Windows
Analysis Report
mhYCwt8wBz.exe
Overview
General Information
Sample name: | mhYCwt8wBz.exerenamed because original name is a hash value |
Original sample name: | 2fb7fc0949aa14070e5e5d1ec37d48e7.exe |
Analysis ID: | 1421033 |
MD5: | 2fb7fc0949aa14070e5e5d1ec37d48e7 |
SHA1: | 9b0043790d9881f690e11086004d3218648d9c22 |
SHA256: | 246ab25a7240d684c1a6bf5abd6bcd6f13e0d86c97940883bc249e2b7cb23853 |
Tags: | exenjratRAT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- mhYCwt8wBz.exe (PID: 6988 cmdline:
"C:\Users\ user\Deskt op\mhYCwt8 wBz.exe" MD5: 2FB7FC0949AA14070E5E5D1EC37D48E7) - Exspa.exe (PID: 6552 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\Exspa. exe" MD5: 2FB7FC0949AA14070E5E5D1EC37D48E7) - cmd.exe (PID: 2004 cmdline:
"C:\Window s\System32 \cmd.exe" /C choice /C Y /N /D Y /T 5 & Del "C:\Us ers\user\D esktop\mhY Cwt8wBz.ex e" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 3444 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - choice.exe (PID: 7060 cmdline:
choice /C Y /N /D Y /T 5 MD5: FCE0E41C87DC4ABBE976998AD26C27E4)
- Exspa.exe (PID: 7444 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\Exspa. exe" .. MD5: 2FB7FC0949AA14070E5E5D1EC37D48E7)
- Exspa.exe (PID: 7612 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\Exspa. exe" .. MD5: 2FB7FC0949AA14070E5E5D1EC37D48E7)
- Exspa.exe (PID: 7728 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\Exspa. exe" .. MD5: 2FB7FC0949AA14070E5E5D1EC37D48E7)
- Exspa.exe (PID: 7836 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Microsoft \Windows\S tart Menu\ Programs\S tartup\Exs pa.exe" MD5: 2FB7FC0949AA14070E5E5D1EC37D48E7)
- Exspa.exe (PID: 7960 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Microsoft \Windows\S tart Menu\ Programs\S tartup\Exs pa.exe" MD5: 2FB7FC0949AA14070E5E5D1EC37D48E7)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
NjRAT | RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored. |
{"Host": "6.tcp.eu.ngrok.io", "Port": "11964", "Campaign ID": "HacKed", "Version": "Platinum", "Network Seprator": "|Ghost|"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Unknown_Malware_Sample_Jul17_2 | Detects unknown malware sample with pastebin RAW URL | Florian Roth |
| |
Click to see the 4 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Unknown_Malware_Sample_Jul17_2 | Detects unknown malware sample with pastebin RAW URL | Florian Roth |
| |
Click to see the 13 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
Njrat | detect njRAT in memory | JPCERT/CC Incident Response Group |
| |
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Click to see the 6 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Unknown_Malware_Sample_Jul17_2 | Detects unknown malware sample with pastebin RAW URL | Florian Roth |
| |
Click to see the 21 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing: |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Data Obfuscation |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | URLs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 1_2_0501172A | |
Source: | Code function: | 1_2_050116EF |
Source: | Code function: | 1_2_04F51B0A |
Source: | Binary or memory string: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | Code function: | 1_2_050114EA | |
Source: | Code function: | 1_2_050114B3 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 6_2_0110073D |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | Registry value created: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 121 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 1 Masquerading | 1 Input Capture | 11 Security Software Discovery | Remote Services | 1 Input Capture | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 12 Process Injection | 11 Disable or Modify Tools | LSASS Memory | 2 Process Discovery | Remote Desktop Protocol | 1 Archive Collected Data | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 121 Registry Run Keys / Startup Folder | 31 Virtualization/Sandbox Evasion | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 1 Access Token Manipulation | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 11 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 12 Process Injection | LSA Secrets | 2 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Obfuscated Files or Information | Cached Domain Credentials | 2 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Software Packing | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 File Deletion | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
84% | ReversingLabs | ByteCode-MSIL.Backdoor.Bladabhindi | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Dropper.Gen | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
84% | ReversingLabs | ByteCode-MSIL.Backdoor.Bladabhindi | ||
84% | ReversingLabs | ByteCode-MSIL.Backdoor.Bladabhindi |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
6.tcp.eu.ngrok.io | 3.68.171.119 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
3.66.38.117 | unknown | United States | 16509 | AMAZON-02US | false | |
52.28.247.255 | unknown | United States | 16509 | AMAZON-02US | false | |
3.68.171.119 | 6.tcp.eu.ngrok.io | United States | 16509 | AMAZON-02US | true | |
3.69.157.220 | unknown | United States | 16509 | AMAZON-02US | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1421033 |
Start date and time: | 2024-04-05 19:21:05 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 46s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | mhYCwt8wBz.exerenamed because original name is a hash value |
Original Sample Name: | 2fb7fc0949aa14070e5e5d1ec37d48e7.exe |
Detection: | MAL |
Classification: | mal100.phis.troj.adwa.spyw.expl.evad.winEXE@13/5@4/4 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: mhYCwt8wBz.exe
Time | Type | Description |
---|---|---|
18:22:07 | Autostart | |
18:22:15 | Autostart | |
18:22:24 | Autostart | |
18:22:32 | Autostart | |
18:22:40 | Autostart | |
19:22:38 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3.66.38.117 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
52.28.247.255 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
3.68.171.119 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
3.69.157.220 | Get hash | malicious | AsyncRAT, DcRat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
6.tcp.eu.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Users\user\AppData\Local\Temp\Exspa.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 525 |
Entropy (8bit): | 5.259753436570609 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve |
MD5: | 260E01CC001F9C4643CA7A62F395D747 |
SHA1: | 492AD0ACE3A9C8736909866EEA168962D418BE5A |
SHA-256: | 4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030 |
SHA-512: | 01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\mhYCwt8wBz.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 525 |
Entropy (8bit): | 5.259753436570609 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve |
MD5: | 260E01CC001F9C4643CA7A62F395D747 |
SHA1: | 492AD0ACE3A9C8736909866EEA168962D418BE5A |
SHA-256: | 4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030 |
SHA-512: | 01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\mhYCwt8wBz.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 67072 |
Entropy (8bit): | 5.822801904545 |
Encrypted: | false |
SSDEEP: | 1536:FIkoUoN36tSQviFw1gnRuBnvbLfLteF3nLrB9z3nNaF9bIS9vM:FIkoUoN36tSQviFC08BnHfWl9zdaF9bw |
MD5: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
SHA1: | 9B0043790D9881F690E11086004D3218648D9C22 |
SHA-256: | 246AB25A7240D684C1A6BF5ABD6BCD6F13E0D86C97940883BC249E2B7CB23853 |
SHA-512: | 13A475DF0962A72F8C817511DBDA22EFB07C41167EBAC229C7B0193A88C0F6BF383025E1327732B152D8A53AB4358D4B40D3C6F4B09CC3881165BDA826E16F3B |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\Exspa.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 67072 |
Entropy (8bit): | 5.822801904545 |
Encrypted: | false |
SSDEEP: | 1536:FIkoUoN36tSQviFw1gnRuBnvbLfLteF3nLrB9z3nNaF9bIS9vM:FIkoUoN36tSQviFC08BnHfWl9zdaF9bw |
MD5: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
SHA1: | 9B0043790D9881F690E11086004D3218648D9C22 |
SHA-256: | 246AB25A7240D684C1A6BF5ABD6BCD6F13E0D86C97940883BC249E2B7CB23853 |
SHA-512: | 13A475DF0962A72F8C817511DBDA22EFB07C41167EBAC229C7B0193A88C0F6BF383025E1327732B152D8A53AB4358D4B40D3C6F4B09CC3881165BDA826E16F3B |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\Exspa.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 176 |
