Windows
Analysis Report
R3ov8eFFFP.exe
Overview
General Information
Sample name: | R3ov8eFFFP.exerenamed because original name is a hash value |
Original sample name: | 0A7D2BBBE2960FF24B9273036FC472DA.exe |
Analysis ID: | 1383432 |
MD5: | 0a7d2bbbe2960ff24b9273036fc472da |
SHA1: | 3b0fbb910651427a6a103327a0630e96acb8649c |
SHA256: | d812b05b85a25ab0ec4258f8a4e9adda4a84d2df5b07fed42b84de539dfcabc8 |
Tags: | exenjratRAT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- R3ov8eFFFP.exe (PID: 6664 cmdline:
C:\Users\u ser\Deskto p\R3ov8eFF FP.exe MD5: 0A7D2BBBE2960FF24B9273036FC472DA) - ESET Service.exe (PID: 3452 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" MD5: 0A7D2BBBE2960FF24B9273036FC472DA) - netsh.exe (PID: 772 cmdline:
netsh fire wall add a llowedprog ram "C:\Us ers\user\A ppData\Roa ming\ESET Service.ex e" "ESET S ervice.exe " ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF) - conhost.exe (PID: 5300 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - taskkill.exe (PID: 5284 cmdline:
taskkill / F /IM task mgr.exe MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD) - conhost.exe (PID: 6404 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- ESET Service.exe (PID: 1772 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" . . MD5: 0A7D2BBBE2960FF24B9273036FC472DA)
- ESET Service.exe (PID: 5252 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" . . MD5: 0A7D2BBBE2960FF24B9273036FC472DA)
- ESET Service.exe (PID: 4544 cmdline:
"C:\Users\ user\AppDa ta\Roaming \ESET Serv ice.exe" . . MD5: 0A7D2BBBE2960FF24B9273036FC472DA)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
NjRAT | RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored. |
{"Host": "2.tcp.eu.ngrok.io", "Port": "18227", "Version": "im523", "Campaign ID": "HacKed", "Install Name": "ESET Service.exe", "Install Dir": "AppData"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
| |
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Click to see the 7 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_Njrat | Yara detected Njrat | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
System Summary |
---|
Source: | Author: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Timestamp: | 192.168.2.43.127.138.5749743182272825564 01/30/24-17:09:29.306132 |
SID: | 2825564 |
Source Port: | 49743 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749743182272825563 01/30/24-17:09:19.453005 |
SID: | 2825563 |
Source Port: | 49743 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749740182272814860 01/30/24-17:08:55.123453 |
SID: | 2814860 |
Source Port: | 49740 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749742182272033132 01/30/24-17:09:13.438158 |
SID: | 2033132 |
Source Port: | 49742 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749741182272033132 01/30/24-17:08:57.484517 |
SID: | 2033132 |
Source Port: | 49741 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749743182272033132 01/30/24-17:09:19.251884 |
SID: | 2033132 |
Source Port: | 49743 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749729182272033132 01/30/24-17:07:18.434785 |
SID: | 2033132 |
Source Port: | 49729 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749741182272814860 01/30/24-17:09:03.945846 |
SID: | 2814860 |
Source Port: | 49741 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649749182272814856 01/30/24-17:10:28.018781 |
SID: | 2814856 |
Source Port: | 49749 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649748182272814856 01/30/24-17:10:15.110171 |
SID: | 2814856 |
Source Port: | 49748 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649747182272814856 01/30/24-17:10:06.444735 |
SID: | 2814856 |
Source Port: | 49747 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749738182272814856 01/30/24-17:08:14.961731 |
SID: | 2814856 |
Source Port: | 49738 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749739182272814856 01/30/24-17:08:27.854209 |
SID: | 2814856 |
Source Port: | 49739 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749743182272814860 01/30/24-17:09:29.306132 |
SID: | 2814860 |
Source Port: | 49743 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749729182272825564 01/30/24-17:07:23.073796 |
SID: | 2825564 |
Source Port: | 49729 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749729182272825563 01/30/24-17:07:18.635283 |
SID: | 2825563 |
Source Port: | 49729 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549752182272033132 01/30/24-17:11:04.732771 |
SID: | 2033132 |
Source Port: | 49752 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749740182272814856 01/30/24-17:08:45.087741 |
SID: | 2814856 |
Source Port: | 49740 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549751182272033132 01/30/24-17:10:49.338671 |
SID: | 2033132 |
Source Port: | 49751 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549750182272033132 01/30/24-17:10:40.149950 |
SID: | 2033132 |
Source Port: | 49750 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749741182272814856 01/30/24-17:08:57.690610 |
SID: | 2814856 |
Source Port: | 49741 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749742182272814856 01/30/24-17:09:13.644212 |
SID: | 2814856 |
Source Port: | 49742 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649745182272814856 01/30/24-17:09:36.950026 |
SID: | 2814856 |
Source Port: | 49745 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649744182272814856 01/30/24-17:09:32.006134 |
SID: | 2814856 |
Source Port: | 49744 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649746182272814856 01/30/24-17:09:54.099801 |
SID: | 2814856 |
Source Port: | 49746 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749736182272814856 01/30/24-17:07:52.958354 |
SID: | 2814856 |
Source Port: | 49736 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749740182272033132 01/30/24-17:08:44.884475 |
SID: | 2033132 |
Source Port: | 49740 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549752182272814856 01/30/24-17:11:04.938711 |
SID: | 2814856 |
Source Port: | 49752 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749743182272814856 01/30/24-17:09:19.453005 |
SID: | 2814856 |
Source Port: | 49743 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549751182272814856 01/30/24-17:10:49.541184 |
SID: | 2814856 |
Source Port: | 49751 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549750182272814856 01/30/24-17:10:40.356210 |
SID: | 2814856 |
Source Port: | 49750 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649746182272825563 01/30/24-17:09:54.099801 |
SID: | 2825563 |
Source Port: | 49746 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649747182272033132 01/30/24-17:10:06.243628 |
SID: | 2033132 |
Source Port: | 49747 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649748182272033132 01/30/24-17:10:14.903223 |
SID: | 2033132 |
Source Port: | 49748 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749736182272033132 01/30/24-17:07:52.757868 |
SID: | 2033132 |
Source Port: | 49736 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649746182272825564 01/30/24-17:10:02.570250 |
SID: | 2825564 |
Source Port: | 49746 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649748182272825564 01/30/24-17:10:16.789499 |
SID: | 2825564 |
Source Port: | 49748 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749736182272825563 01/30/24-17:07:52.958354 |
SID: | 2825563 |
Source Port: | 49736 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749736182272825564 01/30/24-17:07:55.336198 |
SID: | 2825564 |
Source Port: | 49736 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649745182272033132 01/30/24-17:09:36.751580 |
SID: | 2033132 |
Source Port: | 49745 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649746182272033132 01/30/24-17:09:53.899404 |
SID: | 2033132 |
Source Port: | 49746 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649749182272033132 01/30/24-17:10:27.818089 |
SID: | 2033132 |
Source Port: | 49749 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649745182272825563 01/30/24-17:09:36.950026 |
SID: | 2825563 |
Source Port: | 49745 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649749182272825563 01/30/24-17:10:28.018781 |
SID: | 2825563 |
Source Port: | 49749 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649745182272825564 01/30/24-17:09:37.351336 |
SID: | 2825564 |
Source Port: | 49745 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649749182272825564 01/30/24-17:10:33.714882 |
SID: | 2825564 |
Source Port: | 49749 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749738182272033132 01/30/24-17:08:14.761110 |
SID: | 2033132 |
Source Port: | 49738 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649744182272825563 01/30/24-17:09:32.006134 |
SID: | 2825563 |
Source Port: | 49744 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749739182272033132 01/30/24-17:08:27.653310 |
SID: | 2033132 |
Source Port: | 49739 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549750182272814860 01/30/24-17:10:41.866704 |
SID: | 2814860 |
Source Port: | 49750 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549751182272814860 01/30/24-17:10:58.138650 |
SID: | 2814860 |
Source Port: | 49751 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649746182272814860 01/30/24-17:10:03.972545 |
SID: | 2814860 |
Source Port: | 49746 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749736182272814860 01/30/24-17:07:55.336198 |
SID: | 2814860 |
Source Port: | 49736 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649745182272814860 01/30/24-17:09:37.351336 |
SID: | 2814860 |
Source Port: | 49745 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749738182272825564 01/30/24-17:08:24.775359 |
SID: | 2825564 |
Source Port: | 49738 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749739182272825564 01/30/24-17:08:42.669529 |
SID: | 2825564 |
Source Port: | 49739 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649744182272033132 01/30/24-17:09:31.797713 |
SID: | 2033132 |
Source Port: | 49744 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749729182272814856 01/30/24-17:07:18.635283 |
SID: | 2814856 |
Source Port: | 49729 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649748182272825563 01/30/24-17:10:15.110171 |
SID: | 2825563 |
Source Port: | 49748 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549751182272825564 01/30/24-17:10:58.138650 |
SID: | 2825564 |
Source Port: | 49751 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549751182272825563 01/30/24-17:10:49.541184 |
SID: | 2825563 |
Source Port: | 49751 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749729182272814860 01/30/24-17:07:23.073796 |
