618 | TRELLIAN-AS-APTrellianPtyLimitedAU | true | |
206.188.193.211 | www.miamirealestatecommercial.com | United States | 55002 | DEFENSE-NETUS | true | |
38.11.36.68 | www.sxchenggu.com | United States | 174 | COGENT-174US | true | |
34.149.87.45 | td-ccm-neg-87-45.wixdns.net | United States | 2686 | ATGS-MMD-ASUS | true | |
91.195.240.19 | parkingpage.namecheap.com | Germany | 47846 | SEDO-ASDE | false | |
3.33.130.190 | centralngs.com | United States | 8987 | AMAZONEXPANSIONGB | true |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1342301 |
Start date and time: | 2023-11-14 13:25:07 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 10m 20s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | RFQ-T56797W_1.xlsx |
Detection: | MAL |
Classification: | mal100.troj.expl.evad.winXLSX@14/7@9/7 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 72.21.81.240
- Excluded domains from analysis (whitelisted): wu.ec.azureedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, hlb.apr-52dd2-0.edgecastdns.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, wu.azureedge.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
13:26:20 | API Interceptor | |
13:26:26 | API Interceptor | |
13:26:31 | API Interceptor | |
13:26:33 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
41.185.64.155 | Get hash | malicious | FormBook, NSISDropper | Browse |
| |
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | AgentTesla, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
parkingpage.namecheap.com | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
mail.treeoflifeadventures.com | Get hash | malicious | FormBook, NSISDropper | Browse |
| |
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | AgentTesla, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
GridhostZA | Get hash | malicious | FormBook, NSISDropper | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | AgentTesla, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
TRELLIAN-AS-APTrellianPtyLimitedAU | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, GuLoader | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook, NSISDropper | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
⊘No context
⊘No context
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\jakatrol2.1[1].exe
Download File
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 400516 |
Entropy (8bit): | 7.871791543277087 |
Encrypted: | false |
SSDEEP: | 6144:BBlL/NXMMK36zVS2WGWZu3B8W8ee5ssX8dsuM7AjWe/7mr027RSPII41hnDHjD+p:HfrKqz02XSHscDcP/7mAgSPI5DDD+p |
MD5: | AFFC03992E31B5D4324B41CBD40D911E |
SHA1: | 8C3138D444CA823DA937022FE29CB421B243A076 |
SHA-256: | 6F0AED190A415542A227D4DED6FF390ED8FBC0759B75E5BAEC91BD6C9C3FA752 |
SHA-512: | CD5B37C2C0A2CF8594C904084B2C3BDFFC9729B01B79B2135F903F21F502E9C41E8003DCD91DA6D87987DA62EEACC6FB075AE2EC3C901ECF9BE2FDFDF482CA1A |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1536 |
Entropy (8bit): | 1.1464700112623651 |
Encrypted: | false |
SSDEEP: | 3:YmsalTlLPltl2N81HRQjlORGt7RQ//W1XR9//3R9//3R9//:rl912N0xs+CFQXCB9Xh9Xh9X |
MD5: | 72F5C05B7EA8DD6059BF59F50B22DF33 |
SHA1: | D5AF52E129E15E3A34772806F6C5FBF132E7408E |
SHA-256: | 1DC0C8D7304C177AD0E74D3D2F1002EB773F4B180685A7DF6BBE75CCC24B0164 |
SHA-512: | 6FF1E2E6B99BD0A4ED7CA8A9E943551BCD73A0BEFCACE6F1B1106E88595C0846C9BB76CA99A33266FFEC2440CF6A440090F803ABBF28B208A6C7BC6310BEB39E |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Roaming\word.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 265216 |
Entropy (8bit): | 6.485367625505907 |
Encrypted: | false |
SSDEEP: | 6144:DCa08z788ULY36Y4+n/53FIzK2pAOObTlg:Ww78856WF2pMl |
MD5: | CF92A3EC74E407574A58BCF121BEC4F1 |
SHA1: | D117FA6B64E68EA1F24A030153D8BF3F160CB254 |
SHA-256: | 5165CE18A6AA81AE39B901D1AE017BDF4F4B6B2D984B97D6984C8B4B9FB1F652 |
SHA-512: | 172171AD3BB7AFC1AF81EC69C42EACBF8D1D3197B8381F392FE650134FDDACBF7DF687E966C36221BD077BE263A24A7173377EDF5A52667178824F050C48E3AB |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Roaming\word.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 209934 |
Entropy (8bit): | 7.992128423585276 |
Encrypted: | true |
SSDEEP: | 3072:Nm2BowKOqiLmXLw/q0Thw1uYcHFj1UrjjXOmb36STLNQUytr1UWouwDY3PZn8TGo:HJ69oHTUrjdtqEuwU3Bn8Hp |
MD5: | 2D23E7AB5BFB49D8D5C66C4551E9763E |
SHA1: | 9ED89848DE588F204C4AA29878D0AA26C7161239 |
SHA-256: | 671AD33D741EB3A83C2A7CC13C40E9E1FDB2C3CF3DB9D3EA512991700F06D329 |
SHA-512: | 5B2AEC2DB904FDDD124C53D91263F664DE2CD038DB592741AB1FEA91AD0BB80847931D95D04AC907C2B6C11D876E42819A1C1B629A4D3B37D9E115D8B50C860A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1478656 |
Entropy (8bit): | 7.232314461325792 |
Encrypted: | false |
SSDEEP: | 24576:DQI/UZhXtvkMeLaA4mzgY0ezXvKJGLR/GnhYzW:jsZh9TeOnXJ/h |
MD5: | F772FD06411290F17EEFFF387B404E79 |
SHA1: | EE88B130974D67810BB8C7BA8FB77993A22A48B0 |
SHA-256: | FD4F3EB1AB0E9CE2580B082ECCCD3DB3EBFD51514F0127979C66E6DCAAADF7CA |
SHA-512: | 8A4616941A8F58FEC7D4C09A88C8AA541C0EAEDD9FCCFE3F82156A21FFEB62908E025FEA9F269B02B056ADFB6C8A456467607FE05720C2E8FC6163DECDDB0DE7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 400516 |
Entropy (8bit): | 7.871791543277087 |
Encrypted: | false |
SSDEEP: | 6144:BBlL/NXMMK36zVS2WGWZu3B8W8ee5ssX8dsuM7AjWe/7mr027RSPII41hnDHjD+p:HfrKqz02XSHscDcP/7mAgSPI5DDD+p |
MD5: | AFFC03992E31B5D4324B41CBD40D911E |
SHA1: | 8C3138D444CA823DA937022FE29CB421B243A076 |
SHA-256: | 6F0AED190A415542A227D4DED6FF390ED8FBC0759B75E5BAEC91BD6C9C3FA752 |
SHA-512: | CD5B37C2C0A2CF8594C904084B2C3BDFFC9729B01B79B2135F903F21F502E9C41E8003DCD91DA6D87987DA62EEACC6FB075AE2EC3C901ECF9BE2FDFDF482CA1A |
Malicious: | true |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.4377382811115937 |
Encrypted: | false |
SSDEEP: | 3:vZ/FFDJw2fV:vBFFGS |
MD5: | 797869BB881CFBCDAC2064F92B26E46F |
SHA1: | 61C1B8FBF505956A77E9A79CE74EF5E281B01F4B |
SHA-256: | D4E4008DD7DFB936F22D9EF3CC569C6F88804715EAB8101045BA1CD0B081F185 |
SHA-512: | 1B8350E1500F969107754045EB84EA9F72B53498B1DC05911D6C7E771316C632EA750FBCE8AD3A82D664E3C65CC5251D0E4A21F750911AE5DC2FC3653E49F58D |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.998661776240753 |
TrID: |
|
File name: | RFQ-T56797W_1.xlsx |
File size: | 1'228'030 bytes |
MD5: | 138d7d8a55bef05ac6368488b3c9630d |
SHA1: | f9e93ed382d3005a7575443369207f2c3339309b |
SHA256: | 25e7a5ff8ca830bccda9a6617b31fb3992d4f780444cf3adc8cfb8056f26dd58 |
SHA512: | 5ad15b60f1e97b83ccd32b4bb06716552e429d4bec0cee78efa99a545ee05d4abbc6f7c896f7ce079431d90e6758aa4cb68a98672511e9f360a8509d1bf621f6 |
SSDEEP: | 12288:YWdBCwo3NVvUP/hkRQFTvW7HKReRSR0H8CK/+d5NUzsChpgUWxt7HCZoUPYG0hmL:YgtI/u/httvKaey0cgzobrhPEm+RlDS |
TLSH: | 0D4533A1D3AD958F6BA4C06426E45AC6212FFD9C95A339BD12B0E8C758093C7DF3F160 |
File Content Preview: | PK........@*mW...g....g.......[Content_Types].xmlUT.....Qe..Qe..Qe.UKK.1.....%W..U...">..TP.k.L..l.3cm....U..XZ...%...M...Y..)$..W.WvE.^.c.....W.#Q )o...*1...'.;..y.,....c.x,%.1.......0.Z.....JO...~.{(u...:.9.I...$k..S.nT.:r.$1.,....Dq..f.J........z.C...C |
Icon Hash: | 2562ab89a7b7bfbf |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Author: | |
Last Saved By: | |
Create Time: | 2022-11-18T02:05:27Z |
Last Saved Time: | 2022-11-18T02:07:12Z |
Creating Application: | |
Security: | 0 |
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
Stream Path: | \x1oLE10NAtIvE |
CLSID: | |
File Type: | data |
Stream Size: | 1462179 |
Entropy: | 7.225828857618607 |
Base64 Encoded: | True |
Data ASCII: | < . . . . a ' j & . . 6 . O . ( R . ? - U . . . p S D . . . j ) . Y i i X f { > . b $ . V m O . . . I P z C X 7 . > } o w . z . p . * . t . * . e Z . . P . t z . . L I . r . . A h { ] J B # @ ^ 2 . @ : l } " E c { . . . l . Q . . G h . K y W < 0 W . k ` c 6 . Q - W 4 A . . . H . A 9 d . . . . E r . . Y O r . 8 O n 9 I . < d . . } , h . i [ . = . . $ a ) # o = 3 ) . x ? 5 + ~ % y ` { i | z . . O & z & . T c . 0 @ . } . " & f E G . . . $ . < . . . . . ' 7 w . 8 . . V & _ . Z : 9 ! u } 0 J E k t _ . % " |
Data Raw: | 88 cb 3c 04 02 fc f7 98 f4 fd 01 08 61 27 be 6a f9 26 fb 81 c6 d2 c3 1e 05 8b 36 8b 16 b8 4f 98 b9 ff f7 d0 8b 28 52 ff d5 05 3f ce f4 f7 2d 55 1c ed f7 ff e0 03 c6 af 70 fb 9b 53 44 00 13 ce 0c 6a 8c 29 85 d9 ba e5 b4 df 59 69 69 c3 58 66 7b e1 3e f6 df 9f 62 24 18 56 f0 6d a9 d7 eb e2 4f 10 1d d0 1a 96 99 f5 49 b4 f7 50 dc 7a 43 8a 58 37 9e 02 20 3e 7d 6f 77 d2 ab c0 7a 1e 70 82 |
General | |
Stream Path: | WfMtcrVR |
CLSID: | |
File Type: | empty |
Stream Size: | 0 |
Entropy: | 0.0 |
Base64 Encoded: | False |
Data ASCII: | |
Data Raw: |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.2238.11.36.6849167802031412 11/14/23-13:28:23.777818 | TCP | 2031412 | ET TROJAN FormBook CnC Checkin (GET) | 49167 | 80 | 192.168.2.22 | 38.11.36.68 |
192.168.2.2291.195.240.1949166802031412 11/14/23-13:28:02.320328 | TCP | 2031412 | ET TROJAN FormBook CnC Checkin (GET) | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
192.168.2.22103.224.212.21249164802031412 11/14/23-13:27:01.556896 | TCP | 2031412 | ET TROJAN FormBook CnC Checkin (GET) | 49164 | 80 | 192.168.2.22 | 103.224.212.212 |
192.168.2.223.33.130.19049168802031412 11/14/23-13:28:45.165462 | TCP | 2031412 | ET TROJAN FormBook CnC Checkin (GET) | 49168 | 80 | 192.168.2.22 | 3.33.130.190 |
192.168.2.2234.149.87.4549169802031412 11/14/23-13:29:05.883659 | TCP | 2031412 | ET TROJAN FormBook CnC Checkin (GET) | 49169 | 80 | 192.168.2.22 | 34.149.87.45 |
192.168.2.2241.185.64.15549162802021697 11/14/23-13:26:24.263209 | TCP | 2021697 | ET TROJAN EXE Download Request To Wordpress Folder Likely Malicious | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 14, 2023 13:26:23.836503029 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.262617111 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.262689114 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.263209105 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.689160109 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701302052 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701364994 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701396942 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701405048 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701423883 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701446056 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701448917 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701483011 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701486111 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701525927 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701528072 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701565027 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701565027 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701605082 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701606035 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701642990 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701647043 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701679945 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.701680899 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:24.701724052 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:24.712649107 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.127831936 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.127876997 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.127916098 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.127955914 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.127994061 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.127996922 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.127996922 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.127996922 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128037930 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128076077 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128086090 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128086090 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128115892 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128118038 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128154993 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128185987 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128196955 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128225088 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128237009 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128245115 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128278971 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128284931 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128317118 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128340960 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128357887 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128362894 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128396034 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128403902 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128437042 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128444910 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128479004 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128520012 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128556013 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128585100 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128595114 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128598928 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128634930 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.128700972 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.128740072 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.130167961 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.130733967 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554306030 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554337025 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554351091 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554358959 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554373026 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554389000 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554413080 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554426908 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554444075 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554456949 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554521084 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554557085 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554651976 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554666996 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554706097 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554716110 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554722071 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554732084 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554744959 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554754972 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554769039 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554786921 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554917097 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554932117 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554944992 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554960012 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.554965973 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554979086 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.554997921 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555066109 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555107117 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555139065 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555155039 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555166960 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555180073 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555181026 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555193901 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555197954 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555212021 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555216074 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555226088 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555234909 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555248976 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555263996 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555372000 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555416107 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555448055 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555461884 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555474043 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555480957 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555489063 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555510998 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555571079 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555583954 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555597067 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555610895 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555620909 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555622101 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555639982 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555645943 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555663109 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555679083 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555783987 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555798054 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.555831909 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.555843115 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.557790995 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.558686018 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.980669975 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.980690002 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.980701923 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.980716944 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.980853081 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.980943918 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.980958939 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.980969906 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.980984926 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981015921 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.981029034 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.981107950 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981122971 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981139898 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981156111 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981164932 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.981178045 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.981199026 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.981311083 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981328964 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981342077 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981355906 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981372118 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.981395960 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.981477022 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981491089 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.981524944 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.983479977 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.983727932 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.983741045 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.983752966 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.983797073 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.983812094 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.984205008 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.984796047 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.984812021 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.984826088 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.984839916 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.984839916 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.984858990 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.984859943 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.984877110 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.984882116 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.984898090 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.984941006 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.984991074 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985004902 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985033989 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985049963 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985058069 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985073090 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985100985 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985115051 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985331059 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985343933 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985357046 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985369921 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985373974 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985384941 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985390902 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985409021 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985411882 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985424995 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985428095 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985439062 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985456944 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985464096 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985476017 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985512018 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985527039 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985538960 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985552073 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985555887 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985570908 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985585928 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985652924 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985668898 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985682011 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985694885 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985697031 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985707998 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985727072 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985735893 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.985779047 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985793114 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985800982 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:25.985857964 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.986527920 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:25.986994982 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.407355070 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407378912 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407396078 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407412052 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407442093 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.407478094 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.407478094 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.407550097 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407565117 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407599926 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.407603025 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407618999 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.407635927 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.407635927 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.407660007 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.409882069 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.409899950 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.409940958 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.410008907 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410064936 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410079002 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410080910 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.410104036 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.410104990 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410121918 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.410145044 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.410342932 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410358906 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410366058 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410375118 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.410428047 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.410729885 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.412668943 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.412683964 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.412698984 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.412719965 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.412740946 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.412817001 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.412965059 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.412981033 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413008928 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413019896 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413258076 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413300991 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413326979 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413343906 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413357973 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413372040 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413392067 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413403034 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413642883 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413692951 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413803101 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413819075 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413832903 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413845062 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413851976 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413858891 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413870096 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.413886070 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413897991 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413897991 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.413924932 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414151907 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414215088 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414215088 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414247036 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414262056 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414273977 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414287090 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414299965 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414309978 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414310932 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414320946 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414326906 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414340019 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414344072 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414354086 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414372921 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414397955 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414412022 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414412975 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414427996 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414441109 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414446115 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414453983 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414454937 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414475918 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414482117 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.414484024 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414505005 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414520025 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.414635897 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.834266901 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834323883 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834336042 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834343910 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834537983 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.834861040 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834923029 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834935904 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834942102 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.834952116 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.834966898 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.834986925 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835005045 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835005999 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835058928 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835072994 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835086107 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835100889 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835114956 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835134029 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835144043 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835210085 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835222960 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835242033 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835257053 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835262060 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835270882 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835282087 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835309029 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835412979 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835427046 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835443020 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835454941 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835462093 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835488081 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835488081 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835748911 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835800886 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835820913 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835834980 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835846901 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835859060 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835860968 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835877895 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835891008 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835906029 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.835984945 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.835999012 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836011887 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836024046 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836028099 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836040020 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836051941 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836070061 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836211920 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836253881 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836258888 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836297035 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836297989 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836313009 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836338043 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836354017 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836524963 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836568117 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836580038 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836618900 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836620092 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836633921 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836658955 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836673021 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836849928 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836872101 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836890936 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836941957 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836955070 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836968899 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.836982012 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.836996078 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837008953 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837174892 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837188005 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837202072 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837214947 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837215900 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837233067 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837255955 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837312937 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837327957 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837353945 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837369919 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837388992 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837403059 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837414980 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837435007 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837435007 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837456942 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837706089 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837740898 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837750912 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837754011 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837769032 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837779045 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837804079 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.837956905 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837970018 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837981939 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837994099 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.837999105 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838016033 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838033915 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838293076 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838325024 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838339090 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838340044 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838352919 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838363886 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838378906 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838393927 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838435888 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838450909 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838463068 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838475943 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838476896 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838491917 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838506937 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838519096 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838540077 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838582993 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838603020 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838617086 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838644028 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838651896 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838661909 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838685989 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.838937044 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.838982105 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.839014053 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839026928 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839039087 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839051962 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839061975 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.839083910 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.839287043 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839329958 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.839351892 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839365005 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839379072 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839399099 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.839420080 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.839935064 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839966059 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839983940 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.839999914 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840008974 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840024948 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840043068 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840290070 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840303898 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840315104 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840327978 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840338945 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840342999 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840353966 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840358973 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840372086 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840378046 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840387106 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840406895 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840410948 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840423107 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840425968 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840451956 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840465069 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.840470076 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840490103 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840919018 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.840919018 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841216087 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841231108 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841250896 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841265917 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841276884 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841288090 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841290951 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841305971 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841312885 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841319084 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841330051 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841334105 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841348886 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841350079 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841361046 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841377974 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841391087 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841918945 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841933012 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841945887 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841958046 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841959953 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.841979027 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.841990948 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842004061 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842029095 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842066050 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842094898 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842108011 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842119932 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842134953 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842159033 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842437983 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842459917 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842473984 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842485905 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842492104 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842514992 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842521906 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842556953 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842685938 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842720032 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842750072 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842762947 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842776060 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842787027 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842806101 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842818022 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842936039 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842950106 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842962980 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842972994 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842978001 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.842987061 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.842993975 CET | 80 | 49162 | 41.185.64.155 | 192.168.2.22 |
Nov 14, 2023 13:26:26.843005896 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.843020916 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.843035936 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.843868017 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:26.851995945 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:26:28.725647926 CET | 49162 | 80 | 192.168.2.22 | 41.185.64.155 |
Nov 14, 2023 13:27:01.368810892 CET | 49164 | 80 | 192.168.2.22 | 103.224.212.212 |
Nov 14, 2023 13:27:01.556674004 CET | 80 | 49164 | 103.224.212.212 | 192.168.2.22 |
Nov 14, 2023 13:27:01.556788921 CET | 49164 | 80 | 192.168.2.22 | 103.224.212.212 |
Nov 14, 2023 13:27:01.556895971 CET | 49164 | 80 | 192.168.2.22 | 103.224.212.212 |
Nov 14, 2023 13:27:01.751121998 CET | 80 | 49164 | 103.224.212.212 | 192.168.2.22 |
Nov 14, 2023 13:27:01.751142979 CET | 80 | 49164 | 103.224.212.212 | 192.168.2.22 |
Nov 14, 2023 13:27:01.751332045 CET | 49164 | 80 | 192.168.2.22 | 103.224.212.212 |
Nov 14, 2023 13:27:01.751410961 CET | 49164 | 80 | 192.168.2.22 | 103.224.212.212 |
Nov 14, 2023 13:27:01.937576056 CET | 80 | 49164 | 103.224.212.212 | 192.168.2.22 |
Nov 14, 2023 13:28:02.013607979 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.320044994 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.320250988 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.320327997 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.667289019 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687213898 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687242031 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687256098 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687268972 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687280893 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687293053 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687308073 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687319994 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687330961 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.687541008 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.687644005 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.891297102 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.993742943 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993801117 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993813038 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993829966 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993837118 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993851900 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993865013 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993876934 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993880033 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.993880033 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.993889093 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:02.993923903 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.993978024 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:02.994016886 CET | 49166 | 80 | 192.168.2.22 | 91.195.240.19 |
Nov 14, 2023 13:28:03.300403118 CET | 80 | 49166 | 91.195.240.19 | 192.168.2.22 |
Nov 14, 2023 13:28:23.604310036 CET | 49167 | 80 | 192.168.2.22 | 38.11.36.68 |
Nov 14, 2023 13:28:23.777333021 CET | 80 | 49167 | 38.11.36.68 | 192.168.2.22 |
Nov 14, 2023 13:28:23.777555943 CET | 49167 | 80 | 192.168.2.22 | 38.11.36.68 |
Nov 14, 2023 13:28:23.777817965 CET | 49167 | 80 | 192.168.2.22 | 38.11.36.68 |
Nov 14, 2023 13:28:23.949883938 CET | 80 | 49167 | 38.11.36.68 | 192.168.2.22 |
Nov 14, 2023 13:28:23.950438976 CET | 80 | 49167 | 38.11.36.68 | 192.168.2.22 |
Nov 14, 2023 13:28:23.950762033 CET | 49167 | 80 | 192.168.2.22 | 38.11.36.68 |
Nov 14, 2023 13:28:23.950858116 CET | 49167 | 80 | 192.168.2.22 | 38.11.36.68 |
Nov 14, 2023 13:28:24.122905016 CET | 80 | 49167 | 38.11.36.68 | 192.168.2.22 |
Nov 14, 2023 13:28:45.013690948 CET | 49168 | 80 | 192.168.2.22 | 3.33.130.190 |
Nov 14, 2023 13:28:45.165218115 CET | 80 | 49168 | 3.33.130.190 | 192.168.2.22 |
Nov 14, 2023 13:28:45.165352106 CET | 49168 | 80 | 192.168.2.22 | 3.33.130.190 |
Nov 14, 2023 13:28:45.165462017 CET | 49168 | 80 | 192.168.2.22 | 3.33.130.190 |
Nov 14, 2023 13:28:45.316684008 CET | 80 | 49168 | 3.33.130.190 | 192.168.2.22 |
Nov 14, 2023 13:28:45.382431030 CET | 80 | 49168 | 3.33.130.190 | 192.168.2.22 |
Nov 14, 2023 13:28:45.382482052 CET | 80 | 49168 | 3.33.130.190 | 192.168.2.22 |
Nov 14, 2023 13:28:45.382580996 CET | 49168 | 80 | 192.168.2.22 | 3.33.130.190 |
Nov 14, 2023 13:28:45.382627964 CET | 49168 | 80 | 192.168.2.22 | 3.33.130.190 |
Nov 14, 2023 13:28:45.396579981 CET | 80 | 49168 | 3.33.130.190 | 192.168.2.22 |
Nov 14, 2023 13:28:45.396661997 CET | 49168 | 80 | 192.168.2.22 | 3.33.130.190 |
Nov 14, 2023 13:28:45.534183025 CET | 80 | 49168 | 3.33.130.190 | 192.168.2.22 |
Nov 14, 2023 13:29:05.731285095 CET | 49169 | 80 | 192.168.2.22 | 34.149.87.45 |
Nov 14, 2023 13:29:05.883409023 CET | 80 | 49169 | 34.149.87.45 | 192.168.2.22 |
Nov 14, 2023 13:29:05.883658886 CET | 49169 | 80 | 192.168.2.22 | 34.149.87.45 |
Nov 14, 2023 13:29:05.883658886 CET | 49169 | 80 | 192.168.2.22 | 34.149.87.45 |
Nov 14, 2023 13:29:06.035727978 CET | 80 | 49169 | 34.149.87.45 | 192.168.2.22 |
Nov 14, 2023 13:29:06.066524982 CET | 80 | 49169 | 34.149.87.45 | 192.168.2.22 |
Nov 14, 2023 13:29:06.066560030 CET | 80 | 49169 | 34.149.87.45 | 192.168.2.22 |
Nov 14, 2023 13:29:06.066716909 CET | 49169 | 80 | 192.168.2.22 | 34.149.87.45 |
Nov 14, 2023 13:29:06.066764116 CET | 49169 | 80 | 192.168.2.22 | 34.149.87.45 |
Nov 14, 2023 13:29:06.218295097 CET | 80 | 49169 | 34.149.87.45 | 192.168.2.22 |
Nov 14, 2023 13:29:44.455823898 CET | 49170 | 80 | 192.168.2.22 | 206.188.193.211 |
Nov 14, 2023 13:29:47.458198071 CET | 49170 | 80 | 192.168.2.22 | 206.188.193.211 |
Nov 14, 2023 13:29:47.675571918 CET | 80 | 49170 | 206.188.193.211 | 192.168.2.22 |
Nov 14, 2023 13:29:47.675832987 CET | 49170 | 80 | 192.168.2.22 | 206.188.193.211 |
Nov 14, 2023 13:29:47.675930977 CET | 49170 | 80 | 192.168.2.22 | 206.188.193.211 |
Nov 14, 2023 13:29:50.687489986 CET | 49170 | 80 | 192.168.2.22 | 206.188.193.211 |
Nov 14, 2023 13:29:53.008421898 CET | 49170 | 80 | 192.168.2.22 | 206.188.193.211 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 14, 2023 13:26:23.654068947 CET | 57893 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:26:23.819900990 CET | 53 | 57893 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:27:01.154933929 CET | 54821 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:27:01.361637115 CET | 53 | 54821 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:27:21.881318092 CET | 54719 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:27:22.065354109 CET | 53 | 54719 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:28:01.827485085 CET | 49881 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:28:02.012876034 CET | 53 | 49881 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:28:23.203567028 CET | 54998 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:28:23.603432894 CET | 53 | 54998 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:28:44.835366964 CET | 52781 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:28:45.006840944 CET | 53 | 52781 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:29:05.508264065 CET | 63926 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:29:05.729218960 CET | 53 | 63926 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:29:23.881514072 CET | 65510 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:29:24.058892965 CET | 53 | 65510 | 8.8.8.8 | 192.168.2.22 |
Nov 14, 2023 13:29:44.198112011 CET | 62672 | 53 | 192.168.2.22 | 8.8.8.8 |
Nov 14, 2023 13:29:44.450772047 CET | 53 | 62672 | 8.8.8.8 | 192.168.2.22 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 14, 2023 13:26:23.654068947 CET | 192.168.2.22 | 8.8.8.8 | 0xf2c1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:27:01.154933929 CET | 192.168.2.22 | 8.8.8.8 | 0x622a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:27:21.881318092 CET | 192.168.2.22 | 8.8.8.8 | 0xa59f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:28:01.827485085 CET | 192.168.2.22 | 8.8.8.8 | 0xebec | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:28:23.203567028 CET | 192.168.2.22 | 8.8.8.8 | 0x15a2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:28:44.835366964 CET | 192.168.2.22 | 8.8.8.8 | 0xc2c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:29:05.508264065 CET | 192.168.2.22 | 8.8.8.8 | 0xb8e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:29:23.881514072 CET | 192.168.2.22 | 8.8.8.8 | 0xe8fb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:29:44.198112011 CET | 192.168.2.22 | 8.8.8.8 | 0xbbcb | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 14, 2023 13:26:00.929542065 CET | 8.8.8.8 | 192.168.2.22 | 0x9680 | No error (0) | 69.164.40.8 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:26:23.819900990 CET | 8.8.8.8 | 192.168.2.22 | 0xf2c1 | No error (0) | 41.185.64.155 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:27:01.361637115 CET | 8.8.8.8 | 192.168.2.22 | 0x622a | No error (0) | 103.224.212.212 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:27:22.065354109 CET | 8.8.8.8 | 192.168.2.22 | 0xa59f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:28:02.012876034 CET | 8.8.8.8 | 192.168.2.22 | 0xebec | No error (0) | parkingpage.namecheap.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 14, 2023 13:28:02.012876034 CET | 8.8.8.8 | 192.168.2.22 | 0xebec | No error (0) | 91.195.240.19 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:28:23.603432894 CET | 8.8.8.8 | 192.168.2.22 | 0x15a2 | No error (0) | 38.11.36.68 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:28:45.006840944 CET | 8.8.8.8 | 192.168.2.22 | 0xc2c0 | No error (0) | centralngs.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 14, 2023 13:28:45.006840944 CET | 8.8.8.8 | 192.168.2.22 | 0xc2c0 | No error (0) | 3.33.130.190 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:28:45.006840944 CET | 8.8.8.8 | 192.168.2.22 | 0xc2c0 | No error (0) | 15.197.148.33 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:29:05.729218960 CET | 8.8.8.8 | 192.168.2.22 | 0xb8e | No error (0) | cdn1.wixdns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 14, 2023 13:29:05.729218960 CET | 8.8.8.8 | 192.168.2.22 | 0xb8e | No error (0) | td-ccm-neg-87-45.wixdns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 14, 2023 13:29:05.729218960 CET | 8.8.8.8 | 192.168.2.22 | 0xb8e | No error (0) | 34.149.87.45 | A (IP address) | IN (0x0001) | false | ||
Nov 14, 2023 13:29:24.058892965 CET | 8.8.8.8 | 192.168.2.22 | 0xe8fb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 14, 2023 13:29:44.450772047 CET | 8.8.8.8 | 192.168.2.22 | 0xbbcb | No error (0) | 206.188.193.211 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.22 | 49162 | 41.185.64.155 | 80 | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 14, 2023 13:26:24.263209105 CET | 2 | OUT | |
Nov 14, 2023 13:26:24.701302052 CET | 3 | IN |