Entropy (8bit): | 5.162178625646672 |
Encrypted: | false |
SSDEEP: | 3:HRAbABGQYm5uOt+kiEaKC5SufyM1K/RFofD6tRQ8Wu0rvQJ5UvycAI9Ryn:HRYFVmwOwknaZ5SuH1MUmt28307QJ5Uo |
MD5: | C33C9E15DA17109681EDD9C87E157454 |
SHA1: | 09D81E9DB269945CCF07DA9EFC4E991A13777E78 |
SHA-256: | F783C993AA04883B0E64E222FBA31CA6A936F59ED581D673095DEBCD014D0033 |
SHA-512: | 7DEF42DCE5BFEA6F72DDC47BB0505D71A9F0D98FD230E56FFCCFADC59B50783D5DD283F8BE9300A886F4403AE608DF2948A22A7E7A12112F77E17360ACFDB5BC |
Malicious: | true |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.822801904545 |
TrID: |
|
File name: | mhYCwt8wBz.exe |
File size: | 67'072 bytes |
MD5: | 2fb7fc0949aa14070e5e5d1ec37d48e7 |
SHA1: | 9b0043790d9881f690e11086004d3218648d9c22 |
SHA256: | 246ab25a7240d684c1a6bf5abd6bcd6f13e0d86c97940883bc249e2b7cb23853 |
SHA512: | 13a475df0962a72f8c817511dbda22efb07c41167ebac229c7b0193a88c0f6bf383025e1327732b152d8a53ab4358d4b40d3c6f4b09cc3881165bda826e16f3b |
SSDEEP: | 1536:FIkoUoN36tSQviFw1gnRuBnvbLfLteF3nLrB9z3nNaF9bIS9vM:FIkoUoN36tSQviFC08BnHfWl9zdaF9bw |
TLSH: | 11634B4877958A55D2BD2E7844F296518730E50B6D03F72E4CD120FBABB3EC44A82BE7 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...K..f................................. ... ....@.. .......................`............@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x411c2e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66069F4B [Fri Mar 29 11:00:27 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x11bd4 | 0x57 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x12000 | 0x240 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x14000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xfc34 | 0xfe00 | 0008859b44bad9698c92ad320324bed2 | False | 0.47038016732283466 | data | 5.846326734727716 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x12000 | 0x240 | 0x400 | 08e614b8f1d20a50b5b3684e856ff5f3 | False | 0.3115234375 | data | 4.965539353996097 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x14000 | 0xc | 0x200 | 4998dab38619fe0880bcb520e43fac21 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x12058 | 0x1e7 | XML 1.0 document, ASCII text, with CRLF line terminators | 0.5338809034907598 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 5, 2024 19:22:07.297816992 CEST | 49730 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:07.537115097 CEST | 11964 | 49730 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:08.041009903 CEST | 49730 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:08.280199051 CEST | 11964 | 49730 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:08.791017056 CEST | 49730 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:09.030184984 CEST | 11964 | 49730 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:09.541027069 CEST | 49730 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:09.780365944 CEST | 11964 | 49730 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:10.290986061 CEST | 49730 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:10.530154943 CEST | 11964 | 49730 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:12.543591976 CEST | 49736 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:12.785280943 CEST | 11964 | 49736 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:13.290991068 CEST | 49736 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:13.531755924 CEST | 11964 | 49736 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:14.041004896 CEST | 49736 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:14.282237053 CEST | 11964 | 49736 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:14.790998936 CEST | 49736 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:15.033235073 CEST | 11964 | 49736 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:15.541068077 CEST | 49736 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:15.781963110 CEST | 11964 | 49736 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:17.792440891 CEST | 49738 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:18.033575058 CEST | 11964 | 49738 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:18.541110039 CEST | 49738 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:18.781913042 CEST | 11964 | 49738 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:19.291182995 CEST | 49738 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:19.532299042 CEST | 11964 | 49738 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:20.041100979 CEST | 49738 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:20.281969070 CEST | 11964 | 49738 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:20.791136980 CEST | 49738 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:21.032208920 CEST | 11964 | 49738 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:23.042489052 CEST | 49739 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:23.288069010 CEST | 11964 | 49739 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:23.790998936 CEST | 49739 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:24.030498028 CEST | 11964 | 49739 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:24.541148901 CEST | 49739 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:24.780972958 CEST | 11964 | 49739 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:25.291121006 CEST | 49739 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:25.530958891 CEST | 11964 | 49739 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:26.041121960 CEST | 49739 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:26.280565023 CEST | 11964 | 49739 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:29.386138916 CEST | 49740 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:29.626821995 CEST | 11964 | 49740 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:30.134767056 CEST | 49740 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:30.374135971 CEST | 11964 | 49740 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:30.884887934 CEST | 49740 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:31.125152111 CEST | 11964 | 49740 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:31.634818077 CEST | 49740 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:31.874281883 CEST | 11964 | 49740 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:32.384761095 CEST | 49740 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:32.624665976 CEST | 11964 | 49740 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:34.651366949 CEST | 49741 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:34.892337084 CEST | 11964 | 49741 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:35.400394917 CEST | 49741 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:35.641218901 CEST | 11964 | 49741 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:36.150466919 CEST | 49741 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:36.391288996 CEST | 11964 | 49741 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:36.900392056 CEST | 49741 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:37.141921043 CEST | 11964 | 49741 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:37.650381088 CEST | 49741 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:37.891030073 CEST | 11964 | 49741 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:39.902389050 CEST | 49742 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:40.143434048 CEST | 11964 | 49742 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:40.650388956 CEST | 49742 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:40.893666029 CEST | 11964 | 49742 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:41.400412083 CEST | 49742 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:41.641434908 CEST | 11964 | 49742 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:42.150455952 CEST | 49742 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:42.391464949 CEST | 11964 | 49742 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:42.900372982 CEST | 49742 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:43.141352892 CEST | 11964 | 49742 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:45.214732885 CEST | 49743 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:45.454227924 CEST | 11964 | 49743 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:45.962941885 CEST | 49743 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:46.201275110 CEST | 11964 | 49743 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:46.712901115 CEST | 49743 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:46.951157093 CEST | 11964 | 49743 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:47.463067055 CEST | 49743 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:47.702070951 CEST | 11964 | 49743 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:48.212982893 CEST | 49743 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:48.451857090 CEST | 11964 | 49743 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:50.464070082 CEST | 49745 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:50.705948114 CEST | 11964 | 49745 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:51.212992907 CEST | 49745 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:51.454996109 CEST | 11964 | 49745 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:51.962922096 CEST | 49745 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:52.204854965 CEST | 11964 | 49745 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:52.712944984 CEST | 49745 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:52.954829931 CEST | 11964 | 49745 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:53.462941885 CEST | 49745 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:53.704904079 CEST | 11964 | 49745 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:55.714411974 CEST | 49746 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:55.956093073 CEST | 11964 | 49746 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:56.462908030 CEST | 49746 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:56.704787970 CEST | 11964 | 49746 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:57.212958097 CEST | 49746 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:57.454622030 CEST | 11964 | 49746 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:57.963002920 CEST | 49746 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:58.204879045 CEST | 11964 | 49746 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:22:58.712914944 CEST | 49746 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:22:58.954618931 CEST | 11964 | 49746 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:23:02.179332972 CEST | 49747 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:23:02.419209957 CEST | 11964 | 49747 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:23:02.931751966 CEST | 49747 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:23:03.171639919 CEST | 11964 | 49747 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:23:03.681854010 CEST | 49747 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:23:03.925462961 CEST | 11964 | 49747 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:23:04.431691885 CEST | 49747 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:23:04.671680927 CEST | 11964 | 49747 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:23:05.181653023 CEST | 49747 | 11964 | 192.168.2.4 | 3.68.171.119 |
Apr 5, 2024 19:23:05.422029018 CEST | 11964 | 49747 | 3.68.171.119 | 192.168.2.4 |
Apr 5, 2024 19:23:07.572887897 CEST | 49748 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:07.814635992 CEST | 11964 | 49748 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:08.322419882 CEST | 49748 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:08.562649965 CEST | 11964 | 49748 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:09.072408915 CEST | 49748 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:09.312814951 CEST | 11964 | 49748 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:09.822283983 CEST | 49748 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:10.062478065 CEST | 11964 | 49748 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:10.572297096 CEST | 49748 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:10.815032959 CEST | 11964 | 49748 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:12.823803902 CEST | 49749 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:13.064291000 CEST | 11964 | 49749 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:13.572813034 CEST | 49749 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:13.813113928 CEST | 11964 | 49749 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:14.323796988 CEST | 49749 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:14.564997911 CEST | 11964 | 49749 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:15.072309971 CEST | 49749 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:15.312861919 CEST | 11964 | 49749 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:15.822365046 CEST | 49749 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:16.062577009 CEST | 11964 | 49749 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:18.073355913 CEST | 49750 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:18.313458920 CEST | 11964 | 49750 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:18.824409008 CEST | 49750 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:19.064522028 CEST | 11964 | 49750 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:19.572319031 CEST | 49750 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:19.812208891 CEST | 11964 | 49750 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:20.385602951 CEST | 49750 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:20.625541925 CEST | 11964 | 49750 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:21.275468111 CEST | 49750 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:21.515302896 CEST | 11964 | 49750 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:23.526591063 CEST | 49751 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:23.768583059 CEST | 11964 | 49751 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:24.369205952 CEST | 49751 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:24.610922098 CEST | 11964 | 49751 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:25.259862900 CEST | 49751 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:25.501583099 CEST | 11964 | 49751 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:26.072318077 CEST | 49751 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:26.314327002 CEST | 11964 | 49751 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:26.869163990 CEST | 49751 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:27.110781908 CEST | 11964 | 49751 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:29.123294115 CEST | 49752 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:29.364614010 CEST | 11964 | 49752 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:29.884793997 CEST | 49752 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:30.127505064 CEST | 11964 | 49752 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:30.681695938 CEST | 49752 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:30.922976017 CEST | 11964 | 49752 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:31.572388887 CEST | 49752 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:31.813725948 CEST | 11964 | 49752 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:32.384944916 CEST | 49752 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:32.626513958 CEST | 11964 | 49752 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:34.638606071 CEST | 49753 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:34.881577969 CEST | 11964 | 49753 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:35.462948084 CEST | 49753 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:35.705112934 CEST | 11964 | 49753 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:36.259927988 CEST | 49753 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:36.500511885 CEST | 11964 | 49753 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:37.072329044 CEST | 49753 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:37.312895060 CEST | 11964 | 49753 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:37.869240046 CEST | 49753 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:38.110050917 CEST | 11964 | 49753 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:39.996628046 CEST | 49754 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:40.236109972 CEST | 11964 | 49754 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:40.744123936 CEST | 49754 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:40.983221054 CEST | 11964 | 49754 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:41.572367907 CEST | 49754 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:41.812868118 CEST | 11964 | 49754 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:42.369196892 CEST | 49754 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:42.608921051 CEST | 11964 | 49754 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:43.259850025 CEST | 49754 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:43.499108076 CEST | 11964 | 49754 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:45.245676041 CEST | 49755 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:45.486275911 CEST | 11964 | 49755 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:46.072351933 CEST | 49755 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:46.312643051 CEST | 11964 | 49755 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:46.884871006 CEST | 49755 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:47.125252008 CEST | 11964 | 49755 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:47.775651932 CEST | 49755 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:48.020858049 CEST | 11964 | 49755 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:48.572324038 CEST | 49755 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:48.812227011 CEST | 11964 | 49755 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:50.452354908 CEST | 49756 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:50.692250013 CEST | 11964 | 49756 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:51.247174978 CEST | 49756 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:51.486927032 CEST | 11964 | 49756 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:52.072323084 CEST | 49756 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:52.311897993 CEST | 11964 | 49756 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:52.962955952 CEST | 49756 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:53.202617884 CEST | 11964 | 49756 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:53.775440931 CEST | 49756 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:54.015185118 CEST | 11964 | 49756 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:56.246052027 CEST | 49757 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:56.488111019 CEST | 11964 | 49757 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:57.077641964 CEST | 49757 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:57.319461107 CEST | 11964 | 49757 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:57.884896994 CEST | 49757 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:58.126749039 CEST | 11964 | 49757 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:58.681824923 CEST | 49757 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:58.923748970 CEST | 11964 | 49757 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:23:59.572442055 CEST | 49757 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:23:59.814918995 CEST | 11964 | 49757 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:01.263046980 CEST | 49758 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:01.504719019 CEST | 11964 | 49758 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:02.087954998 CEST | 49758 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:02.329411030 CEST | 11964 | 49758 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:02.884826899 CEST | 49758 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:03.127078056 CEST | 11964 | 49758 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:03.681822062 CEST | 49758 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:03.923358917 CEST | 11964 | 49758 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:04.587965965 CEST | 49758 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:04.829462051 CEST | 11964 | 49758 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:06.167346954 CEST | 49759 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:06.410228968 CEST | 11964 | 49759 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:07.072443008 CEST | 49759 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:07.313772917 CEST | 11964 | 49759 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:07.869225979 CEST | 49759 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:08.124398947 CEST | 11964 | 49759 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:08.759835005 CEST | 49759 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:09.001341105 CEST | 11964 | 49759 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:09.572391033 CEST | 49759 | 11964 | 192.168.2.4 | 3.69.157.220 |
Apr 5, 2024 19:24:09.813731909 CEST | 11964 | 49759 | 3.69.157.220 | 192.168.2.4 |
Apr 5, 2024 19:24:12.649383068 CEST | 49760 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:12.892554045 CEST | 11964 | 49760 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:13.587976933 CEST | 49760 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:13.830274105 CEST | 11964 | 49760 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:14.384968042 CEST | 49760 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:14.627065897 CEST | 11964 | 49760 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:15.181706905 CEST | 49760 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:15.423703909 CEST | 11964 | 49760 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:16.072335958 CEST | 49760 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:16.314817905 CEST | 11964 | 49760 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:17.479774952 CEST | 49761 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:17.719369888 CEST | 11964 | 49761 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:18.224705935 CEST | 49761 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:18.464500904 CEST | 11964 | 49761 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:19.072331905 CEST | 49761 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:19.311927080 CEST | 11964 | 49761 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:19.962969065 CEST | 49761 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:20.203484058 CEST | 11964 | 49761 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:20.775475025 CEST | 49761 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:21.019875050 CEST | 11964 | 49761 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:22.109770060 CEST | 49762 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:22.350229979 CEST | 11964 | 49762 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:22.869206905 CEST | 49762 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:23.109728098 CEST | 11964 | 49762 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:23.666110039 CEST | 49762 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:23.906630993 CEST | 11964 | 49762 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:24.572341919 CEST | 49762 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:24.813199997 CEST | 11964 | 49762 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:25.462975025 CEST | 49762 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:25.703763008 CEST | 11964 | 49762 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:26.714397907 CEST | 49763 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:26.956549883 CEST | 11964 | 49763 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:27.572352886 CEST | 49763 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:27.813064098 CEST | 11964 | 49763 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:28.384850025 CEST | 49763 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:28.625664949 CEST | 11964 | 49763 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:29.181760073 CEST | 49763 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:29.422352076 CEST | 11964 | 49763 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:30.087980986 CEST | 49763 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:30.328695059 CEST | 11964 | 49763 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:32.058938980 CEST | 49764 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:32.301079035 CEST | 11964 | 49764 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:32.962969065 CEST | 49764 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:33.205022097 CEST | 11964 | 49764 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:33.759872913 CEST | 49764 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:34.001944065 CEST | 11964 | 49764 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:34.572336912 CEST | 49764 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:34.814367056 CEST | 11964 | 49764 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:35.463032007 CEST | 49764 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:35.705465078 CEST | 11964 | 49764 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:36.589509964 CEST | 49765 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:36.831367970 CEST | 11964 | 49765 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:37.337991953 CEST | 49765 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:37.579674006 CEST | 11964 | 49765 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:38.087984085 CEST | 49765 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:38.329571962 CEST | 11964 | 49765 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:38.839442015 CEST | 49765 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:39.081033945 CEST | 11964 | 49765 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:39.588037014 CEST | 49765 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:39.829595089 CEST | 11964 | 49765 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:40.651725054 CEST | 49766 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:40.892986059 CEST | 11964 | 49766 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:41.400532007 CEST | 49766 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:41.641864061 CEST | 11964 | 49766 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:42.150496960 CEST | 49766 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:42.391733885 CEST | 11964 | 49766 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:42.900475025 CEST | 49766 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:43.141802073 CEST | 11964 | 49766 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:43.650490046 CEST | 49766 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:43.891813993 CEST | 11964 | 49766 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:44.668334961 CEST | 49767 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:44.908256054 CEST | 11964 | 49767 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:45.572386980 CEST | 49767 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:45.811589956 CEST | 11964 | 49767 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:46.322370052 CEST | 49767 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:46.561327934 CEST | 11964 | 49767 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:47.072391033 CEST | 49767 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:47.312304974 CEST | 11964 | 49767 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:47.822360992 CEST | 49767 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:48.061244965 CEST | 11964 | 49767 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:49.184050083 CEST | 49768 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:49.425971031 CEST | 11964 | 49768 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:49.931859016 CEST | 49768 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:50.174396992 CEST | 11964 | 49768 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:50.681745052 CEST | 49768 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:50.923355103 CEST | 11964 | 49768 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:51.431860924 CEST | 49768 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:51.674660921 CEST | 11964 | 49768 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:52.181741953 CEST | 49768 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:52.423387051 CEST | 11964 | 49768 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:53.089647055 CEST | 49769 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:53.331455946 CEST | 11964 | 49769 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:53.838017941 CEST | 49769 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:54.080256939 CEST | 11964 | 49769 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:54.588021994 CEST | 49769 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:54.829710007 CEST | 11964 | 49769 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:55.338016987 CEST | 49769 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:55.579731941 CEST | 11964 | 49769 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:56.088097095 CEST | 49769 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:56.329849958 CEST | 11964 | 49769 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:56.964318037 CEST | 49770 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:57.204320908 CEST | 11964 | 49770 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:57.713006020 CEST | 49770 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:57.952430964 CEST | 11964 | 49770 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:58.462999105 CEST | 49770 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:58.702302933 CEST | 11964 | 49770 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:59.212997913 CEST | 49770 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:24:59.452316999 CEST | 11964 | 49770 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:24:59.962994099 CEST | 49770 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:00.202317953 CEST | 11964 | 49770 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:00.792211056 CEST | 49771 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:01.031544924 CEST | 11964 | 49771 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:01.541148901 CEST | 49771 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:01.780400038 CEST | 11964 | 49771 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:02.291136026 CEST | 49771 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:02.530307055 CEST | 11964 | 49771 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:03.041126013 CEST | 49771 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:03.280313969 CEST | 11964 | 49771 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:03.791348934 CEST | 49771 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:04.030649900 CEST | 11964 | 49771 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:04.573507071 CEST | 49772 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:04.812726974 CEST | 11964 | 49772 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:05.322411060 CEST | 49772 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:05.562650919 CEST | 11964 | 49772 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:06.066909075 CEST | 49772 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:06.306195021 CEST | 11964 | 49772 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:06.806775093 CEST | 49772 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:07.045878887 CEST | 11964 | 49772 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:07.556751966 CEST | 49772 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:07.795777082 CEST | 11964 | 49772 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:08.315831900 CEST | 49773 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:08.555104971 CEST | 11964 | 49773 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:09.056783915 CEST | 49773 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:09.296416044 CEST | 11964 | 49773 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:09.806767941 CEST | 49773 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:10.048887014 CEST | 11964 | 49773 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:10.556766033 CEST | 49773 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:10.796128988 CEST | 11964 | 49773 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:11.306761980 CEST | 49773 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:11.546577930 CEST | 11964 | 49773 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:12.028295040 CEST | 49774 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:12.268028021 CEST | 11964 | 49774 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:12.775547981 CEST | 49774 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:13.015346050 CEST | 11964 | 49774 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:13.525516033 CEST | 49774 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:13.765528917 CEST | 11964 | 49774 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:14.275585890 CEST | 49774 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:14.515638113 CEST | 11964 | 49774 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:15.025501966 CEST | 49774 | 11964 | 192.168.2.4 | 52.28.247.255 |
Apr 5, 2024 19:25:15.265203953 CEST | 11964 | 49774 | 52.28.247.255 | 192.168.2.4 |
Apr 5, 2024 19:25:15.842367887 CEST | 49775 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:16.082531929 CEST | 11964 | 49775 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:16.588037014 CEST | 49775 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:16.828027964 CEST | 11964 | 49775 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:17.338047028 CEST | 49775 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:17.578061104 CEST | 11964 | 49775 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:18.088108063 CEST | 49775 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:18.328228951 CEST | 11964 | 49775 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:18.838028908 CEST | 49775 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:19.077990055 CEST | 11964 | 49775 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:19.495503902 CEST | 49776 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:19.737445116 CEST | 11964 | 49776 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:20.244266033 CEST | 49776 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:20.486155987 CEST | 11964 | 49776 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:20.994402885 CEST | 49776 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:21.236941099 CEST | 11964 | 49776 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:21.759912014 CEST | 49776 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:22.001879930 CEST | 11964 | 49776 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:22.666189909 CEST | 49776 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:22.908193111 CEST | 11964 | 49776 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:23.292469025 CEST | 49777 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:23.532253981 CEST | 11964 | 49777 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:24.088025093 CEST | 49777 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:24.328263044 CEST | 11964 | 49777 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:24.900548935 CEST | 49777 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:25.140991926 CEST | 11964 | 49777 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:25.697627068 CEST | 49777 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:25.937335014 CEST | 11964 | 49777 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:26.588052034 CEST | 49777 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:26.827799082 CEST | 11964 | 49777 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:27.200978041 CEST | 49778 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:27.442257881 CEST | 11964 | 49778 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:28.088017941 CEST | 49778 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:28.329315901 CEST | 11964 | 49778 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:28.884902954 CEST | 49778 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:29.126118898 CEST | 11964 | 49778 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:29.697451115 CEST | 49778 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:29.938955069 CEST | 11964 | 49778 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:30.494277000 CEST | 49778 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:30.735719919 CEST | 11964 | 49778 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:31.074537039 CEST | 49779 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:31.316025972 CEST | 11964 | 49779 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:31.822504997 CEST | 49779 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:32.063308001 CEST | 11964 | 49779 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:32.572494030 CEST | 49779 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:32.813374043 CEST | 11964 | 49779 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:33.322396994 CEST | 49779 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:33.563108921 CEST | 11964 | 49779 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:34.072407961 CEST | 49779 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:34.313245058 CEST | 11964 | 49779 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:34.636576891 CEST | 49780 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:34.877774954 CEST | 11964 | 49780 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:35.400580883 CEST | 49780 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:35.642462015 CEST | 11964 | 49780 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:36.291249990 CEST | 49780 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:36.532505989 CEST | 11964 | 49780 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:37.197432995 CEST | 49780 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:37.438641071 CEST | 11964 | 49780 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:37.947391987 CEST | 49780 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:38.190748930 CEST | 11964 | 49780 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:38.639174938 CEST | 49781 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:38.879858017 CEST | 11964 | 49781 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:39.384897947 CEST | 49781 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:39.625772953 CEST | 11964 | 49781 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:40.291152000 CEST | 49781 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:40.531929016 CEST | 11964 | 49781 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:41.166192055 CEST | 49781 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:41.406826019 CEST | 11964 | 49781 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:41.978703022 CEST | 49781 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:42.220755100 CEST | 11964 | 49781 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:42.498361111 CEST | 49782 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:42.737929106 CEST | 11964 | 49782 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:43.275521994 CEST | 49782 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:43.515212059 CEST | 11964 | 49782 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:44.166256905 CEST | 49782 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:44.406040907 CEST | 11964 | 49782 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:44.978735924 CEST | 49782 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:45.218743086 CEST | 11964 | 49782 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:45.775568962 CEST | 49782 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:46.015441895 CEST | 11964 | 49782 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:46.276957989 CEST | 49783 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:46.517575979 CEST | 11964 | 49783 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:47.025542974 CEST | 49783 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:47.266141891 CEST | 11964 | 49783 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:47.775556087 CEST | 49783 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:48.015958071 CEST | 11964 | 49783 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:48.525991917 CEST | 49783 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:48.766473055 CEST | 11964 | 49783 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:49.275557041 CEST | 49783 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:49.516298056 CEST | 11964 | 49783 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:49.761346102 CEST | 49784 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:50.002140045 CEST | 11964 | 49784 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:50.509924889 CEST | 49784 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:50.750116110 CEST | 11964 | 49784 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:51.259932995 CEST | 49784 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:51.501058102 CEST | 11964 | 49784 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:52.009929895 CEST | 49784 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:52.250560999 CEST | 11964 | 49784 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:52.759918928 CEST | 49784 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:53.000305891 CEST | 11964 | 49784 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:53.229871988 CEST | 49785 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:53.469588041 CEST | 11964 | 49785 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:53.978678942 CEST | 49785 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:54.218391895 CEST | 11964 | 49785 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:54.728646040 CEST | 49785 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:54.968301058 CEST | 11964 | 49785 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:55.478674889 CEST | 49785 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:55.718230009 CEST | 11964 | 49785 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:56.228652954 CEST | 49785 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:56.469310999 CEST | 11964 | 49785 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:57.843935966 CEST | 49786 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:58.085999012 CEST | 11964 | 49786 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:58.596972942 CEST | 49786 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:58.839190960 CEST | 11964 | 49786 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:25:59.353660107 CEST | 49786 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:25:59.595747948 CEST | 11964 | 49786 | 3.66.38.117 | 192.168.2.4 |
Apr 5, 2024 19:26:00.244399071 CEST | 49786 | 11964 | 192.168.2.4 | 3.66.38.117 |
Apr 5, 2024 19:26:00.486531019 CEST | 11964 | 49786 | 3.66.38.117 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 5, 2024 19:22:07.168579102 CEST | 57842 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 5, 2024 19:22:07.295521021 CEST | 53 | 57842 | 1.1.1.1 | 192.168.2.4 |
Apr 5, 2024 19:23:07.432658911 CEST | 56576 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 5, 2024 19:23:07.571945906 CEST | 53 | 56576 | 1.1.1.1 | 192.168.2.4 |
Apr 5, 2024 19:24:12.509212017 CEST | 60585 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 5, 2024 19:24:12.648593903 CEST | 53 | 60585 | 1.1.1.1 | 192.168.2.4 |
Apr 5, 2024 19:25:15.714392900 CEST | 65476 | 53 | 192.168.2.4 | 1.1.1.1 |
Apr 5, 2024 19:25:15.840666056 CEST | 53 | 65476 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 5, 2024 19:22:07.168579102 CEST | 192.168.2.4 | 1.1.1.1 | 0xb75a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 5, 2024 19:23:07.432658911 CEST | 192.168.2.4 | 1.1.1.1 | 0xaaaf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 5, 2024 19:24:12.509212017 CEST | 192.168.2.4 | 1.1.1.1 | 0xed99 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Apr 5, 2024 19:25:15.714392900 CEST | 192.168.2.4 | 1.1.1.1 | 0x4cdb | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 5, 2024 19:22:07.295521021 CEST | 1.1.1.1 | 192.168.2.4 | 0xb75a | No error (0) | 3.68.171.119 | A (IP address) | IN (0x0001) | false | ||
Apr 5, 2024 19:23:07.571945906 CEST | 1.1.1.1 | 192.168.2.4 | 0xaaaf | No error (0) | 3.69.157.220 | A (IP address) | IN (0x0001) | false | ||
Apr 5, 2024 19:24:12.648593903 CEST | 1.1.1.1 | 192.168.2.4 | 0xed99 | No error (0) | 52.28.247.255 | A (IP address) | IN (0x0001) | false | ||
Apr 5, 2024 19:25:15.840666056 CEST | 1.1.1.1 | 192.168.2.4 | 0x4cdb | No error (0) | 3.66.38.117 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 19:21:50 |
Start date: | 05/04/2024 |
Path: | C:\Users\user\Desktop\mhYCwt8wBz.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x60000 |
File size: | 67'072 bytes |
MD5 hash: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 19:21:57 |
Start date: | 05/04/2024 |
Path: | C:\Users\user\AppData\Local\Temp\Exspa.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x770000 |
File size: | 67'072 bytes |
MD5 hash: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 19:21:57 |
Start date: | 05/04/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 19:21:57 |
Start date: | 05/04/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 19:21:57 |
Start date: | 05/04/2024 |
Path: | C:\Windows\SysWOW64\choice.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa0000 |
File size: | 28'160 bytes |
MD5 hash: | FCE0E41C87DC4ABBE976998AD26C27E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 6 |
Start time: | 19:22:15 |
Start date: | 05/04/2024 |
Path: | C:\Users\user\AppData\Local\Temp\Exspa.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb40000 |
File size: | 67'072 bytes |
MD5 hash: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 9 |
Start time: | 19:22:24 |
Start date: | 05/04/2024 |
Path: | C:\Users\user\AppData\Local\Temp\Exspa.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb90000 |
File size: | 67'072 bytes |
MD5 hash: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 10 |
Start time: | 19:22:32 |
Start date: | 05/04/2024 |
Path: | C:\Users\user\AppData\Local\Temp\Exspa.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd90000 |
File size: | 67'072 bytes |
MD5 hash: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 12 |
Start time: | 19:22:40 |
Start date: | 05/04/2024 |
Path: | C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Exspa.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd90000 |
File size: | 67'072 bytes |
MD5 hash: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 13 |
Start time: | 19:22:48 |
Start date: | 05/04/2024 |
Path: | C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Exspa.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x950000 |
File size: | 67'072 bytes |
MD5 hash: | 2FB7FC0949AA14070E5E5D1EC37D48E7 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 7.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 47 |
Total number of Limit Nodes: | 2 |
Graph
Callgraph
Function 00A803A8 Relevance: 4.1, Strings: 3, Instructions: 356COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80397 Relevance: 4.1, Strings: 3, Instructions: 348COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80400 Relevance: 4.1, Strings: 3, Instructions: 324COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80438 Relevance: 4.1, Strings: 3, Instructions: 318COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80466 Relevance: 4.1, Strings: 3, Instructions: 314COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80494 Relevance: 4.1, Strings: 3, Instructions: 310COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A804F1 Relevance: 4.0, Strings: 3, Instructions: 299COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063A94F Relevance: 1.6, APIs: 1, Instructions: 98fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063AA5C Relevance: 1.6, APIs: 1, Instructions: 80COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063A986 Relevance: 1.6, APIs: 1, Instructions: 76fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063AC0E Relevance: 1.6, APIs: 1, Instructions: 70fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063A710 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063A2D2 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063AC2E Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063AE30 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063AA9E Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063AE52 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0063A2FE Relevance: 1.5, APIs: 1, Instructions: 35COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80B05 Relevance: .4, Instructions: 441COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80081 Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A80006 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BF0606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006323F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006323BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 20.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 9.4% |
Total number of Nodes: | 139 |
Total number of Limit Nodes: | 5 |
Graph
Function 04F51B0A Relevance: 5.6, Strings: 4, Instructions: 602COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050114B3 Relevance: 1.6, APIs: 1, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050116EF Relevance: 1.6, APIs: 1, Instructions: 64nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050114EA Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0501172A Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04F51510 Relevance: 1.6, APIs: 1, Instructions: 116COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050106DB Relevance: 1.6, APIs: 1, Instructions: 116COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04F51500 Relevance: 1.6, APIs: 1, Instructions: 110COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011910 Relevance: 1.6, APIs: 1, Instructions: 101windowCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010DF0 Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010CE8 Relevance: 1.6, APIs: 1, Instructions: 92timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050105E4 Relevance: 1.6, APIs: 1, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109ACF9 Relevance: 1.6, APIs: 1, Instructions: 86fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010E12 Relevance: 1.6, APIs: 1, Instructions: 84COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109A120 Relevance: 1.6, APIs: 1, Instructions: 83COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109ADF4 Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050100AE Relevance: 1.6, APIs: 1, Instructions: 77networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AF82 Relevance: 1.6, APIs: 1, Instructions: 77fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0501060A Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AD1E Relevance: 1.6, APIs: 1, Instructions: 76fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011BDB Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011AF7 Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011A1C Relevance: 1.6, APIs: 1, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AC1F Relevance: 1.6, APIs: 1, Instructions: 72fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011635 Relevance: 1.6, APIs: 1, Instructions: 67COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050107BA Relevance: 1.6, APIs: 1, Instructions: 67fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010FC2 Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 050100CE Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109A710 Relevance: 1.6, APIs: 1, Instructions: 66COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010D26 Relevance: 1.6, APIs: 1, Instructions: 64timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011348 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AEC4 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011B1A Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011BFE Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011A3E Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109B2D3 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AFAE Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0501045A Relevance: 1.6, APIs: 1, Instructions: 59COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109A2D2 Relevance: 1.6, APIs: 1, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0501136A Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AC56 Relevance: 1.6, APIs: 1, Instructions: 53fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AE36 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109B46F Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011666 Relevance: 1.5, APIs: 1, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010FF2 Relevance: 1.5, APIs: 1, Instructions: 49networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109AEF6 Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05011996 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109A172 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109B2FA Relevance: 1.5, APIs: 1, Instructions: 45COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05010486 Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109B49E Relevance: 1.5, APIs: 1, Instructions: 39COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0109A2FE Relevance: 1.5, APIs: 1, Instructions: 35COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01150814 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011507E4 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011505E0 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011507C4 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011508D0 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01150606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010923F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010923BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 10.5% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 014703A8 Relevance: 2.9, Strings: 2, Instructions: 356COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01470397 Relevance: 2.8, Strings: 2, Instructions: 350COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0115A710 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0115A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01470006 Relevance: .1, Instructions: 53COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011005E4 Relevance: .0, Instructions: 43COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01100606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011523F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 011523BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 10.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 016703A8 Relevance: 2.9, Strings: 2, Instructions: 356COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01670397 Relevance: 2.8, Strings: 2, Instructions: 350COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0108A710 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0108A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 016905E0 Relevance: .1, Instructions: 72COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01670015 Relevance: .0, Instructions: 43COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01690606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010823F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010823BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 13.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 055703A8 Relevance: 4.1, Strings: 3, Instructions: 356COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05570397 Relevance: 4.1, Strings: 3, Instructions: 355COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 016AA710 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 016AA74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0557008B Relevance: .1, Instructions: 149COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05570006 Relevance: .0, Instructions: 48COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01750606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 016A23F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 016A23BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 14.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 055703A8 Relevance: 4.1, Strings: 3, Instructions: 356COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05570397 Relevance: 4.1, Strings: 3, Instructions: 350COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0136A710 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0136A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0557008A Relevance: .2, Instructions: 150COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05570006 Relevance: .0, Instructions: 49COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 016505E1 Relevance: .0, Instructions: 43COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01650606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 013623F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 013623BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 10.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 012803A8 Relevance: 2.9, Strings: 2, Instructions: 356COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01280397 Relevance: 2.8, Strings: 2, Instructions: 348COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0106A710 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0106A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015105E3 Relevance: .0, Instructions: 44COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01280016 Relevance: .0, Instructions: 44COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 01510606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010623F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010623BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |