Windows
Analysis Report
CNWSFY59Z6S1D.JS
Overview
General Information
Detection
Score: | 60 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 1280 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\CNWSF Y59Z6S1D.J S" MD5: A47CBE969EA935BDD3AB568BB126BC80)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Houdini, WSHRAT | Houdini is a VBS-based RAT dating back to 2013. Past in the days, it used to be wrapped in an .exe but started being spamvertized or downloaded by other malware directly as .vbs in 2018. In 2019, WSHRAT appeared, a Javascript-based version of Houdini, recoded by the name of Kognito. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_WSHRAT | Yara detected WSHRAT | Joe Security | ||
JoeSecurity_WSHRAT | Yara detected WSHRAT | Joe Security | ||
JoeSecurity_WSHRAT | Yara detected WSHRAT | Joe Security |
System Summary |
---|
Source: | Author: frack113, Florian Roth: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: frack113: |
Source: | Author: Michael Haag: |
Click to jump to signature section
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior |
Source: | Initial sample: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Classification label: |
Source: | Key opened: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static file information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | Windows Management Instrumentation | 2 Scripting | 1 DLL Side-Loading | 1 DLL Side-Loading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | Boot or Logon Initialization Scripts | 1 Obfuscated Files or Information | LSASS Memory | 2 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 14 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
codeberg.org | 217.197.91.145 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
217.197.91.145 | codeberg.org | Germany | 29670 | IN-BERLIN-ASIndividualNetworkBerlineVDE | true |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1423162 |
Start date and time: | 2024-04-09 17:54:57 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | CNWSFY59Z6S1D.JS |
Detection: | MAL |
Classification: | mal60.troj.winJS@1/0@1/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: CNWSFY59Z6S1D.JS
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
217.197.91.145 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
codeberg.org | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
IN-BERLIN-ASIndividualNetworkBerlineVDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Agent Tesla, AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | SmokeLoader, Xehook Stealer | Browse |
| ||
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | Vidar | Browse |
| |
Get hash | malicious | SocGholish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Latrodectus | Browse |
| ||
Get hash | malicious | Latrodectus | Browse |
| ||
Get hash | malicious | SocGholish | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer, PureLog Stealer | Browse |
|
File type: | |
Entropy (8bit): | 3.268189195410624 |
TrID: | |
File name: | CNWSFY59Z6S1D.JS |
File size: | 4'681'079 bytes |
MD5: | 8db29e3dbaa512a1585c582d32fcb311 |
SHA1: | f4eed5b85a18556d8f37ad2467872deafcc4993b |
SHA256: | fbb264da43e2d947bb2cce148d7e4758277aefb6e60345715dcc11e43166918d |
SHA512: | 07d045ea3b637add8e68d53230f0940df9c87c86c9a7e49526199e71d67af4d15a181173af692cb65419082291c60760c58c93b41109f842684903787617b2ac |
SSDEEP: | 3072:PKq84wWFsEB0ZIxvfvtvq4Gh0YXSLSvq6HxppTUNOYIl1nhr0TRHEYX2vq6LMXPg:mf |
TLSH: | 942614EA47C6D80369CC26936F86BFF50129B16756FC32C3A255378D09E85A3C5E1CCA |
File Content Preview: | try{var _0x31ed=["\x64\x6D\x46\x79\x49\x48\x6C\x69\x62\x57\x77\x37\x7B\x31\x7D\x51\x70\x32\x59\x58\x49\x67\x65\x57\x4A\x74\x62\x7B\x31\x7D\x73\x4E\x43\x6E\x5A\x68\x63\x69\x7B\x30\x7D\x7B\x32\x7D\x56\x6D\x67\x6B\x58\x32\x4A\x72\x49\x7B\x31\x7D\x30\x67\x57\ |
Icon Hash: | 68d69b8bb6aa9a86 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 9, 2024 17:55:50.046298027 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.046339989 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.047270060 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.076137066 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.076152086 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.440869093 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.441000938 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.516237974 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.516277075 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.516673088 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.520246983 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.520246983 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.564238071 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.799292088 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.799367905 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.799386978 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.799465895 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:50.799484968 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.799545050 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.804084063 CEST | 49699 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:50.804099083 CEST | 443 | 49699 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:52.796171904 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:52.796221972 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:52.796550989 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:52.796550989 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:52.796590090 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:53.149947882 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:53.150105000 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:53.150684118 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:53.150695086 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:53.150907993 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:53.150913954 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:53.505510092 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:53.505589008 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:53.505609035 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:53.505636930 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:53.506314993 CEST | 49700 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:53.506329060 CEST | 443 | 49700 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:55.538634062 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:55.538666010 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:55.538737059 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:55.539690018 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:55.539702892 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:55.905108929 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:55.905421019 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:55.905699015 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:55.905704975 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:55.905967951 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:55.905972004 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:56.258678913 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:56.258776903 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:56.258794069 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:56.258841038 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:56.258861065 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:56.259196043 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:56.259592056 CEST | 49701 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:56.259609938 CEST | 443 | 49701 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.280226946 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.280266047 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.280390978 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.281014919 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.281029940 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.638304949 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.638408899 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.638883114 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.638901949 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.639173031 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.639188051 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.991103888 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.991159916 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.991172075 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.991224051 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.991272926 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:55:58.991566896 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.991776943 CEST | 49702 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:55:58.991794109 CEST | 443 | 49702 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:00.988056898 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:00.988131046 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:00.988257885 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:00.988467932 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:00.988501072 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:01.342511892 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:01.342601061 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:01.343137026 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:01.343163967 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:01.343466043 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:01.343477964 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:01.695066929 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:01.695242882 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:01.695295095 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:01.695343971 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:01.696067095 CEST | 49703 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:01.696099043 CEST | 443 | 49703 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:03.718362093 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:03.718408108 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:03.718493938 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:03.718849897 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:03.718866110 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:04.073079109 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:04.073185921 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:05.349445105 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:05.349524975 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:05.349674940 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:05.349693060 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:05.525868893 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:05.525959015 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:05.526025057 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:05.526063919 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:05.526094913 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:05.526125908 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:05.526546001 CEST | 49704 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:05.526581049 CEST | 443 | 49704 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:07.546127081 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:07.546226978 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:07.546355009 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:07.546699047 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:07.546783924 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:07.909213066 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:07.909291983 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:07.910074949 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:07.910085917 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:07.910310984 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:07.910315990 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:08.261368036 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:08.261466026 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:08.261485100 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:08.261547089 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:08.261568069 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:08.261629105 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:08.262347937 CEST | 49711 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:08.262366056 CEST | 443 | 49711 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.287692070 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:10.287763119 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.287849903 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:10.288364887 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:10.288382053 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.651413918 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.651567936 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:10.652518034 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:10.652533054 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.652776003 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:10.652781963 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.999619961 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.999805927 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:10.999943018 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:11.000477076 CEST | 49712 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:11.000495911 CEST | 443 | 49712 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.013721943 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.013767004 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.013894081 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.014210939 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.014235020 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.367799997 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.368166924 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.368917942 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.368918896 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.368932962 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.368958950 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.719436884 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.719500065 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.719502926 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:13.719552040 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.720009089 CEST | 49713 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:13.720033884 CEST | 443 | 49713 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:15.716026068 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:15.716068029 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:15.716151953 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:15.716402054 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:15.716413021 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:16.077472925 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:16.077681065 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:16.078268051 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:16.078278065 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:16.078515053 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:16.078520060 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:16.427835941 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:16.427925110 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:16.428000927 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:16.428536892 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:16.428536892 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:16.727984905 CEST | 49714 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:16.728022099 CEST | 443 | 49714 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:18.419855118 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:18.419893980 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:18.420243025 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:18.420341969 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:18.420351028 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:18.785108089 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:18.785209894 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:18.785872936 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:18.785881042 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:18.786142111 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:18.786147118 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:19.133902073 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:19.134021044 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:19.134042025 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:19.134077072 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:19.134135008 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:19.134249926 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:19.134742022 CEST | 49715 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:19.134758949 CEST | 443 | 49715 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.162787914 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:21.162838936 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.162906885 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:21.163266897 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:21.163289070 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.526041985 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.526175976 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:21.526650906 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:21.526664972 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.526896000 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:21.526902914 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.874177933 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.874258041 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:21.874293089 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:21.874344110 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:23.146308899 CEST | 49716 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:23.146338940 CEST | 443 | 49716 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.157505035 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.157550097 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.157660961 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.157871008 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.157890081 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.521852970 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.521935940 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.522283077 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.522291899 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.522496939 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.522501945 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.869746923 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.869818926 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.869828939 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:25.869875908 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.870469093 CEST | 49717 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:25.870498896 CEST | 443 | 49717 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:27.873265982 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:27.873311043 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:27.873394966 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:27.873672009 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:27.873689890 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:28.226985931 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:28.227308035 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:28.227729082 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:28.227740049 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:28.227961063 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:28.227967978 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:28.581146955 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:28.581221104 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:28.581283092 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:28.581321955 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:28.581971884 CEST | 49718 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:28.581990957 CEST | 443 | 49718 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:30.577267885 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:30.577318907 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:30.577418089 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:30.577725887 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:30.577739000 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:30.931451082 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:30.931659937 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:30.932090998 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:30.932104111 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:30.932326078 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:30.932332993 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:31.282146931 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:31.282239914 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:31.282327890 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:31.282327890 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:31.282890081 CEST | 49719 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:31.282906055 CEST | 443 | 49719 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.281878948 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.281925917 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.282074928 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.282294035 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.282303095 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.635225058 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.635298967 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.635827065 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.635838032 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.636059999 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.636065006 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.991439104 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.991527081 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:33.991604090 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.991633892 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.992445946 CEST | 49720 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:33.992471933 CEST | 443 | 49720 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:35.998575926 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:35.998613119 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:35.998692989 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.006052971 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.006083012 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:36.361064911 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:36.361387014 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.366462946 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.366472960 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:36.366883039 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.366889000 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:36.712047100 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:36.712161064 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:36.712178946 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.712213993 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.712879896 CEST | 49721 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:36.712896109 CEST | 443 | 49721 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:38.735739946 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:38.735785007 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:38.735858917 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:38.736094952 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:38.736108065 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:39.093426943 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:39.093566895 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:39.094048023 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:39.094064951 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:39.094315052 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:39.094321966 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:39.442397118 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:39.442486048 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:39.442564011 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:39.442564964 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:40.993180037 CEST | 49722 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:40.993218899 CEST | 443 | 49722 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.001076937 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.001123905 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.001198053 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.001429081 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.001446962 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.359340906 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.359431982 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.359905958 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.359914064 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.360146999 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.360152006 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.708617926 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.708693027 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:43.708741903 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.708766937 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.709420919 CEST | 49723 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:43.709434032 CEST | 443 | 49723 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:45.710405111 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:45.710453033 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:45.710540056 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:45.710768938 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:45.710791111 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:46.064682007 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:46.064754963 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:46.065259933 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:46.065314054 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:46.065501928 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:46.065517902 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:46.415153980 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:46.415224075 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:46.415354013 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:46.415354013 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:46.415934086 CEST | 49727 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:46.415972948 CEST | 443 | 49727 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:48.428977013 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:48.429085016 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:48.429176092 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:48.429404020 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:48.429438114 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:48.783839941 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:48.784020901 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:48.785523891 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:48.785554886 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:48.785845041 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:48.785857916 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:49.132375956 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:49.132473946 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:49.132586002 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:49.133210897 CEST | 49728 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:49.133255005 CEST | 443 | 49728 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.122781992 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.122816086 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.122879982 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.123186111 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.123217106 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.477035999 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.477133989 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.477612972 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.477618933 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.477876902 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.477880955 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.827431917 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.827482939 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.827500105 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.827512026 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:51.827536106 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.827559948 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.829658031 CEST | 49729 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:51.829674006 CEST | 443 | 49729 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:53.841708899 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:53.841736078 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:53.841841936 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:53.842118025 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:53.842130899 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:54.195282936 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:54.195390940 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:54.195806026 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:54.195817947 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:54.196041107 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:54.196047068 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:54.544646978 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:54.544719934 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:54.544768095 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:54.544800997 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:54.545403004 CEST | 49730 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:54.545423031 CEST | 443 | 49730 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:56.692698002 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:56.692754030 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:56.692830086 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:56.693069935 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:56.693085909 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:57.051198006 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:57.052413940 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:58.575397015 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:58.575431108 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:58.575608015 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:58.575614929 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:58.752230883 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:58.752346992 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:56:58.752393007 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:58.752423048 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:58.752935886 CEST | 49731 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:56:58.752955914 CEST | 443 | 49731 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:00.750849009 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:00.750884056 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:00.751036882 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:00.751691103 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:00.751699924 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:01.112409115 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:01.112624884 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:01.113162994 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:01.113173962 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:01.113411903 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:01.113416910 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:01.458971024 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:01.459033966 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:01.459052086 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:01.459073067 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:01.459090948 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:01.459122896 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:01.459600925 CEST | 49732 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:01.459615946 CEST | 443 | 49732 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:03.452668905 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:03.452718019 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:03.452858925 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:03.453094006 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:03.453109026 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:03.816967964 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:03.817236900 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:03.817862988 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:03.817871094 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:03.818131924 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:03.818135977 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:04.166593075 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:04.166666031 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:04.166762114 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:04.166845083 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:04.167850018 CEST | 49733 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:04.167867899 CEST | 443 | 49733 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.170511007 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.170528889 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.170627117 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.170954943 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.170963049 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.525042057 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.525192976 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.525907993 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.525913000 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.526174068 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.526176929 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.874250889 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.874325037 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:06.874362946 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.874389887 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.875058889 CEST | 49734 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:06.875070095 CEST | 443 | 49734 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:08.873769999 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:08.873806000 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:08.873888969 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:08.874164104 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:08.874174118 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:09.227292061 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:09.227350950 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:09.227834940 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:09.227842093 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:09.228085041 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:09.228087902 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:09.592622995 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:09.592689991 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:09.592739105 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:09.592813969 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:09.593888998 CEST | 49735 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:09.593902111 CEST | 443 | 49735 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:11.592366934 CEST | 49736 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:11.592421055 CEST | 443 | 49736 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:57:11.592516899 CEST | 49736 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:11.592814922 CEST | 49736 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:57:11.592824936 CEST | 443 | 49736 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:59:14.119182110 CEST | 443 | 49736 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:59:14.121200085 CEST | 49737 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:59:14.121237040 CEST | 443 | 49737 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:59:14.121382952 CEST | 49737 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:59:14.121741056 CEST | 49737 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:59:14.121750116 CEST | 443 | 49737 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:59:17.902646065 CEST | 443 | 49737 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:59:17.903069019 CEST | 49737 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:59:17.909010887 CEST | 49737 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:59:17.909025908 CEST | 443 | 49737 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:59:17.910249949 CEST | 443 | 49737 | 217.197.91.145 | 192.168.2.7 |
Apr 9, 2024 17:59:17.910358906 CEST | 49737 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:59:17.910726070 CEST | 49737 | 443 | 192.168.2.7 | 217.197.91.145 |
Apr 9, 2024 17:59:17.956373930 CEST | 443 | 49737 | 217.197.91.145 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Apr 9, 2024 17:55:49.951590061 CEST | 53852 | 53 | 192.168.2.7 | 1.1.1.1 |
Apr 9, 2024 17:55:50.040527105 CEST | 53 | 53852 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Apr 9, 2024 17:55:49.951590061 CEST | 192.168.2.7 | 1.1.1.1 | 0xc5ae | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Apr 9, 2024 17:55:50.040527105 CEST | 1.1.1.1 | 192.168.2.7 | 0xc5ae | No error (0) | 217.197.91.145 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49699 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:55:50 UTC | 365 | OUT | |
2024-04-09 15:55:50 UTC | 639 | IN | |
2024-04-09 15:55:50 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49700 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:55:53 UTC | 466 | OUT | |
2024-04-09 15:55:53 UTC | 383 | IN | |
2024-04-09 15:55:53 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49701 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:55:55 UTC | 466 | OUT | |
2024-04-09 15:55:56 UTC | 383 | IN | |
2024-04-09 15:55:56 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49702 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:55:58 UTC | 466 | OUT | |
2024-04-09 15:55:58 UTC | 383 | IN | |
2024-04-09 15:55:58 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49703 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:01 UTC | 466 | OUT | |
2024-04-09 15:56:01 UTC | 383 | IN | |
2024-04-09 15:56:01 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49704 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:05 UTC | 466 | OUT | |
2024-04-09 15:56:05 UTC | 383 | IN | |
2024-04-09 15:56:05 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49711 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:07 UTC | 466 | OUT | |
2024-04-09 15:56:08 UTC | 383 | IN | |
2024-04-09 15:56:08 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49712 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:10 UTC | 466 | OUT | |
2024-04-09 15:56:10 UTC | 383 | IN | |
2024-04-09 15:56:10 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.7 | 49713 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:13 UTC | 466 | OUT | |
2024-04-09 15:56:13 UTC | 383 | IN | |
2024-04-09 15:56:13 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.7 | 49714 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:16 UTC | 466 | OUT | |
2024-04-09 15:56:16 UTC | 383 | IN | |
2024-04-09 15:56:16 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.7 | 49715 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:18 UTC | 466 | OUT | |
2024-04-09 15:56:19 UTC | 383 | IN | |
2024-04-09 15:56:19 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.7 | 49716 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:21 UTC | 466 | OUT | |
2024-04-09 15:56:21 UTC | 383 | IN | |
2024-04-09 15:56:21 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.7 | 49717 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:25 UTC | 466 | OUT | |
2024-04-09 15:56:25 UTC | 383 | IN | |
2024-04-09 15:56:25 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.7 | 49718 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:28 UTC | 466 | OUT | |
2024-04-09 15:56:28 UTC | 383 | IN | |
2024-04-09 15:56:28 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.7 | 49719 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:30 UTC | 466 | OUT | |
2024-04-09 15:56:31 UTC | 383 | IN | |
2024-04-09 15:56:31 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.7 | 49720 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:33 UTC | 466 | OUT | |
2024-04-09 15:56:33 UTC | 383 | IN | |
2024-04-09 15:56:33 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.7 | 49721 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:36 UTC | 466 | OUT | |
2024-04-09 15:56:36 UTC | 383 | IN | |
2024-04-09 15:56:36 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.7 | 49722 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:39 UTC | 466 | OUT | |
2024-04-09 15:56:39 UTC | 383 | IN | |
2024-04-09 15:56:39 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.7 | 49723 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:43 UTC | 466 | OUT | |
2024-04-09 15:56:43 UTC | 383 | IN | |
2024-04-09 15:56:43 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.7 | 49727 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:46 UTC | 466 | OUT | |
2024-04-09 15:56:46 UTC | 383 | IN | |
2024-04-09 15:56:46 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.7 | 49728 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:48 UTC | 466 | OUT | |
2024-04-09 15:56:49 UTC | 383 | IN | |
2024-04-09 15:56:49 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.7 | 49729 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:51 UTC | 466 | OUT | |
2024-04-09 15:56:51 UTC | 383 | IN | |
2024-04-09 15:56:51 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.7 | 49730 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:54 UTC | 466 | OUT | |
2024-04-09 15:56:54 UTC | 383 | IN | |
2024-04-09 15:56:54 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.7 | 49731 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:56:58 UTC | 466 | OUT | |
2024-04-09 15:56:58 UTC | 383 | IN | |
2024-04-09 15:56:58 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.7 | 49732 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:57:01 UTC | 466 | OUT | |
2024-04-09 15:57:01 UTC | 383 | IN | |
2024-04-09 15:57:01 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.7 | 49733 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:57:03 UTC | 466 | OUT | |
2024-04-09 15:57:04 UTC | 383 | IN | |
2024-04-09 15:57:04 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.7 | 49734 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:57:06 UTC | 466 | OUT | |
2024-04-09 15:57:06 UTC | 383 | IN | |
2024-04-09 15:57:06 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.7 | 49735 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:57:09 UTC | 466 | OUT | |
2024-04-09 15:57:09 UTC | 383 | IN | |
2024-04-09 15:57:09 UTC | 11 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.7 | 49737 | 217.197.91.145 | 443 | 1280 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-04-09 15:59:17 UTC | 466 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 1 |
Start time: | 17:55:47 |
Start date: | 09/04/2024 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7701c0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | try | |
1 | { | |
2 | var _0x31ed = [ "\x64\x6D\x46\x79\x49\x48\x6C\x69\x62\x57\x77\x37\x7B\x31\x7D\x51\x70\x32\x59\x58... | |
3 | var XPBNFBNTLNVW = _0x31ed[0]; | |
4 | var HAQAYZCQOWOB = _0x31ed[_0x31ed.length - 1]; | |
5 | var _0x42b2 = [ "\x70\x72\x6F\x63", "\x70\x72\x6F\x74\x6F\x74\x79\x70\x65", "\x43\x72\x65\x61\x74... | |
6 | var _0xc188 = [ "\x6F\x74\x79\x70\x65\x2E\x66\x34\x6D\x31\x6C\x59\x20\x3D\x20\x5B\x22\x52\x55\x4F... | |
7 | var _0x5223ca = _0x27ba; | |
8 | function _0x2a94() { | |
9 | var _0x45bb6b = [ '15397wWvFvL', '5rsFWvL', '2010rLhAFq', '3184566DtBCdj', '8959122xEaZji', '4361... | |
10 | _0x2a94 = | |
11 | function () { | |
12 | return _0x45bb6b; | |
13 | }; | |
14 | return _0x2a94 ( ); | |
15 | } | |
16 | ( function (_0x22ce22, _0x1cecae) { | |
17 | var _0x50ae4b = _0x27ba, _0x4fa990 = _0x22ce22 ( ); | |
18 | while (! ! [ ] ) | |
19 | { | |
20 | try | |
21 | { | |
22 | var _0x25de5e = parseInt ( _0x50ae4b ( 0x16a ) ) / 0x1 + - parseInt ( _0x50ae4b ( 0x162 ) ) / 0x2... | |
23 | if ( _0x25de5e === _0x1cecae ) | |
24 | break ; | |
25 | else | |
26 | _0x4fa990['push'] ( _0x4fa990['shift'] ( ) ); | |
27 | } | |
28 | catch ( _0x25a06e ) | |
29 | { | |
30 | _0x4fa990['push'] ( _0x4fa990['shift'] ( ) ); | |
31 | } | |
32 | } | |
33 | } ( _0x2a94, 0xd3311 ) ); | |
34 | function _0x27ba(_0x503518, _0x32f208) { | |
35 | var _0x2a9448 = _0x2a94 ( ); | |
36 | return _0x27ba = | |
37 | function (_0x27baa6, _0x25f382) { | |
38 | _0x27baa6 = _0x27baa6 - 0x160; | |
39 | var _0x4e895b = _0x2a9448[_0x27baa6]; | |
40 | return _0x4e895b; | |
41 | }, _0x27ba ( _0x503518, _0x32f208 ); | |
42 | } | |
43 | var OILDNHXDWJEM = _0x5223ca ( 0x168 ); | |
44 | var _0xa35c = [ "\x52\x55\x4F\x44\x49\x4D\x46\x5B\x34\x5D\x28\x29\x5B\x52\x55\x4F\x44\x49\x4D\x46... | |
45 | var _0x48de49 = _0x41bc; | |
46 | function _0x41bc(_0x179b12, _0x22e550) { | |
47 | var _0x300b64 = _0x300b ( ); | |
48 | return _0x41bc = | |
49 | function (_0x41bc85, _0x199135) { | |
50 | _0x41bc85 = _0x41bc85 - 0x122; | |
51 | var _0x14c109 = _0x300b64[_0x41bc85]; | |
52 | return _0x14c109; | |
53 | }, _0x41bc ( _0x179b12, _0x22e550 ); | |
54 | } | |
55 | ( function (_0x186ccf, _0x14c92f) { | |
56 | var _0x128bcc = _0x41bc, _0x19d679 = _0x186ccf ( ); | |
57 | while (! ! [ ] ) | |
58 | { | |
59 | try | |
60 | { | |
61 | var _0x58ea8c = - parseInt ( _0x128bcc ( 0x127 ) ) / 0x1 + - parseInt ( _0x128bcc ( 0x123 ) ) / 0... | |
62 | if ( _0x58ea8c === _0x14c92f ) | |
63 | break ; | |
64 | else | |
65 | _0x19d679['push'] ( _0x19d679['shift'] ( ) ); | |
66 | } | |
67 | catch ( _0x471eff ) | |
68 | { | |
69 | _0x19d679['push'] ( _0x19d679['shift'] ( ) ); | |
70 | } | |
71 | } | |
72 | } ( _0x300b, 0xa49f5 ) ); | |
73 | var FZSXYHNHBILD = _0x48de49 ( 0x128 ); | |
74 | function _0x300b() { | |
75 | var _0x18bf45 = [ '9QnJRTO', '6732340LQgKqL', '4024bTGBLP', '868744TSeEkN', '105YOeUnk', '156708e... | |
76 | _0x300b = | |
77 | function () { | |
78 | return _0x18bf45; | |
79 | }; | |
80 | return _0x300b ( ); | |
81 | } | |
82 | } | |
83 | catch ( error ) | |
84 | { | |
85 | } | |
86 | try | |
87 | { | |
88 | String[_0x42b2[0x1]][_0x42b2[0x0]] = eval; | |
89 | var RUODIMF = [ null, Array ( _0x42b2[0x2], _0x42b2[0x3], _0x42b2[0x4], _0x42b2[0x5], _0x42b2[0x6... | |
90 | eval ( _0x42b2[0xe] ); | |
91 | function _0xeae7() { | |
92 | var _0x5c72bc = [ '333BYNZxa', '2918125cqLQmp', '5773830eDgHxC', 'prototype', '404481ZPAYTK', '16... | |
93 | _0xeae7 = | |
94 | function () { | |
95 | return _0x5c72bc; | |
96 | }; | |
97 | return _0xeae7 ( ); | |
98 | } | |
99 | var _0x557ff3 = _0x228c; | |
100 | function _0x228c(_0x114bd0, _0x447caa) { | |
101 | var _0xeae707 = _0xeae7 ( ); | |
102 | return _0x228c = | |
103 | function (_0x228c03, _0x225376) { | |
104 | _0x228c03 = _0x228c03 - 0x65; | |
105 | var _0x3a638b = _0xeae707[_0x228c03]; | |
106 | return _0x3a638b; | |
107 | }, _0x228c ( _0x114bd0, _0x447caa ); | |
108 | } | |
109 | ( function (_0x2ab462, _0x1cc490) { | |
110 | var _0x26b9cb = _0x228c, _0x2cda2e = _0x2ab462 ( ); | |
111 | while (! ! [ ] ) | |
112 | { | |
113 | try | |
114 | { | |
115 | var _0x287683 = parseInt ( _0x26b9cb ( 0x68 ) ) / 0x1 + parseInt ( _0x26b9cb ( 0x6e ) ) / 0x2 * (... | |
116 | if ( _0x287683 === _0x1cc490 ) | |
117 | break ; | |
118 | else | |
119 | _0x2cda2e['push'] ( _0x2cda2e['shift'] ( ) ); | |
120 | } | |
121 | catch ( _0x50ca54 ) | |
122 | { | |
123 | _0x2cda2e['push'] ( _0x2cda2e['shift'] ( ) ); | |
124 | } | |
125 | } | |
126 | } ( _0xeae7, 0xa20aa ), | |
127 | Array[_0x557ff3 ( 0x67 ) ][_0x557ff3 ( 0x6a ) ] = | |
128 | function () { | |
129 | var _0x3d9dcb = _0x557ff3, _0xb18ed8 = arguments; | |
130 | return this[0x0][_0x3d9dcb ( 0x6d ) ] ( /{(\d+)}/g, | |
131 | function (_0x1c8168, _0xcb677b) { | |
132 | try | |
133 | { | |
134 | return _0xb18ed8[_0xcb677b]; | |
135 | } | |
136 | catch ( _0x49dc98 ) | |
137 | { | |
138 | return _0x1c8168; | |
139 | } | |
140 | } ) ; | |
141 | } ); | |
142 | if ( XPBNFBNTLNVW != null ) | |
143 | { | |
144 | Array.prototype.s0fStu = HAQAYZCQOWOB; | |
145 | } | |
146 | RUODIMF[0x2] = Array ( _0xa35c[0x0], _0xa35c[0x1], _0xa35c[0x2], null ); | |
147 | } | |
148 | catch ( error ) | |
149 | { | |
150 | } | |
151 | try | |
152 | { | |
153 | var _0x5a2c8a = _0x2a11; | |
154 | function _0x2a11(_0x599b12, _0x43f623) { | |
155 | var _0x414dec = _0x414d ( ); | |
156 | return _0x2a11 = | |
157 | function (_0x2a11fa, _0x10aa91) { | |
158 | _0x2a11fa = _0x2a11fa - 0x1b0; | |
159 | var _0x52bd4a = _0x414dec[_0x2a11fa]; | |
160 | return _0x52bd4a; | |
161 | }, _0x2a11 ( _0x599b12, _0x43f623 ); | |
162 | } | |
163 | function _0x414d() { | |
164 | var _0x48f6ac = [ '783006SogRkb', '5266omAMio', '388660bqNjNl', 'bst', '15YDpsBA', '2873766eTSsYO... | |
165 | _0x414d = | |
166 | function () { | |
167 | return _0x48f6ac; | |
168 | }; | |
169 | return _0x414d ( ); | |
170 | } | |
171 | ( function (_0xd04537, _0x5218e5) { | |
172 | var _0x2d3869 = _0x2a11, _0x5c8d55 = _0xd04537 ( ); | |
173 | while (! ! [ ] ) | |
174 | { | |
175 | try | |
176 | { | |
177 | var _0x21794c = - parseInt ( _0x2d3869 ( 0x1bd ) ) / 0x1 + parseInt ( _0x2d3869 ( 0x1b2 ) ) / 0x2... | |
178 | if ( _0x21794c === _0x5218e5 ) | |
179 | break ; | |
180 | else | |
181 | _0x5c8d55['push'] ( _0x5c8d55['shift'] ( ) ); | |
182 | } | |
183 | catch ( _0x13a5aa ) | |
184 | { | |
185 | _0x5c8d55['push'] ( _0x5c8d55['shift'] ( ) ); | |
186 | } | |
187 | } | |
188 | } ( _0x414d, 0xa906b ), RUODIMF[0x3] = Array ( WSH[RUODIMF[0x1][0x0]] ( [ _0x5a2c8a ( 0x1bc ) ][... | |
189 | function _0x59be() { | |
190 | var _0x3dc390 = [ '5WEyrjq', '8jvtQFi', '775aWsIwk', '684610ykLdgD', '12SPMuKd', '843801EpwIJA', ... | |
191 | _0x59be = | |
192 | function () { | |
193 | return _0x3dc390; | |
194 | }; | |
195 | return _0x59be ( ); | |
196 | } | |
197 | function _0x475c(_0x281eaa, _0x2e06b6) { | |
198 | var _0x59bec3 = _0x59be ( ); | |
199 | return _0x475c = | |
200 | function (_0x475cb4, _0x13754d) { | |
201 | _0x475cb4 = _0x475cb4 - 0x1d8; | |
202 | var _0xeecc6b = _0x59bec3[_0x475cb4]; | |
203 | return _0xeecc6b; | |
204 | }, _0x475c ( _0x281eaa, _0x2e06b6 ); | |
205 | } | |
206 | ( function (_0x3b8901, _0x5cf182) { | |
207 | var _0x4e5a93 = _0x475c, _0x47acf3 = _0x3b8901 ( ); | |
208 | while (! ! [ ] ) | |
209 | { | |
210 | try | |
211 | { | |
212 | var _0xade77a = parseInt ( _0x4e5a93 ( 0x1df ) ) / 0x1 * ( - parseInt ( _0x4e5a93 ( 0x1e7 ) ) / 0... | |
213 | if ( _0xade77a === _0x5cf182 ) | |
214 | break ; | |
215 | else | |
216 | _0x47acf3['push'] ( _0x47acf3['shift'] ( ) ); | |
217 | } | |
218 | catch ( _0x14327f ) | |
219 | { | |
220 | _0x47acf3['push'] ( _0x47acf3['shift'] ( ) ); | |
221 | } | |
222 | } | |
223 | } ( _0x59be, 0xba967 ), | |
224 | RUODIMF[0x4] = | |
225 | function () { | |
226 | return RUODIMF[0x3][0x0]; | |
227 | }, | |
228 | RUODIMF[0x5] = | |
229 | function () { | |
230 | var _0x3e58d3 = _0x475c; | |
231 | for ( var _0x8f5906 = 0x0 ; _0x8f5906 < RUODIMF[0x2][_0x3e58d3 ( 0x1d8 ) ] ; _0x8f5906 ++ ) | |
232 | { | |
233 | eval ( RUODIMF[0x2][_0x8f5906] ); | |
234 | } | |
235 | RUODIMF[0x2][0x0] = RUODIMF[0x2][0x0] + [ _0x3e58d3 ( 0x1e5 ) ][_0x3e58d3 ( 0x1d9 ) ] ( 'Te' ); | |
236 | } ); | |
237 | var _0x16e9 = []; | |
238 | eval ( [ _0xc188[4] ][_0xc188[3]] ( _0xc188[0], _0xc188[1], _0xc188[2] ) ); | |
239 | var exact = RUODIMF[3][1][_0xc188[6][_0xc188[5]][1]] = _0xc188[7]; | |
240 | eval ( _0xc188[8] ); | |
241 | eval ( [ _0xc188[13] ][_0xc188[3]] ( _0xc188[9], _0xc188[10], _0xc188[11], _0xc188[12] ) ); | |
242 | } | |
243 | catch ( error ) | |
244 | { | |
245 | } |