SID: | 2814860 |
Source Port: | 49729 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549750182272825564 01/30/24-17:10:41.866704 |
SID: | 2825564 |
Source Port: | 49750 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549750182272825563 01/30/24-17:10:40.356210 |
SID: | 2825563 |
Source Port: | 49750 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649748182272814860 01/30/24-17:10:16.789499 |
SID: | 2814860 |
Source Port: | 49748 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749739182272814860 01/30/24-17:08:42.669529 |
SID: | 2814860 |
Source Port: | 49739 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749738182272814860 01/30/24-17:08:25.085626 |
SID: | 2814860 |
Source Port: | 49738 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649747182272814860 01/30/24-17:10:07.250125 |
SID: | 2814860 |
Source Port: | 49747 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.197.239.549752182272825563 01/30/24-17:11:04.938711 |
SID: | 2825563 |
Source Port: | 49752 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649749182272814860 01/30/24-17:10:33.714882 |
SID: | 2814860 |
Source Port: | 49749 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749741182272825564 01/30/24-17:09:03.945846 |
SID: | 2825564 |
Source Port: | 49741 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749741182272825563 01/30/24-17:08:57.690610 |
SID: | 2825563 |
Source Port: | 49741 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.127.138.5749742182272825563 01/30/24-17:09:13.644212 |
SID: | 2825563 |
Source Port: | 49742 |
Destination Port: | 18227 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Spreading |
---|
Source: | File created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | URLs: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Operating System Destruction |
---|
Source: | Process information set: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 1_2_058E010E | |
Source: | Code function: | 1_2_058E0346 | |
Source: | Code function: | 1_2_058E00EC | |
Source: | Code function: | 1_2_058E030B |
Source: | Binary or memory string: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 1_2_015EBDA2 | |
Source: | Code function: | 1_2_015EBD6B |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Persistence and Installation Behavior |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Registry value created or modified: | Jump to behavior |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: |
Source: | Process created: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | Process created: |
Source: | Process created: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 11 Replication Through Removable Media | 21 Windows Management Instrumentation | 221 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 11 Masquerading | 1 Input Capture | 111 Security Software Discovery | Remote Services | 1 Input Capture | 1 Non-Standard Port | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 12 Process Injection | 311 Disable or Modify Tools | LSASS Memory | 2 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 221 Registry Run Keys / Startup Folder | 41 Virtualization/Sandbox Evasion | Security Account Manager | 41 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 11 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 1 Access Token Manipulation | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 12 Process Injection | LSA Secrets | 1 Peripheral Device Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 33 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/ATRAPS.Gen | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay | ||
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay | ||
97% | ReversingLabs | ByteCode-MSIL.Backdoor.Ratenjay |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
2.tcp.eu.ngrok.io | 3.127.138.57 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
3.127.138.57 | 2.tcp.eu.ngrok.io | United States | 16509 | AMAZON-02US | true | |
18.192.93.86 | unknown | United States | 16509 | AMAZON-02US | true | |
18.197.239.5 | unknown | United States | 16509 | AMAZON-02US | true |
Joe Sandbox version: | 39.0.0 Ruby |
Analysis ID: | 1383432 |
Start date and time: | 2024-01-30 17:06:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 46s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | R3ov8eFFFP.exerenamed because original name is a hash value |
Original Sample Name: | 0A7D2BBBE2960FF24B9273036FC472DA.exe |
Detection: | MAL |
Classification: | mal100.spre.troj.adwa.spyw.evad.winEXE@12/10@4/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 52.165.165.26, 23.40.205.58, 23.40.205.34, 23.40.205.75, 23.40.205.57, 23.40.205.59, 23.40.205.83, 23.40.205.9, 23.40.205.81, 20.3.187.198, 13.95.31.18, 20.166.126.56
- Excluded domains from analysis (whitelisted): fe3.delivery.mp.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, ctldl.windowsupdate.com, a767.dspw65.akamai.net, wu-bg-shim.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, download.windowsupdate.com.edgesuite.net, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: R3ov8eFFFP.exe
Time | Type | Description |
---|---|---|
16:07:16 | Autostart | |
16:07:25 | Autostart | |
16:07:33 | Autostart | |
16:07:42 | Autostart | |
17:07:47 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3.127.138.57 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
18.192.93.86 | Get hash | malicious | RedLine | Browse |
| |
Get hash | malicious | RedLine | Browse |
| ||
18.197.239.5 | Get hash | malicious | RedLine | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
2.tcp.eu.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 525 |
Entropy (8bit): | 5.259753436570609 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve |
MD5: | 260E01CC001F9C4643CA7A62F395D747 |
SHA1: | 492AD0ACE3A9C8736909866EEA168962D418BE5A |
SHA-256: | 4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030 |
SHA-512: | 01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\R3ov8eFFFP.exe |
File Type: | |
Category: | modified |
Size (bytes): | 525 |
Entropy (8bit): | 5.259753436570609 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve |
MD5: | 260E01CC001F9C4643CA7A62F395D747 |
SHA1: | 492AD0ACE3A9C8736909866EEA168962D418BE5A |
SHA-256: | 4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030 |
SHA-512: | 01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\R3ov8eFFFP.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 37888 |
Entropy (8bit): | 5.5730226036804105 |
Encrypted: | false |
SSDEEP: | 384:jstKUiDtblmJEpRGyEf7JfJuQCY6iXQrAF+rMRTyN/0L+EcoinblneHQM3epzX48:YtiHpR9Ef7JsQCFiArM+rMRa8NuqUt |
MD5: | 0A7D2BBBE2960FF24B9273036FC472DA |
SHA1: | 3B0FBB910651427A6A103327A0630E96ACB8649C |
SHA-256: | D812B05B85A25AB0EC4258F8A4E9ADDA4A84D2DF5B07FED42B84DE539DFCABC8 |
SHA-512: | 8266B81B3D24B0650465D35A5CF83EA4339F7CF417A78E4A5BD8EB5D111BD90EEB1C672DBE7A2C6F772849AECF13C6FE62488958CD27986727CD723D154DD62F |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\R3ov8eFFFP.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fa8cebf4f3fd11252bf351a94ee5fa4a.exe
Download File
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 37888 |
Entropy (8bit): | 5.5730226036804105 |
Encrypted: | false |
SSDEEP: | 384:jstKUiDtblmJEpRGyEf7JfJuQCY6iXQrAF+rMRTyN/0L+EcoinblneHQM3epzX48:YtiHpR9Ef7JsQCFiArM+rMRa8NuqUt |
MD5: | 0A7D2BBBE2960FF24B9273036FC472DA |
SHA1: | 3B0FBB910651427A6A103327A0630E96ACB8649C |
SHA-256: | D812B05B85A25AB0EC4258F8A4E9ADDA4A84D2DF5B07FED42B84DE539DFCABC8 |
SHA-512: | 8266B81B3D24B0650465D35A5CF83EA4339F7CF417A78E4A5BD8EB5D111BD90EEB1C672DBE7A2C6F772849AECF13C6FE62488958CD27986727CD723D154DD62F |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fa8cebf4f3fd11252bf351a94ee5fa4a.exe:Zone.Identifier
Download File
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 50 |
Entropy (8bit): | 4.320240000427043 |
Encrypted: | false |
SSDEEP: | 3:It1KV2LKMACovK0x:e1KzxvD |
MD5: | 5B0B50BADE67C5EC92D42E971287A5D9 |
SHA1: | 90D5C99143E7A56AD6E5EE401015F8ECC093D95A |
SHA-256: | 04DDE2489D2D2E6846D42250D813AB90B5CA847D527F8F2C022E6C327DC6DB53 |
SHA-512: | C064DC3C4185A38D1CAEBD069ACB9FDBB85DFB650D6A241036E501A09BC89FD06E267BE9D400D20E6C14B4068473D1C6557962E8D82FDFD191DB7EABB6E66821 |
Malicious: | true |
Preview: |
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 37888 |
Entropy (8bit): | 5.5730226036804105 |
Encrypted: | false |
SSDEEP: | 384:jstKUiDtblmJEpRGyEf7JfJuQCY6iXQrAF+rMRTyN/0L+EcoinblneHQM3epzX48:YtiHpR9Ef7JsQCFiArM+rMRa8NuqUt |
MD5: | 0A7D2BBBE2960FF24B9273036FC472DA |
SHA1: | 3B0FBB910651427A6A103327A0630E96ACB8649C |
SHA-256: | D812B05B85A25AB0EC4258F8A4E9ADDA4A84D2DF5B07FED42B84DE539DFCABC8 |
SHA-512: | 8266B81B3D24B0650465D35A5CF83EA4339F7CF417A78E4A5BD8EB5D111BD90EEB1C672DBE7A2C6F772849AECF13C6FE62488958CD27986727CD723D154DD62F |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Roaming\ESET Service.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\netsh.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 313 |
Entropy (8bit): | 4.971939296804078 |
Encrypted: | false |
SSDEEP: | 6:/ojfKsUTGN8Ypox42k9L+DbGMKeQE+vigqAZs2E+AYeDPO+Yswyha:wjPIGNrkHk9iaeIM6ADDPOHyha |
MD5: | 689E2126A85BF55121488295EE068FA1 |
SHA1: | 09BAAA253A49D80C18326DFBCA106551EBF22DD6 |
SHA-256: | D968A966EF474068E41256321F77807A042F1965744633D37A203A705662EC25 |
SHA-512: | C3736A8FC7E6573FA1B26FE6A901C05EE85C55A4A276F8F569D9EADC9A58BEC507D1BB90DBF9EA62AE79A6783178C69304187D6B90441D82E46F5F56172B5C5C |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 5.5730226036804105 |
TrID: |
|
File name: | R3ov8eFFFP.exe |
File size: | 37'888 bytes |
MD5: | 0a7d2bbbe2960ff24b9273036fc472da |
SHA1: | 3b0fbb910651427a6a103327a0630e96acb8649c |
SHA256: | d812b05b85a25ab0ec4258f8a4e9adda4a84d2df5b07fed42b84de539dfcabc8 |
SHA512: | 8266b81b3d24b0650465d35a5cf83ea4339f7cf417a78e4a5bd8eb5d111bd90eeb1c672dbe7a2c6f772849aecf13c6fe62488958cd27986727cd723d154dd62f |
SSDEEP: | 384:jstKUiDtblmJEpRGyEf7JfJuQCY6iXQrAF+rMRTyN/0L+EcoinblneHQM3epzX48:YtiHpR9Ef7JsQCFiArM+rMRa8NuqUt |
TLSH: | 6D032A4D7FE18168C5FD467B05B2D41207BBE04B6E23D90E8EF564AA37636C18B50AF2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......e................................. ........@.. ....................................@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x40abbe |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x65B3A597 [Fri Jan 26 12:29:11 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xab70 | 0x4b | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc000 | 0x240 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x8bc4 | 0x8c00 | 52435bf8111a2b756b0ca350659b2ea6 | False | 0.46353236607142856 | data | 5.604430733714899 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc000 | 0x240 | 0x400 | f7ce2f7b506ce16c06c85a549ef2cd98 | False | 0.3134765625 | data | 4.968771659524424 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xe000 | 0xc | 0x200 | 163d66697186c0743c0da6f82247a39a | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0xc058 | 0x1e7 | XML 1.0 document, ASCII text, with CRLF line terminators | 0.5338809034907598 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.43.127.138.5749743182272825564 01/30/24-17:09:29.306132 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749743182272825563 01/30/24-17:09:19.453005 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749740182272814860 01/30/24-17:08:55.123453 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749742182272033132 01/30/24-17:09:13.438158 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749741182272033132 01/30/24-17:08:57.484517 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749743182272033132 01/30/24-17:09:19.251884 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749729182272033132 01/30/24-17:07:18.434785 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749741182272814860 01/30/24-17:09:03.945846 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649749182272814856 01/30/24-17:10:28.018781 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649748182272814856 01/30/24-17:10:15.110171 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649747182272814856 01/30/24-17:10:06.444735 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749738182272814856 01/30/24-17:08:14.961731 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749739182272814856 01/30/24-17:08:27.854209 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749743182272814860 01/30/24-17:09:29.306132 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749729182272825564 01/30/24-17:07:23.073796 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749729182272825563 01/30/24-17:07:18.635283 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.197.239.549752182272033132 01/30/24-17:11:04.732771 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49752 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.43.127.138.5749740182272814856 01/30/24-17:08:45.087741 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.197.239.549751182272033132 01/30/24-17:10:49.338671 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.197.239.549750182272033132 01/30/24-17:10:40.149950 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.43.127.138.5749741182272814856 01/30/24-17:08:57.690610 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749742182272814856 01/30/24-17:09:13.644212 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649745182272814856 01/30/24-17:09:36.950026 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649744182272814856 01/30/24-17:09:32.006134 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649746182272814856 01/30/24-17:09:54.099801 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749736182272814856 01/30/24-17:07:52.958354 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749740182272033132 01/30/24-17:08:44.884475 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.197.239.549752182272814856 01/30/24-17:11:04.938711 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49752 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.43.127.138.5749743182272814856 01/30/24-17:09:19.453005 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.197.239.549751182272814856 01/30/24-17:10:49.541184 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.197.239.549750182272814856 01/30/24-17:10:40.356210 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.192.93.8649746182272825563 01/30/24-17:09:54.099801 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649747182272033132 01/30/24-17:10:06.243628 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649748182272033132 01/30/24-17:10:14.903223 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749736182272033132 01/30/24-17:07:52.757868 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649746182272825564 01/30/24-17:10:02.570250 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649748182272825564 01/30/24-17:10:16.789499 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749736182272825563 01/30/24-17:07:52.958354 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749736182272825564 01/30/24-17:07:55.336198 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649745182272033132 01/30/24-17:09:36.751580 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649746182272033132 01/30/24-17:09:53.899404 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649749182272033132 01/30/24-17:10:27.818089 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649745182272825563 01/30/24-17:09:36.950026 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649749182272825563 01/30/24-17:10:28.018781 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649745182272825564 01/30/24-17:09:37.351336 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649749182272825564 01/30/24-17:10:33.714882 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749738182272033132 01/30/24-17:08:14.761110 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649744182272825563 01/30/24-17:09:32.006134 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749739182272033132 01/30/24-17:08:27.653310 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.197.239.549750182272814860 01/30/24-17:10:41.866704 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.197.239.549751182272814860 01/30/24-17:10:58.138650 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.192.93.8649746182272814860 01/30/24-17:10:03.972545 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749736182272814860 01/30/24-17:07:55.336198 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649745182272814860 01/30/24-17:09:37.351336 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749738182272825564 01/30/24-17:08:24.775359 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749739182272825564 01/30/24-17:08:42.669529 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649744182272033132 01/30/24-17:09:31.797713 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749729182272814856 01/30/24-17:07:18.635283 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649748182272825563 01/30/24-17:10:15.110171 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.197.239.549751182272825564 01/30/24-17:10:58.138650 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.197.239.549751182272825563 01/30/24-17:10:49.541184 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.43.127.138.5749729182272814860 01/30/24-17:07:23.073796 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.197.239.549750182272825564 01/30/24-17:10:41.866704 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.197.239.549750182272825563 01/30/24-17:10:40.356210 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.192.93.8649748182272814860 01/30/24-17:10:16.789499 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749739182272814860 01/30/24-17:08:42.669529 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749738182272814860 01/30/24-17:08:25.085626 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.418.192.93.8649747182272814860 01/30/24-17:10:07.250125 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.197.239.549752182272825563 01/30/24-17:11:04.938711 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49752 | 18227 | 192.168.2.4 | 18.197.239.5 |
192.168.2.418.192.93.8649749182272814860 01/30/24-17:10:33.714882 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.127.138.5749741182272825564 01/30/24-17:09:03.945846 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749741182272825563 01/30/24-17:08:57.690610 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
192.168.2.43.127.138.5749742182272825563 01/30/24-17:09:13.644212 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 30, 2024 17:07:18.118943930 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:18.319217920 CET | 18227 | 49729 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:18.319299936 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:18.434784889 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:18.635211945 CET | 18227 | 49729 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:18.635282993 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:18.835705996 CET | 18227 | 49729 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:23.073796034 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:23.274883032 CET | 18227 | 49729 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:38.365947008 CET | 18227 | 49729 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:38.366117954 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:50.537448883 CET | 18227 | 49729 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:50.537543058 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:52.540827036 CET | 49729 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:52.543697119 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:52.741385937 CET | 18227 | 49729 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:52.744189024 CET | 18227 | 49736 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:52.744402885 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:52.757868052 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:52.958242893 CET | 18227 | 49736 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:52.958353996 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:53.158967018 CET | 18227 | 49736 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:07:55.336198092 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:07:55.536633968 CET | 18227 | 49736 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:10.617690086 CET | 18227 | 49736 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:10.617791891 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:12.537127018 CET | 18227 | 49736 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:12.537514925 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:14.539102077 CET | 49736 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:14.542673111 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:14.739630938 CET | 18227 | 49736 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:14.742988110 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:14.743413925 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:14.761110067 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:14.961522102 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:14.961730957 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:15.161993980 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:19.243091106 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:19.443494081 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:19.477243900 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:19.677969933 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:20.367721081 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:20.568304062 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:20.568823099 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:20.769416094 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:20.963871002 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:21.164271116 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:21.164709091 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:21.365112066 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:21.365535021 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:21.566121101 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:21.566350937 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:21.766688108 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:21.767122984 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:21.967407942 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:21.967708111 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:22.168124914 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:22.168242931 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:22.368449926 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:22.368839025 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:22.569097996 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:22.569669962 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:22.769943953 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:22.770020008 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:22.970360041 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:22.970438004 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:23.170423031 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:23.170541048 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:23.370558977 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:23.370650053 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:23.570831060 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:23.570909023 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:23.771100044 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:23.771297932 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:23.971381903 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:23.971502066 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:24.171686888 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:24.172255993 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:24.372564077 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:24.373183012 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:24.573587894 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:24.574031115 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:24.774331093 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:24.775358915 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:24.969839096 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:24.970046997 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:24.975495100 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:25.085625887 CET | 49738 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:25.170259953 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:25.286309004 CET | 18227 | 49738 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:27.444000006 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:27.644758940 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:27.645101070 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:27.653310061 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:27.853856087 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:27.854208946 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:28.055088043 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:28.055363894 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:28.256254911 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:28.256463051 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:28.457463980 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:28.457796097 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:28.658519030 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:28.658653975 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:28.859358072 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:28.859611034 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:29.060507059 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:29.060678005 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:29.262550116 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:29.262775898 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:29.463494062 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:29.463891029 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:29.665312052 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:29.665427923 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:29.866010904 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:29.866297960 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:30.067047119 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:30.067300081 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:30.268131971 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:30.268381119 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:30.469274998 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:30.469749928 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:30.670468092 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:30.670931101 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:30.872039080 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:30.872251034 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:31.073065042 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:31.073275089 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:31.274019957 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:31.274292946 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:31.475121021 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:31.475404024 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:31.676198006 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:31.676640034 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:31.877504110 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:31.877969027 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:32.079165936 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:32.079366922 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:32.279973984 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:32.280376911 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:32.481098890 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:32.481379032 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:32.682281017 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:32.682615042 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:32.883357048 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:32.883622885 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:33.084570885 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:33.084770918 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:33.285358906 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:33.285561085 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:33.486411095 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:33.486510992 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:33.687203884 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:33.687428951 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:33.887970924 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:33.888179064 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:34.088859081 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:34.089088917 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:34.289917946 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:34.290045023 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:34.490910053 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:34.491003990 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:34.692013979 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:34.692235947 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:34.893011093 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:34.893368959 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:35.094140053 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:35.094481945 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:35.296802044 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:35.296936035 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:35.497612000 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:35.497757912 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:35.698784113 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:35.699018002 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:35.899802923 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:35.900118113 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:36.100967884 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:36.101224899 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:36.301995039 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:36.302151918 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:36.503012896 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:36.503396034 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:36.704019070 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:36.704241037 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:36.904968977 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:36.905261993 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:37.105923891 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:37.106182098 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:37.308156013 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:37.308360100 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:37.508959055 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:37.509193897 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:37.709985971 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:37.710367918 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:37.911137104 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:37.911438942 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:38.112112999 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:38.112317085 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:38.313105106 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:38.313308001 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:38.514097929 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:38.514327049 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:38.714885950 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:38.715102911 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:38.915584087 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:38.915797949 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:39.117832899 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:39.118065119 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:39.319658995 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:39.319864035 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:39.520365000 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:39.520576954 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:39.721039057 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:39.721290112 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:39.921797991 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:39.922024965 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:40.122467041 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:40.122648001 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:40.322992086 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:40.323195934 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:40.524761915 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:40.525044918 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:40.725555897 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:40.725764990 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:40.926168919 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:40.926422119 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:41.126811028 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:41.127103090 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:41.327806950 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:41.328018904 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:41.528436899 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:41.528764963 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:41.729111910 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:41.729312897 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:41.929708004 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:41.929812908 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:42.130331993 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:42.130444050 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:42.330782890 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:42.330997944 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:42.531397104 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:42.531575918 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:42.669207096 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:42.669528961 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:42.734142065 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:42.872009993 CET | 18227 | 49739 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:44.679548979 CET | 49739 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:44.681642056 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:44.881992102 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:44.882122040 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:44.884474993 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:45.087626934 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:45.087740898 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:45.287996054 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:45.288111925 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:45.488462925 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:45.488564014 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:45.688940048 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:45.689011097 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:45.889549971 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:45.889744997 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:46.091192007 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:46.091260910 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:46.291507959 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:46.291585922 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:46.491950989 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:46.492031097 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:46.692506075 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:46.692730904 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:46.892987013 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:46.893059015 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:47.093296051 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:47.093439102 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:47.293668032 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:47.293873072 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:47.494277000 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:47.494352102 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:47.694648027 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:47.694982052 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:47.895296097 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:47.895435095 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:48.095747948 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:48.095837116 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:48.296068907 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:48.296242952 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:48.496522903 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:48.496678114 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:48.696949959 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:48.697027922 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:48.897325039 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:48.897505999 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:49.097862005 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:49.097980022 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:49.298382044 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:49.298487902 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:49.498874903 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:49.499016047 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:49.699412107 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:49.699527979 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:49.899882078 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:49.899991989 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:50.100332975 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:50.100490093 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:50.301017046 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:50.301127911 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:50.501569986 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:50.501708984 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:50.702137947 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:50.702244043 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:50.902580976 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:50.902679920 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:51.102962971 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:51.103044033 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:51.304964066 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:51.305064917 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:51.505270004 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:51.505410910 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:51.707837105 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:51.707947016 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:51.908606052 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:51.908724070 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:52.109834909 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:52.109925032 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:52.310616970 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:52.310734987 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:52.510993958 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:52.511230946 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:52.711625099 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:52.711745024 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:52.914916992 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:52.915050983 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:53.115425110 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:53.115540028 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:53.316591978 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:53.316668034 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:53.518784046 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:53.518970966 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:53.719316959 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:53.719502926 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:53.919795990 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:53.919861078 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:54.120193958 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:54.120398045 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:54.320712090 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:54.320959091 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:54.521378994 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:54.521447897 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:54.721806049 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:54.722073078 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:54.922344923 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:54.922549009 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:55.123080015 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:55.123452902 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:55.264420033 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:55.264622927 CET | 49740 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:55.323803902 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:55.465073109 CET | 18227 | 49740 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:57.275511026 CET | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:57.481945038 CET | 18227 | 49741 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:57.482146978 CET | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:57.484517097 CET | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:57.690444946 CET | 18227 | 49741 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:08:57.690609932 CET | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:08:57.896656990 CET | 18227 | 49741 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:03.945846081 CET | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:04.151952028 CET | 18227 | 49741 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:11.212969065 CET | 18227 | 49741 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:11.213119030 CET | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:13.226383924 CET | 49741 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:13.228857994 CET | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:13.432775974 CET | 18227 | 49741 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:13.434715986 CET | 18227 | 49742 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:13.434828043 CET | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:13.438158035 CET | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:13.643991947 CET | 18227 | 49742 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:13.644212008 CET | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:13.850090027 CET | 18227 | 49742 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:16.845592022 CET | 18227 | 49742 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:16.845807076 CET | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:19.044230938 CET | 49742 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:19.047009945 CET | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:19.247746944 CET | 18227 | 49743 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:19.247994900 CET | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:19.250448942 CET | 18227 | 49742 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:19.251883984 CET | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:19.452675104 CET | 18227 | 49743 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:19.453005075 CET | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:19.653126001 CET | 18227 | 49743 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:21.117424011 CET | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:21.317758083 CET | 18227 | 49743 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:29.306132078 CET | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:29.459018946 CET | 18227 | 49743 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:29.459239006 CET | 49743 | 18227 | 192.168.2.4 | 3.127.138.57 |
Jan 30, 2024 17:09:29.506648064 CET | 18227 | 49743 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:29.659554958 CET | 18227 | 49743 | 3.127.138.57 | 192.168.2.4 |
Jan 30, 2024 17:09:31.585031033 CET | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:31.793375015 CET | 18227 | 49744 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:31.793809891 CET | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:31.797713041 CET | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:32.005939960 CET | 18227 | 49744 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:32.006134033 CET | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:32.214406967 CET | 18227 | 49744 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:33.836033106 CET | 18227 | 49744 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:33.836234093 CET | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:36.547142982 CET | 49744 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:36.548971891 CET | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:36.749315977 CET | 18227 | 49745 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:36.749444008 CET | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:36.751580000 CET | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:36.756670952 CET | 18227 | 49744 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:36.949923038 CET | 18227 | 49745 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:36.950026035 CET | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:37.148559093 CET | 18227 | 49745 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:37.351336002 CET | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:37.549942017 CET | 18227 | 49745 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:51.692215919 CET | 18227 | 49745 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:51.692401886 CET | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:53.694715977 CET | 49745 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:53.696887970 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:53.893224955 CET | 18227 | 49745 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:53.896965981 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:53.897161007 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:53.899404049 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:54.099476099 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:54.099801064 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:54.299922943 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:55.136574984 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:55.336728096 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:58.523324013 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:58.723436117 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:09:59.210922003 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:09:59.411084890 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:01.444931984 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:01.647478104 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:01.647605896 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:01.847635031 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:02.570250034 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:02.770273924 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:02.770452976 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:02.970413923 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:02.970638037 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:03.171406031 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:03.171694994 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:03.371750116 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:03.371994019 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:03.572016001 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:03.572249889 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:03.772270918 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:03.772475004 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:03.972434998 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:03.972544909 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:04.025881052 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:04.025981903 CET | 49746 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:04.172636986 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:04.225955963 CET | 18227 | 49746 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:06.040126085 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:06.241348028 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:06.241463900 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:06.243628025 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:06.444627047 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:06.444735050 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:06.646179914 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:06.646333933 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:06.847616911 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:06.847719908 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:07.048841000 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:07.048954010 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:07.250024080 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:07.250124931 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:07.454602003 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:12.683803082 CET | 18227 | 49747 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:12.866539955 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:14.695255041 CET | 49747 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:14.698376894 CET | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:14.900815010 CET | 18227 | 49748 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:14.901004076 CET | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:14.903223038 CET | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:15.109992981 CET | 18227 | 49748 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:15.110171080 CET | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:15.312527895 CET | 18227 | 49748 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:16.789499044 CET | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:16.992105007 CET | 18227 | 49748 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:25.581134081 CET | 18227 | 49748 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:25.581331968 CET | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:27.607204914 CET | 49748 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:27.609694958 CET | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:27.809581995 CET | 18227 | 49748 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:27.810312033 CET | 18227 | 49749 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:27.810412884 CET | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:27.818089008 CET | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:28.018533945 CET | 18227 | 49749 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:28.018780947 CET | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:28.220441103 CET | 18227 | 49749 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:33.714881897 CET | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:33.915666103 CET | 18227 | 49749 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:37.814516068 CET | 18227 | 49749 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:37.814601898 CET | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:39.819660902 CET | 49749 | 18227 | 192.168.2.4 | 18.192.93.86 |
Jan 30, 2024 17:10:39.941637993 CET | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:40.020395041 CET | 18227 | 49749 | 18.192.93.86 | 192.168.2.4 |
Jan 30, 2024 17:10:40.147718906 CET | 18227 | 49750 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:40.147929907 CET | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:40.149950027 CET | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:40.356014967 CET | 18227 | 49750 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:40.356209993 CET | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:40.562290907 CET | 18227 | 49750 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:41.866703987 CET | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:42.074218035 CET | 18227 | 49750 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:47.123547077 CET | 18227 | 49750 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:47.123745918 CET | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:49.132155895 CET | 49750 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:49.133641958 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:49.336246967 CET | 18227 | 49751 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:49.336455107 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:49.338367939 CET | 18227 | 49750 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:49.338670969 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:49.541121006 CET | 18227 | 49751 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:49.541183949 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:49.743701935 CET | 18227 | 49751 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:49.991692066 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:50.194586039 CET | 18227 | 49751 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:10:58.138649940 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:10:58.341072083 CET | 18227 | 49751 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:11:02.507663012 CET | 18227 | 49751 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:11:02.507812023 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:11:04.522767067 CET | 49751 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:11:04.524475098 CET | 49752 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:11:04.725284100 CET | 18227 | 49751 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:11:04.728880882 CET | 18227 | 49752 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:11:04.730376005 CET | 49752 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:11:04.732770920 CET | 49752 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:11:04.937268019 CET | 18227 | 49752 | 18.197.239.5 | 192.168.2.4 |
Jan 30, 2024 17:11:04.938710928 CET | 49752 | 18227 | 192.168.2.4 | 18.197.239.5 |
Jan 30, 2024 17:11:05.143266916 CET | 18227 | 49752 | 18.197.239.5 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 30, 2024 17:07:17.994070053 CET | 55139 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 30, 2024 17:07:18.113529921 CET | 53 | 55139 | 1.1.1.1 | 192.168.2.4 |
Jan 30, 2024 17:08:27.322241068 CET | 55307 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 30, 2024 17:08:27.442148924 CET | 53 | 55307 | 1.1.1.1 | 192.168.2.4 |
Jan 30, 2024 17:09:31.462668896 CET | 51061 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 30, 2024 17:09:31.583060980 CET | 53 | 51061 | 1.1.1.1 | 192.168.2.4 |
Jan 30, 2024 17:10:39.820972919 CET | 64057 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 30, 2024 17:10:39.940418959 CET | 53 | 64057 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 30, 2024 17:07:17.994070053 CET | 192.168.2.4 | 1.1.1.1 | 0x82f2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2024 17:08:27.322241068 CET | 192.168.2.4 | 1.1.1.1 | 0x283 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2024 17:09:31.462668896 CET | 192.168.2.4 | 1.1.1.1 | 0x8cd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2024 17:10:39.820972919 CET | 192.168.2.4 | 1.1.1.1 | 0x8034 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 30, 2024 17:07:18.113529921 CET | 1.1.1.1 | 192.168.2.4 | 0x82f2 | No error (0) | 3.127.138.57 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2024 17:08:27.442148924 CET | 1.1.1.1 | 192.168.2.4 | 0x283 | No error (0) | 3.127.138.57 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2024 17:09:31.583060980 CET | 1.1.1.1 | 192.168.2.4 | 0x8cd3 | No error (0) | 18.192.93.86 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2024 17:10:39.940418959 CET | 1.1.1.1 | 192.168.2.4 | 0x8034 | No error (0) | 18.197.239.5 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 17:07:00 |
Start date: | 30/01/2024 |
Path: | C:\Users\user\Desktop\R3ov8eFFFP.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x460000 |
File size: | 37'888 bytes |
MD5 hash: | 0A7D2BBBE2960FF24B9273036FC472DA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 17:07:07 |
Start date: | 30/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xdd0000 |
File size: | 37'888 bytes |
MD5 hash: | 0A7D2BBBE2960FF24B9273036FC472DA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 17:07:13 |
Start date: | 30/01/2024 |
Path: | C:\Windows\SysWOW64\netsh.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1560000 |
File size: | 82'432 bytes |
MD5 hash: | 4E89A1A088BE715D6C946E55AB07C7DF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 4 |
Start time: | 17:07:13 |
Start date: | 30/01/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 17:07:13 |
Start date: | 30/01/2024 |
Path: | C:\Windows\SysWOW64\taskkill.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd30000 |
File size: | 74'240 bytes |
MD5 hash: | CA313FD7E6C2A778FFD21CFB5C1C56CD |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 6 |
Start time: | 17:07:13 |
Start date: | 30/01/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 17:07:25 |
Start date: | 30/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x250000 |
File size: | 37'888 bytes |
MD5 hash: | 0A7D2BBBE2960FF24B9273036FC472DA |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 11 |
Start time: | 17:07:33 |
Start date: | 30/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x4c0000 |
File size: | 37'888 bytes |
MD5 hash: | 0A7D2BBBE2960FF24B9273036FC472DA |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 12 |
Start time: | 17:07:42 |
Start date: | 30/01/2024 |
Path: | C:\Users\user\AppData\Roaming\ESET Service.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x690000 |
File size: | 37'888 bytes |
MD5 hash: | 0A7D2BBBE2960FF24B9273036FC472DA |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 8.3% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 37 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 00F20938 Relevance: 1.7, Strings: 1, Instructions: 492COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3AA07 Relevance: 1.6, APIs: 1, Instructions: 72fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3A2D2 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3AC24 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3A8A4 Relevance: 1.6, APIs: 1, Instructions: 59COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3AA3E Relevance: 1.6, APIs: 1, Instructions: 53fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3A8C6 Relevance: 1.5, APIs: 1, Instructions: 48COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3AC46 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C3A2FE Relevance: 1.5, APIs: 1, Instructions: 35COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F20310 Relevance: .2, Instructions: 190COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F20014 Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F203BD Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F805E0 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F20889 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F80606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C323F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C323BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 20.7% |
Dynamic/Decrypted Code Coverage: | 91.3% |
Signature Coverage: | 5.1% |
Total number of Nodes: | 277 |
Total number of Limit Nodes: | 11 |
Graph
Function 015EBD6B Relevance: 1.6, APIs: 1, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E030B Relevance: 1.6, APIs: 1, Instructions: 64nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EBDA2 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E00EC Relevance: 1.6, APIs: 1, Instructions: 50nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E010E Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0346 Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590310 Relevance: 3.9, Strings: 3, Instructions: 189COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055903BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591E41 Relevance: 2.8, Strings: 2, Instructions: 334COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591EB1 Relevance: 2.8, Strings: 2, Instructions: 280COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591ECF Relevance: 2.8, Strings: 2, Instructions: 277COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591EE2 Relevance: 2.8, Strings: 2, Instructions: 276COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590938 Relevance: 1.7, Strings: 1, Instructions: 496COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EAC19 Relevance: 1.6, APIs: 1, Instructions: 96fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E191C Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1BAA Relevance: 1.6, APIs: 1, Instructions: 92COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1208 Relevance: 1.6, APIs: 1, Instructions: 89COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2EDC Relevance: 1.6, APIs: 1, Instructions: 85COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1814 Relevance: 1.6, APIs: 1, Instructions: 84timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E193E Relevance: 1.6, APIs: 1, Instructions: 84COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EAD30 Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2E0D Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB51A Relevance: 1.6, APIs: 1, Instructions: 78COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E13BE Relevance: 1.6, APIs: 1, Instructions: 77fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0DE2 Relevance: 1.6, APIs: 1, Instructions: 77networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055923D8 Relevance: 1.6, Strings: 1, Instructions: 327COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EAC5A Relevance: 1.6, APIs: 1, Instructions: 76fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E122E Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E023C Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0006 Relevance: 1.6, APIs: 1, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB0D2 Relevance: 1.6, APIs: 1, Instructions: 73fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2FDB Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1655 Relevance: 1.6, APIs: 1, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EBBF0 Relevance: 1.6, APIs: 1, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2D47 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EBE38 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E13DE Relevance: 1.6, APIs: 1, Instructions: 67fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1AEE Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0E02 Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB19B Relevance: 1.6, APIs: 1, Instructions: 66COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1E86 Relevance: 1.6, APIs: 1, Instructions: 66libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB330 Relevance: 1.6, APIs: 1, Instructions: 64fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1852 Relevance: 1.6, APIs: 1, Instructions: 64timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EA710 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2FFE Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2F1A Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E03C0 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0032 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB0F2 Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2D6A Relevance: 1.6, APIs: 1, Instructions: 58COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EAA81 Relevance: 1.6, APIs: 1, Instructions: 57comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1682 Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EA2D2 Relevance: 1.6, APIs: 1, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1EA6 Relevance: 1.6, APIs: 1, Instructions: 56libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E2E46 Relevance: 1.6, APIs: 1, Instructions: 55COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EA078 Relevance: 1.6, APIs: 1, Instructions: 54networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB352 Relevance: 1.6, APIs: 1, Instructions: 53fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EBC22 Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EAD72 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB48C Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EA9E4 Relevance: 1.6, APIs: 1, Instructions: 51COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E0282 Relevance: 1.5, APIs: 1, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1B1E Relevance: 1.5, APIs: 1, Instructions: 49networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB1D6 Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E1C1A Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 058E03EE Relevance: 1.5, APIs: 1, Instructions: 45COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EA74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EBE72 Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EA09A Relevance: 1.5, APIs: 1, Instructions: 42networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EAA06 Relevance: 1.5, APIs: 1, Instructions: 40COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EAAAE Relevance: 1.5, APIs: 1, Instructions: 39comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB4AE Relevance: 1.5, APIs: 1, Instructions: 39COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EB572 Relevance: 1.5, APIs: 1, Instructions: 38COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015EA2FE Relevance: 1.5, APIs: 1, Instructions: 35COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055923C9 Relevance: 1.5, Strings: 1, Instructions: 264COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055924DD Relevance: 1.5, Strings: 1, Instructions: 228COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0559252D Relevance: 1.5, Strings: 1, Instructions: 217COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0559256F Relevance: 1.5, Strings: 1, Instructions: 210COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590B03 Relevance: 1.4, Strings: 1, Instructions: 194COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055925E3 Relevance: 1.4, Strings: 1, Instructions: 189COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055926C5 Relevance: 1.4, Strings: 1, Instructions: 142COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055927E0 Relevance: 1.3, Strings: 1, Instructions: 89COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590509 Relevance: 1.3, Strings: 1, Instructions: 50COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0559158F Relevance: .5, Instructions: 497COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591A28 Relevance: .3, Instructions: 283COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05592E40 Relevance: .2, Instructions: 216COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055905D7 Relevance: .2, Instructions: 172COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590BA8 Relevance: .2, Instructions: 153COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590634 Relevance: .1, Instructions: 145COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591DF8 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590080 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590C22 Relevance: .1, Instructions: 125COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591238 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591228 Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05592C90 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590C8D Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015F0DD3 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05DD1C82 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05593110 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590E55 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590D40 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590773 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05592B00 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05DD2400 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015F0E0C Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05592BA8 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0160B5A0 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055929F2 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590006 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055913B8 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 055913AA Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015F05E7 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05590D98 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591500 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0559088A Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015F0EC8 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015F0606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0160B5EF Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05DD246B Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05DD1D17 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05591450 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05592C52 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015E23F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015E23BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 10.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 12 |
Total number of Limit Nodes: | 0 |
Graph
Callgraph
Function 04A10310 Relevance: 3.9, Strings: 3, Instructions: 189COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04A103BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04A10080 Relevance: .1, Instructions: 128COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04A10006 Relevance: .0, Instructions: 41COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 008E0648 Relevance: .0, Instructions: 40COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 008E05EC Relevance: .0, Instructions: 39COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 008E0606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B623F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00B623BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 10.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 00F90310 Relevance: 3.9, Strings: 3, Instructions: 190COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F903BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00ADA710 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00ADA74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F90006 Relevance: .2, Instructions: 186COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F605E0 Relevance: .0, Instructions: 44COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00F60606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AD23F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AD23BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 10% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00FDA710 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00FDA74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04F90310 Relevance: .2, Instructions: 191COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04F903BD Relevance: .1, Instructions: 135COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04F90080 Relevance: .1, Instructions: 132COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04F90006 Relevance: .1, Instructions: 54COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 012705E0 Relevance: .0, Instructions: 43COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01270606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00FD23F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00FD23BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |