Windows
Analysis Report
upfilles.dll.dll
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- loaddll64.exe (PID: 6632 cmdline:
loaddll64. exe "C:\Us ers\user\D esktop\upf illes.dll. dll" MD5: 763455F9DCB24DFEECC2B9D9F8D46D52) - conhost.exe (PID: 6636 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 344 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\upf illes.dll. dll",#1 MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - rundll32.exe (PID: 5472 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\upfi lles.dll.d ll",#1 MD5: EF3179D498793BF4234F708D3BE28633) - regsvr32.exe (PID: 2180 cmdline:
regsvr32.e xe /i /s C :\Users\us er\Desktop \upfilles. dll.dll MD5: B0C2FA35D14A9FAD919E99D9D75E1B9E) - rundll32.exe (PID: 6296 cmdline:
rundll32.e xe C:\User s\user\Des ktop\upfil les.dll.dl l,DllCanUn loadNow MD5: EF3179D498793BF4234F708D3BE28633) - rundll32.exe (PID: 6324 cmdline:
rundll32.e xe C:\User s\user\Des ktop\upfil les.dll.dl l,DllGetCl assObject MD5: EF3179D498793BF4234F708D3BE28633) - WerFault.exe (PID: 6688 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 6 324 -s 344 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) - rundll32.exe (PID: 6516 cmdline:
rundll32.e xe C:\User s\user\Des ktop\upfil les.dll.dl l,DllInsta ll MD5: EF3179D498793BF4234F708D3BE28633) - WerFault.exe (PID: 3732 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 6 516 -s 344 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) - rundll32.exe (PID: 7264 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\upfi lles.dll.d ll",DllCan UnloadNow MD5: EF3179D498793BF4234F708D3BE28633) - rundll32.exe (PID: 7272 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\upfi lles.dll.d ll",DllGet ClassObjec t MD5: EF3179D498793BF4234F708D3BE28633) - WerFault.exe (PID: 7388 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 7 272 -s 344 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) - rundll32.exe (PID: 7288 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\upfi lles.dll.d ll",DllIns tall MD5: EF3179D498793BF4234F708D3BE28633) - WerFault.exe (PID: 7396 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 7 288 -s 344 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0) - rundll32.exe (PID: 7296 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\upfi lles.dll.d ll",DllUnr egisterSer ver MD5: EF3179D498793BF4234F708D3BE28633) - rundll32.exe (PID: 7320 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\upfi lles.dll.d ll",stow MD5: EF3179D498793BF4234F708D3BE28633) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5) - rundll32.exe (PID: 7856 cmdline:
"C:\Window s\system32 \rundll32. exe" "C:\U sers\user\ AppData\Ro aming\upfi lles.dll", stow MD5: EF3179D498793BF4234F708D3BE28633) - rundll32.exe (PID: 7984 cmdline:
"C:\Window s\system32 \rundll32. exe" "C:\U sers\user\ AppData\Ro aming\upfi lles.dll", stow MD5: EF3179D498793BF4234F708D3BE28633)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Brute Ratel C4, BruteRatel | Brute Ratel is a a Customized Command and Control Center for Red Team and Adversary SimulationSMB and TCP payloads provide functionality to write custom external C2 channels over legitimate websites such as Slack, Discord, Microsoft Teams and more.Built-in debugger to detect EDR userland hooks.Ability to keep memory artifacts hidden from EDRs and AV.Direct Windows SYS calls on the fly. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Unidentified 111 (Latrodectus), Latrodectus | First discovered in October 2023, BLACKWIDOW is a backdoor written in C that communicates over HTTP using RC4 encrypted requests. The malware has the capability to execute discovery commands, query information about the victim's machine, update itself, as well as download and execute an EXE, DLL, or shellcode. The malware is believed to have been developed by LUNAR SPIDER, the creators of IcedID (aka BokBot) Malware. | No Attribution |
{"C2 url": ["https://workspacin.cloud/live/", "https://illoskanawer.com/live/"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Latrodectus | Yara detected Latrodectus | Joe Security | ||
JoeSecurity_BruteRatel_1 | Yara detected BruteRatel | Joe Security | ||
JoeSecurity_BruteRatel_1 | Yara detected BruteRatel | Joe Security | ||
JoeSecurity_BruteRatel_1 | Yara detected BruteRatel | Joe Security | ||
JoeSecurity_BruteRatel_1 | Yara detected BruteRatel | Joe Security | ||
Click to see the 35 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Latrodectus | Yara detected Latrodectus | Joe Security | ||
JoeSecurity_Latrodectus | Yara detected Latrodectus | Joe Security | ||
JoeSecurity_Latrodectus | Yara detected Latrodectus | Joe Security | ||
JoeSecurity_Latrodectus | Yara detected Latrodectus | Joe Security | ||
JoeSecurity_Latrodectus | Yara detected Latrodectus | Joe Security | ||
Click to see the 4 entries |
System Summary |
---|
Source: | Author: elhoim, CD_ROM_: |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: |
Source: | Code function: | 6_2_00000001800192B8 | |
Source: | Code function: | 22_2_013A8BA8 | |
Source: | Code function: | 22_2_013A1A08 | |
Source: | Code function: | 22_2_013ADCE0 |
Networking |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 22_2_013A4004 |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 6_2_00000001800012B0 | |
Source: | Code function: | 6_2_0000000180001490 | |
Source: | Code function: | 6_2_0000000180001650 | |
Source: | Code function: | 18_3_000002921300D31C | |
Source: | Code function: | 18_3_000002921300D2AC | |
Source: | Code function: | 22_2_013A6814 | |
Source: | Code function: | 22_2_013A958C | |
Source: | Code function: | 22_2_013AA5CC | |
Source: | Code function: | 22_2_013A6728 | |
Source: | Code function: | 22_2_013A6618 | |
Source: | Code function: | 22_2_013A650C | |
Source: | Code function: | 22_2_013A6464 | |
Source: | Code function: | 22_2_013A67A0 |
Source: | Code function: | 6_2_000000018001C030 | |
Source: | Code function: | 6_2_000000018000A040 | |
Source: | Code function: | 6_2_00000001800190AC | |
Source: | Code function: | 6_2_0000000180001950 | |
Source: | Code function: | 6_2_000000018000B992 | |
Source: | Code function: | 6_2_00000001800131E0 | |
Source: | Code function: | 6_2_000000018000E200 | |
Source: | Code function: | 6_2_000000018000B210 | |
Source: | Code function: | 6_2_00000001800192B8 | |
Source: | Code function: | 6_2_0000000180020B88 | |
Source: | Code function: | 6_2_0000000180004C00 | |
Source: | Code function: | 6_2_0000000180013448 | |
Source: | Code function: | 6_2_000000018001C45C | |
Source: | Code function: | 6_2_000000018000C480 | |
Source: | Code function: | 6_2_000000018001EC90 | |
Source: | Code function: | 6_2_00000001800154A0 | |
Source: | Code function: | 6_2_0000000180023584 | |
Source: | Code function: | 6_2_00000001800176FC | |
Source: | Code function: | 18_2_00000292116E254C | |
Source: | Code function: | 18_2_000000026E7DFB4C | |
Source: | Code function: | 22_2_013A1030 |
Source: | Process created: |
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | Code function: | 18_3_00007DF4F0240000 |
Source: | Code function: | 6_2_000000018000AEB0 |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: |
Source: | Window detected: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Process created: |
Source: | Code function: | 6_2_000000018000613D | |
Source: | Code function: | 18_2_00000292116A5BB5 | |
Source: | Code function: | 18_2_000000026E7A31B5 |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Code function: | 6_2_0000000180023584 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: |
Source: | Code function: | 22_2_013A5904 | |
Source: | Code function: | 22_2_013A6984 | |
Source: | Code function: | 22_2_013ADDF8 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | API coverage: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | Code function: | 6_2_00000001800192B8 | |
Source: | Code function: | 22_2_013A8BA8 | |
Source: | Code function: | 22_2_013A1A08 | |
Source: | Code function: | 22_2_013ADCE0 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_18-2200 | ||
Source: | API call chain: | graph_22-3034 |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 6_2_00000001800118B8 |
Source: | Code function: | 6_2_000000018000D1F4 |
Source: | Code function: | 6_2_000000018001AC34 |
Source: | Code function: | 6_2_00000001800118B8 | |
Source: | Code function: | 6_2_000000018000E470 | |
Source: | Code function: | 6_2_000000018000D638 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 18_3_00007DF4F0240100 | |
Source: | Code function: | 18_2_000000026E7A1370 |
Source: | Thread created: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Thread register set: | Jump to behavior | ||
Source: | Thread register set: | Jump to behavior | ||
Source: | Thread register set: | Jump to behavior | ||
Source: | Thread register set: | Jump to behavior | ||
Source: | Thread register set: | Jump to behavior |
Source: | Thread register set: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 6_2_00000001800206B0 |
Source: | Code function: | 6_2_000000018000E5BC |
Source: | Code function: | 22_2_013A7318 |
Source: | Code function: | 22_2_013ADB28 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 912 Process Injection | 21 Virtualization/Sandbox Evasion | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 Registry Run Keys / Startup Folder | 912 Process Injection | LSASS Memory | 51 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 1 Obfuscated Files or Information | Security Account Manager | 21 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Regsvr32 | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | 114 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Rundll32 | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 DLL Side-Loading | Cached Domain Credentials | 1 Account Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 System Owner/User Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 2 File and Directory Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | Dynamic API Resolution | Network Sniffing | 13 System Information Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
16% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
workspacin.cloud | 104.21.16.155 | true | true | unknown | |
ae1f8849daaac4ee6b80681872ab88b9-1762121307.eu-central-1.elb.amazonaws.com | 3.69.236.35 | true | false | high | |
boriz400.com | 91.194.11.183 | true | true | unknown | |
altynbe.com | 138.124.183.215 | true | true | unknown | |
anikvan.com | 95.164.68.73 | true | true | unknown | |
ae97372e4f96e4d1299fbaeb7130b656-1584023256.us-east-1.elb.amazonaws.com | 54.175.181.104 | true | false | high | |
uncertain-kitten-gw.aws-euc1.cloud-ara.tyk.io | unknown | unknown | false | unknown | |
ridiculous-breakpoint-gw.aws-use1.cloud-ara.tyk.io | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| low | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
95.164.68.73 | anikvan.com | Gibraltar | 29632 | NASSIST-ASGI | true | |
138.124.183.215 | altynbe.com | Norway | 8983 | NOKIA-ASFI | true | |
104.21.16.155 | workspacin.cloud | United States | 13335 | CLOUDFLARENETUS | true | |
3.69.236.35 | ae1f8849daaac4ee6b80681872ab88b9-1762121307.eu-central-1.elb.amazonaws.com | United States | 16509 | AMAZON-02US | false | |
91.194.11.183 | boriz400.com | Russian Federation | 42994 | HQservCommunicationSolutionsIL | true | |
54.175.181.104 | ae97372e4f96e4d1299fbaeb7130b656-1584023256.us-east-1.elb.amazonaws.com | United States | 14618 | AMAZON-AESUS | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1439879 |
Start date and time: | 2024-05-11 00:03:08 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 28 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | upfilles.dll.dll (renamed file extension from exe to dll) |
Original Sample Name: | upfilles.dll.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winDLL@32/17@8/6 |
EGA Information: |
|
HCA Information: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.168.117.173, 20.189.173.20
- Excluded domains from analysis (whitelisted): onedsblobprdeus16.eastus.cloudapp.azure.com, ocsp.digicert.com, login.live.com, slscr.update.microsoft.com, blobcollector.events.data.trafficmanager.net, onedsblobprdwus15.westus.cloudapp.azure.com, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
- HTTPS proxy raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: upfilles.dll.dll
Time | Type | Description |
---|---|---|
00:04:08 | API Interceptor | |
00:04:08 | API Interceptor | |
00:04:11 | API Interceptor | |
00:04:51 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.21.16.155 | Get hash | malicious | Latrodectus | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
workspacin.cloud | Get hash | malicious | Latrodectus | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Gafgyt, Mirai | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HtmlDropper, HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
HQservCommunicationSolutionsIL | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | DanaBot, SmokeLoader | Browse |
| ||
Get hash | malicious | DarkGate | Browse |
| ||
Get hash | malicious | DarkGate | Browse |
| ||
Get hash | malicious | DarkGate | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | PrivateLoader, RisePro Stealer | Browse |
| ||
Get hash | malicious | PrivateLoader, RisePro Stealer | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
NOKIA-ASFI | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | NetSupport RAT | Browse |
| ||
Get hash | malicious | NetSupport RAT | Browse |
| ||
Get hash | malicious | NetSupport RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
NASSIST-ASGI | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | NetSupport RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
a0e9f5d64349fb13191bc781f81f42e1 | Get hash | malicious | VMdetect | Browse |
| |
Get hash | malicious | PrivateLoader, RisePro Stealer | Browse |
| ||
Get hash | malicious | PrivateLoader, RisePro Stealer | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | PrivateLoader, RisePro Stealer | Browse |
| ||
Get hash | malicious | PrivateLoader, RisePro Stealer | Browse |
| ||
Get hash | malicious | PrivateLoader, VMdetect | Browse |
| ||
Get hash | malicious | DBatLoader | Browse |
| ||
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | PrivateLoader, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Latrodectus | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
|
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_upf_964e80f5d1a5f925558a7e6299462efecb949df_9db0ef65_6fb130ca-cac1-4736-bec2-e227247d8b1e\Report.wer
Download File
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.7695669651831538 |
Encrypted: | false |
SSDEEP: | 96:0SFi/iSyKyosj+4RvNxrfNrQXIDcQOc6ncECcw3l+XaXz+HbHgSQgJjZh88Wpoxf:3ciSyoA80wjIx8jbyzuiFeZ24lO83l |
MD5: | F38F1F5A2799280E9AE9ECAED3D4D7F2 |
SHA1: | 614B13F3576A06B0A5D66A28720AD52CD48F64F1 |
SHA-256: | 73EACA5144E5222EA3859908633BE224CDF2CD699D28056A5D123197108AFA1D |
SHA-512: | B9504BAE2E55AB063A7D732A66DBD0739F937C3A3F9B1ED05B2C9E54966B1D4A4FF1AF7BF0FA1B5BC023C7BFA404DDCCC9217463CBFCCB67275A9DBB3F848250 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_upf_964e80f5d1a5f925558a7e6299462efecb949df_9db0ef65_d9b8934c-437b-450d-af46-0185962b24b1\Report.wer
Download File
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.7695284270582192 |
Encrypted: | false |
SSDEEP: | 96:DgFPd/ifyKyOsj+4RvNxrfNrQXIDcQOc6ncECcw3l+XaXz+HbHgSQgJjZh88Wpo3:s11ifyOA80wjIx8jbyzuiFeZ24lO83D |
MD5: | 2A79D4F0CC409452333A8DDF84450AEF |
SHA1: | 512CBEAAAC2972AE331C435F33652DABEA99A541 |
SHA-256: | 3B527751CA5679B2B05D430B17ADDE2A98AFCC30216D6AA11E58AFF116A824B0 |
SHA-512: | 9B02987593193A773237874A8B64ED4910787AF41B8B8ABCCC5DBA27DF4A1CFE6DC316B2342075BCB51ADB9B0D7033C8AEE7CBCC8867DFD0860E46D5A3FFF0A6 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_upf_dc8a9dd96bb43aa654aa29aa9f464ac6a31131f_9db0ef65_7dc7f057-dc81-4d91-9caa-bd8701d223a3\Report.wer
Download File
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.7695293488830603 |
Encrypted: | false |
SSDEEP: | 96:CcxgFF3/iOyKyZsj+4RvNxrfKQXIDcQOc6ncETcw3CCXaXz+HbHgSQgJjZh88Wp8:FgviOyZK0wjpFjbyzuiFeZ24lO83 |
MD5: | 02C2AE579A388FFA4C5C6A5104F49832 |
SHA1: | 0C660AE3539AE95EDF65C53088E9DA7EB5DFFEC9 |
SHA-256: | C313D051688A264AD7778F15CEC6ECB0D2FA908EA92D9134E25ED80B3B43C826 |
SHA-512: | A0A17281B979ACB45169A5C79673EC67EEC58F73B21E9D325CE34BD1630D7DBF459BF7AA4DCCE803D8D4842130BCD62AEE4F3822E8A75FA2770905BD285D0830 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_upf_dc8a9dd96bb43aa654aa29aa9f464ac6a31131f_9db0ef65_8641b0ad-46f6-452c-a496-10d58d4ec871\Report.wer
Download File
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.7695999953173611 |
Encrypted: | false |
SSDEEP: | 96:TEF1ks0/idyKygsj+4RvNxrfKQXIDcQOc6ncETcw3CCXaXz+HbHgSQgJjZh88Wp8:o3CidygK0wjpFjbyzuiFeZ24lO83 |
MD5: | F9DA4317B3745718F8A31BB61F06A4F4 |
SHA1: | 9BD89B72FF6CD9493B7343C4A720B403B54D0439 |
SHA-256: | 072151E64254174294A716437E4F986EC8336BAC545EBEA5D71EC5A481A00DBD |
SHA-512: | D2E3D37FAB0EB27FDEAA9A17C253B5D225EA96CD53D898A9F7A8A829D2D6B887E0139387DF6CDA03D85A7E2E8595025E08032A65822C12B65E124144B35837AC |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66070 |
Entropy (8bit): | 1.5462375465383378 |
Encrypted: | false |
SSDEEP: | 96:5u8hjNE3e2neSVUa52sl4GbfhHoi7M9UUACGcKutR1ZfE0FXtpqgJbqStCSqjWIF:XhjNi2OM+UAtq1ZfNTqgwStCS9ngz |
MD5: | 677694119DA44E5FEC7BF1C1317E830B |
SHA1: | 4FEB41E3E2792D4305F3FD66F5EE17E8BFFDA32D |
SHA-256: | 13C9DE6CF736408ECF3F5D8B186442A3381B005B307FDBD5DCEB114A627866FB |
SHA-512: | 000B790E53523A6DFE23A290EFD228BFF0E399927D925B880663ED99F0F3E07957C357E346C4976419B62BC34EC43367BE19E3CA39663B65BD3A6E16CDCE2824 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8534 |
Entropy (8bit): | 3.6939797702013397 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJqdgkmE6Yo8N4LgmfWP3pry89bU66Wf088m:R6lXJqakmE6YLegmfWPRU6DfR |
MD5: | 80B9B0AFA9ABA69B9A78557C448086C5 |
SHA1: | B99101A8A598F674B85334D5F8A0609AC22631E6 |
SHA-256: | 9968C12422E570B5EE4916B7EDF4BC0240E72DE23F62EF10630EC4B1E51814FF |
SHA-512: | 8D2CBE94CDDBA9C7F4FDD42B91E690533542BB23B8DD38FD258D3CC44585D6C07E12DA68A06CC179B1B8C7D8C3A8F400316A4787D58FB980DD530F34F2BAB469 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4777 |
Entropy (8bit): | 4.477202967569579 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zssJg771I99aWpW8VY+Ym8M4JCNCF0laFtyq85mQCy8ptSTSLd:uIjfqI7+b7VeJilCGT8poOLd |
MD5: | 5D367A225C41966DC6550185A90DAE6F |
SHA1: | 101CC4DF6477453EA9552B5AD0EE1273F1599AEA |
SHA-256: | E6997AC198F3DBE27F9915E0C4A3CC5E65654C6536885480C9BC6EF40290C190 |
SHA-512: | EDF7487656C3685EFE40BEAB794203DDBF95DD49E14CA56E27EAC8BD88B5CCE0BFF9C5555D329990288C05738F40CF731B5EE9D15DB3800A90DCA5F80C5D46F8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 58190 |
Entropy (8bit): | 1.605256614606473 |
Encrypted: | false |
SSDEEP: | 192:0VrYrCpCzQOMAsu+Qiqwxay+QsK0QRAQh:2E1TpoQi1aZQsK/Rp |
MD5: | CAAA37C00D8ECF6FA5FC4FA2A30BD2FA |
SHA1: | 2F9D061ED037ECE51B72AC937A99813073410435 |
SHA-256: | ECA00EFCB890B105FA3A548999F1E7A161FD7BDB5ED7B1F2FF2240DF570C41E2 |
SHA-512: | 9432BA4BCEB6E8A6D56DB1CBD256C7A1C3835413B22B4CEC7A7D8D7FACC8A85CF7E981CDC802E9A7001EB67285401042ED97471A5617B1D8BC220A145DD928C2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8534 |
Entropy (8bit): | 3.6966319113948383 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJRBAmS6YojN4LgmfWfiwsprRC89br4Wf9vZm:R6lXJXAmS6YEegmfWqP7rxfi |
MD5: | B607A2EB5584FD30993D12ABB2C4DF8A |
SHA1: | F2E1E2CE69FB5F3AB9850FF3A56668B6DFAE0AFF |
SHA-256: | DC1BDEED634E5907DFD137282558057ED000A00CD7BABC1ABC665D6B47410064 |
SHA-512: | 249030B4D7B167C51DA04101F483BFE2D977EDE4D0DBAF6E45720002D56785033391999DCBE0591289B8DE51E15D1C1ADBCE641A4472471D0A4B869CED69DDAD |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4777 |
Entropy (8bit): | 4.480227848947886 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zssJg771I99aWpW8VYsYm8M4JCNCF0saFmjyq85mQCrAptSTSDd:uIjfqI7+b7VEJi8jGfpoODd |
MD5: | 76611ED68AE98A3C1C5418DA42AD9839 |
SHA1: | E56614DC31056975565348CCA2BC464DC61B1657 |
SHA-256: | 1E7C757B8CED61BB0960A6FD8EE447BE3D82DF516B6DBF0CD4E9DD3CD465F897 |
SHA-512: | 1852341A694CC87F021633950EA49ECE0FDC5D470769097BE801C9F5F525F77E075FF0F4FC9BAE3266E303161AB520D0DEFF756C4B6DF3F6CF50F20AD73A052C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57494 |
Entropy (8bit): | 1.6234250646337964 |
Encrypted: | false |
SSDEEP: | 192:duYrC6W3OMlUsn9pHz+bF7frc/wHGpzp/iaBReJd5U6:rhZgV9lxXpzp/9jePL |
MD5: | 66F2A3C376DA0D558312FF6110D838C3 |
SHA1: | 834B317025A81AA5E7F00DF4430D56F7D760645B |
SHA-256: | 562F917C37C8D1E62F2E934483DEF3B9032D3EDBDE40154FD19E1CEA1BE2BAF2 |
SHA-512: | 58CC96682B33937C6CBB1E4CA8C0F7A07A37CD327DF704A9149CEAD1272E8F4C2539691B2C8FA46B75BB017353F11C02BD129EFE4159EE3081DF67D534CB974C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8522 |
Entropy (8bit): | 3.6962697567258553 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJtabmV6Y7pGgmfWP3prM89b+rWfxKm:R6lXJwbmV6YFGgmfWPT+6fd |
MD5: | B71FE5E91F46A2F6E80793B28555315E |
SHA1: | 52F0EE991F743BEA0995768C5AA075635A979098 |
SHA-256: | 7F8F6E795A696CA77E094A9664C2A6B795FFB3C2E9A5A6AEF1ED303C408F7EA0 |
SHA-512: | 5CE960EE43F0BD8BEE75A7688B62FD8BD51F4CE59AF84251C28867D7FD5E54FF5E03D2D159A5C36D8B04415FB04CF4EA130D1036D1D8DC564B5B2F961FFE0203 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4777 |
Entropy (8bit): | 4.478653683433715 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zssJg771I99aWpW8VYpYm8M4JCNCF0laFniyq85mQCypptSTS6d:uIjfqI7+b7V1JilVGTppoO6d |
MD5: | DA7D9A451274291EFD3755DC8FC3A141 |
SHA1: | 51E42DA26BBC94435F94EFDBDF8A242CC744E57C |
SHA-256: | 821799E5797BB8E3BCB45C123C170C09004DB0C21BB4FC46A6F6A99DE66FFC12 |
SHA-512: | 1AADD5F0D59B95756B48DFE2F6F95D358774409C5E209449411050C86A5F3990AE52D7AA1BBDD93063D712B6CB0DC84BE371833813004423128DF6949663B53A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 54894 |
Entropy (8bit): | 1.6839237359198767 |
Encrypted: | false |
SSDEEP: | 96:59S8veE3+XuQRawUKUCGsV3bBvgoi7MxpnZ0mK1NX7RT9bCmYhJbqmpx5OqWRW/F:diYrCrOMzuJXeDwwx5OLIH9EyXh |
MD5: | A837E0375D7983509A56860346CFCC15 |
SHA1: | F75FAE2A056C6FEF8D8F1D700F3412213DFFFB2D |
SHA-256: | 205CD9270682DC17A83E8D40610371F3ED964DD319E67BDBA4BE1780DF36D02F |
SHA-512: | DAD398EB6A465DF561E9F4A51FD2D414C84CFFB7F34BC06FEE2515B88EDCAC48978359ADA324F8A441AE9304221089DF081651A0CC5B770D121A04ED586B5A4A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8522 |
Entropy (8bit): | 3.6958245523678235 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJoigmd6Y7GGgmfWfiwsprH89b+vWfuKm:R6lXJdgmd6Y6GgmfWq2+ef6 |
MD5: | 57975B44072D1C9B3E80DB2266217745 |
SHA1: | A9CF9831C70448BFE57EB598D192F042A2AE3A6D |
SHA-256: | 415AD9CE27C4A61A389B2D2AE85DF89BB06FEFD9971BDB3399CAE445E58B8910 |
SHA-512: | 93854E117CDB0F89602B01AA667CE2E15D7607242C6EC26A4B7060F5FCB7EB905ADB72A73E979F8B35E01DA8F21F8CEE3A99D7FA40DD04ABBBD3428F6F83C212 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4777 |
Entropy (8bit): | 4.481691067176541 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zssJg771I99aWpW8VYSYm8M4JCNCF0saFBwtjyq85mQCrdptSTSNd:uIjfqI7+b7VCJiP0GqpoONd |
MD5: | 243DA7FD47223239375D054C23BDE13D |
SHA1: | 01345C28EFD562EEDE44945D9F8B54A30951ABC4 |
SHA-256: | CF4636B318E7DCECACDC72437D290E86C0501BCA90B77EE7585C1C837614D3D3 |
SHA-512: | 9BCE637D0F2AA10F4FD3BE688AFC8B97DC87CD20E03157250D55EC6368C6E353BB80A712BA982C01CA00B082C593634FA65DC3295A1EF8F9DCAA3C69330CCD3F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.46640558354698 |
Encrypted: | false |
SSDEEP: | 6144:/IXfpi67eLPU9skLmb0b4zWSPKaJG8nAgejZMMhA2gX4WABl0uNcdwBCswSb9:wXD94zWlLZMM6YFHa+9 |
MD5: | B7B3B5CD7790EDF0686FF777BA5097D3 |
SHA1: | ED234CE4B519238F46F4AA9519B3C51AFB301F20 |
SHA-256: | 221475E4ACF30CBC675FA384CAE2C143B9C04EF7B913D8D65B0052080F31D095 |
SHA-512: | 2F5813E176688BB57E91FD992373740377CDE50F0EBF56BD906A17D6325F158525F85FA13581310839B2EB9219FD5E6F03A3DE3E3E9A32CF3DAAC2D1BAE26831 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.38766220411242 |
TrID: |
|
File name: | upfilles.dll.dll |
File size: | 520'704 bytes |
MD5: | ccb6d3cb020f56758622911ddd2f1fcb |
SHA1: | 4a013f752c2bf84ca37e418175e0d9b6f61f636d |
SHA256: | f4cb6b684ea097f867d406a978b3422bbf2ecfea39236bf3ab99340996b825de |
SHA512: | 6ed929967005eaa6407e273b53a1fedcb2b084d775bed17272fd05b1ce143dbf921ac201246dfbfdbe663c7351e44c12f162e6f03343548b69b5d4598bb3492e |
SSDEEP: | 12288:8XG3MpAOIQ1LjbJFqzqUtYP4VnRk62yoK2:SpAOfFJIq/Py8K2 |
TLSH: | 4AB4BE4A37A80CB6E867C17D88634705E3B27D610761C6DF1290536F9F3BBD2663AB12 |
File Content Preview: | MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........C.s.". .". .". .D.!.". .D.!o". .J.!.". .J.!.". .J.!.". tK.!.". .D.!.". .D.!.". .". q". tK.!.". tK.!.". tK.!.". tK? .". ."W .". |
Icon Hash: | 7ae282899bbab082 |
Entrypoint: | 0x18000e1c0 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x180000000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, DLL |
DLL Characteristics: | HIGH_ENTROPY_VA |
Time Stamp: | 0x5C24FE09 [Thu Dec 27 16:30:01 2018 UTC] |
TLS Callbacks: | 0x80020fe0, 0x1 |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 90ad3b5a283c3a333bb222c03419fb76 |
Signature Valid: | |
Signature Issuer: | |
Signature Validation Error: | |
Error Number: | |
Not Before, Not After | |
Subject Chain | |
Version: | |
Thumbprint MD5: | |
Thumbprint SHA-1: | |
Thumbprint SHA-256: | |
Serial: |
Instruction |
---|
dec eax |
mov dword ptr [esp+08h], ebx |
dec eax |
mov dword ptr [esp+10h], esi |
push edi |
dec eax |
sub esp, 20h |
dec ecx |
mov edi, eax |
mov ebx, edx |
dec eax |
mov esi, ecx |
cmp edx, 01h |
jne 00007F611CBAF4F7h |
call 00007F611CBAF8D0h |
dec esp |
mov eax, edi |
mov edx, ebx |
dec eax |
mov ecx, esi |
dec eax |
mov ebx, dword ptr [esp+30h] |
dec eax |
mov esi, dword ptr [esp+38h] |
dec eax |
add esp, 20h |
pop edi |
jmp 00007F611CBAF384h |
int3 |
int3 |
int3 |
dec eax |
mov dword ptr [esp+10h], ebx |
dec eax |
mov dword ptr [esp+18h], ebp |
push esi |
push edi |
inc ecx |
push esi |
dec eax |
sub esp, 10h |
xor ecx, ecx |
mov dword ptr [00029DFEh], 00000002h |
xor eax, eax |
mov dword ptr [00029DEEh], 00000001h |
cpuid |
inc esp |
mov edx, ecx |
inc esp |
mov ecx, edx |
xor ecx, 444D4163h |
xor edx, 69746E65h |
mov ebp, ebx |
inc ebp |
xor ebx, ebx |
xor ebp, 68747541h |
inc esp |
mov eax, ebx |
or ebp, edx |
inc esp |
mov esi, eax |
or ebp, ecx |
inc ecx |
xor ecx, 49656E69h |
inc ecx |
xor eax, 756E6547h |
inc ecx |
lea eax, dword ptr [ebx+01h] |
xor ecx, ecx |
inc ecx |
xor edx, 6C65746Eh |
cpuid |
inc ebp |
or eax, ecx |
mov dword ptr [esp], eax |
inc ebp |
or eax, edx |
mov dword ptr [esp+04h], ebx |
mov esi, ecx |
mov dword ptr [esp+08h], ecx |
mov edi, eax |
mov dword ptr [esp+00h], edx |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x36de0 | 0xbc | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x36e9c | 0x8c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x3e000 | 0x1238 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x3b000 | 0x22bc | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x3c400 | 0x3278 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x40000 | 0x8fc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x31570 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x316d0 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x315d0 | 0x100 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x25000 | 0x3d8 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x23a99 | 0x23c00 | 87bfc32636bf93aa5ba6a79278de1d82 | False | 0.5472779173951049 | data | 6.420263931637599 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x25000 | 0x12b20 | 0x12c00 | 0f7e92ec4b27ef7a718d78d4d512f916 | False | 0.4034114583333333 | OpenPGP Secret Key Version 3 | 4.778349716646358 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x38000 | 0x2b34 | 0x1600 | a4dd3c567a44787ef36b75c1461eadc7 | False | 0.189453125 | data | 3.77323134284555 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x3b000 | 0x22bc | 0x2400 | 4b6b0ab05d617b8443d04115ebcf4698 | False | 0.4678819444444444 | data | 5.261331885690949 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x3e000 | 0x1238 | 0x1400 | 262a27cc3c07916543c338d007e971a7 | False | 0.3376953125 | data | 4.197268760185116 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x40000 | 0x8fc | 0xa00 | 029935b97db1b1dda5ddd384d84aface | False | 0.52734375 | data | 5.178504761959821 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
hVr | 0x41000 | 0x43000 | 0x42e00 | b359e2ed16a1c00b78e0035c276c8cf4 | False | 0.9683703271028037 | data | 7.985612673503669 | IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
REGISTRY | 0x3e6c0 | 0xc | ASCII text, with CRLF line terminators | English | United States | 1.6666666666666667 |
REGISTRY | 0x3e598 | 0x125 | ASCII text, with CRLF line terminators | English | United States | 0.7747440273037542 |
REGISTRY | 0x3e6d0 | 0x1fc | ASCII text, with CRLF line terminators | English | United States | 0.5866141732283464 |
TYPELIB | 0x3e8d0 | 0x7b8 | data | English | United States | 0.31983805668016196 |
RT_STRING | 0x3f088 | 0x2c | data | English | United States | 0.5681818181818182 |
RT_VERSION | 0x3e200 | 0x398 | OpenPGP Public Key | English | United States | 0.45652173913043476 |
RT_MANIFEST | 0x3f0b8 | 0x17d | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.5931758530183727 |
DLL | Import |
---|---|
KERNEL32.dll | UnmapViewOfFile, FreeLibrary, GetModuleFileNameW, GetModuleHandleW, GetProcAddress, LoadLibraryExW, LoadResource, SizeofResource, FindResourceW, lstrcmpiW, MultiByteToWideChar, MapViewOfFile, EncodePointer, EnterCriticalSection, LeaveCriticalSection, GetThreadLocale, SetThreadLocale, CreateFileW, GetFileSizeEx, CreateFileMappingW, GetCurrentThreadId, GetCurrentProcessId, DeleteCriticalSection, InitializeCriticalSectionEx, GetLastError, RaiseException, DecodePointer, CloseHandle, CreateEventW, OpenEventA, CreateEventA, WaitForSingleObjectEx, ResetEvent, SetEvent, WriteConsoleW, GetConsoleMode, GetConsoleCP, WriteFile, LocalAlloc, SetLastError, LocalFree, IsDebuggerPresent, OutputDebugStringW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, GetStartupInfoW, QueryPerformanceCounter, GetSystemTimeAsFileTime, InitializeSListHead, RtlPcToFileHeader, RtlUnwindEx, InterlockedFlushSList, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, ExitProcess, GetModuleHandleExW, HeapFree, HeapAlloc, HeapSize, HeapReAlloc, GetStdHandle, GetFileType, FindClose, FindFirstFileExW, FindNextFileW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, LCMapStringW, GetProcessHeap, SetFilePointerEx, GetStringTypeW, SetStdHandle, FlushFileBuffers |
USER32.dll | CharNextW |
ADVAPI32.dll | RegQueryInfoKeyW, RegOpenKeyExW, RegEnumKeyExW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegCloseKey, RegSetValueExW |
ole32.dll | CoTaskMemRealloc, CoTaskMemFree, CoCreateInstance, StringFromGUID2, CoTaskMemAlloc |
OLEAUT32.dll | VarUI4FromStr, SysFreeString, SysAllocString, SysStringLen, LoadTypeLib, RegisterTypeLib, UnRegisterTypeLib |
ntdll.dll | NtRequestWaitReplyPort, NtConnectPort, NtClose, NtRequestPort, RtlCaptureContext, RtlLookupFunctionEntry, NtCreateSection, RtlVirtualUnwind, RtlNtStatusToDosError, RtlInitUnicodeString |
Name | Ordinal | Address |
---|---|---|
DllCanUnloadNow | 1 | 0x18000b1c0 |
DllGetClassObject | 2 | 0x18000b060 |
DllInstall | 3 | 0x18000b350 |
stow | 4 | 0x18000b1f0 |
DllUnregisterServer | 5 | 0x18000b330 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 11, 2024 00:04:12.876111984 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:12.876151085 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:12.876234055 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:12.884301901 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:12.884325027 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.100040913 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.100138903 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.150934935 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.150954962 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.151766062 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.151813984 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.153366089 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.196130991 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.836091995 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.836138010 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.836318970 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.836368084 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.836373091 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.836404085 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.836424112 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.836445093 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:13.836451054 CEST | 443 | 49745 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:04:13.836477041 CEST | 49745 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:04:14.160665989 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:14.160695076 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:14.160757065 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:14.161567926 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:14.161585093 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:14.349921942 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:14.349992037 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:14.633188009 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:14.633209944 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:14.633583069 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:14.633660078 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:14.633950949 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:14.680125952 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.302793026 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.302824020 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.302925110 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.302937031 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.302953005 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.303011894 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.303020000 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.303076029 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.423475027 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.423537016 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.423574924 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.423590899 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.423614025 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.423616886 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.423635960 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.423640013 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.423652887 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.423682928 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.423687935 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.423732996 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.544538021 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.544625044 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.544735909 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.544791937 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.545012951 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.545084953 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.545223951 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.545291901 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.545304060 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.545350075 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.665793896 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.665921926 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.665981054 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.666047096 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.666162968 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.666223049 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.787254095 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.787345886 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.787383080 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.787396908 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.787437916 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.787437916 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.787859917 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.787950039 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.788012028 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.788074017 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.788597107 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.788633108 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.788666964 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.788672924 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.788682938 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.788746119 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.908390045 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.908490896 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.908793926 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.908823967 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.908847094 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.908876896 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.908876896 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:15.908888102 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:15.908951044 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.029175997 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.029218912 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.029264927 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.029280901 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.029320002 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.029320002 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.029334068 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.029392958 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.029403925 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.029464960 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.156616926 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.156735897 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.156819105 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.156900883 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.156963110 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.157041073 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.157193899 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.157263994 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.281892061 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.282010078 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.282191992 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.282262087 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.282413960 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.282485008 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.282649994 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.282737970 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.401212931 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.401323080 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.401331902 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.401340961 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.401420116 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.401422977 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.401427984 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.401524067 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.401549101 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.401633024 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.402426004 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.402496099 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.402559042 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.402621984 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.402714014 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.402751923 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.402765989 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.402776003 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.402793884 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.402817011 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.524367094 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.524405956 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.524487019 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.524517059 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.524533033 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.524557114 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.524588108 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.524621964 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.524629116 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.524683952 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.524684906 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:16.524734020 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.581928968 CEST | 49750 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:16.581959963 CEST | 443 | 49750 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:18.800654888 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:18.800705910 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:18.800782919 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:18.801140070 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:18.801151991 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.006895065 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.006954908 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.010859013 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.010878086 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.011146069 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.011267900 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.011759043 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.052115917 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.605072975 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.605142117 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.605285883 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.605534077 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.605552912 CEST | 443 | 49753 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:19.605581999 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.605693102 CEST | 49753 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:19.713289022 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:19.713349104 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:19.713514090 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:19.713869095 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:19.713892937 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.069000959 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.069299936 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.072027922 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.072046995 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.072290897 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.072371006 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.072694063 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.120126009 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.584696054 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.584779978 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.584791899 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.584887028 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.584928036 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.584948063 CEST | 443 | 49754 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:20.584959030 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:20.585009098 CEST | 49754 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:25.662625074 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:25.662666082 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:25.662748098 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:25.662981987 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:25.662997007 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:26.007230997 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:26.007307053 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:26.007765055 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:26.007776022 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:26.009032011 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:26.009037018 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:26.566164970 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:26.566241980 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:26.566246986 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:26.566293001 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:26.566401958 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:26.566418886 CEST | 443 | 49755 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:26.566431046 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:26.566463947 CEST | 49755 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:28.600533009 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:28.600570917 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:28.600650072 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:28.600826979 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:28.600836039 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:29.295164108 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:29.295233011 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:29.296261072 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:29.296268940 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:29.298552036 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:29.298557997 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:29.488142014 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:29.488218069 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:29.488240004 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:29.488251925 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:29.488281965 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:29.488300085 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:29.488487959 CEST | 49756 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:29.488501072 CEST | 443 | 49756 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:31.538259029 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:31.538309097 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:31.538393974 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:31.539045095 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:31.539060116 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:31.718983889 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:31.719063044 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:31.733103991 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:31.733115911 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:31.734328032 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:31.734333038 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:32.381103039 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:32.381189108 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:32.381222010 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:32.381272078 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:32.381299019 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:32.381340027 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:32.435678959 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:32.435707092 CEST | 443 | 49757 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:04:32.435714960 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:32.435760975 CEST | 49757 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:04:35.620846033 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:35.620884895 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:35.620964050 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:35.621238947 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:35.621258020 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:35.974225044 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:35.974396944 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:35.977263927 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:35.977272034 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:35.977473974 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:35.977529049 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:35.977814913 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:36.024108887 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:36.536477089 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:36.536587954 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:36.536607027 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:36.536648989 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:36.536652088 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:36.536686897 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:36.536729097 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:36.536742926 CEST | 443 | 49758 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:36.536751032 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:36.536780119 CEST | 49758 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:41.689709902 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:41.689759970 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:41.689852953 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:41.690062046 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:41.690076113 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:42.034646988 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:42.034755945 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:42.035279036 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:42.035290003 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:42.036478996 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:42.036483049 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:42.521622896 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:42.521697998 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:42.521708965 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:42.521752119 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:42.521817923 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:42.521836042 CEST | 443 | 49759 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:42.521852016 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:42.521876097 CEST | 49759 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:47.553693056 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:47.553729057 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:47.553805113 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:47.554006100 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:47.554018021 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:47.910607100 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:47.910713911 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:47.911115885 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:47.911122084 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:47.912341118 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:47.912344933 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:48.498056889 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:48.498131037 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:48.498161077 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:48.498198986 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:48.498260975 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:48.498275042 CEST | 443 | 49760 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:48.498286009 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:48.498310089 CEST | 49760 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:49.553919077 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:49.553960085 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:49.554033995 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:49.554229021 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:49.554241896 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:49.905736923 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:49.905863047 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:50.011501074 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:50.011514902 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:50.012701035 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:50.012706041 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:50.426254034 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:50.426323891 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:50.426328897 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:50.426367998 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:50.426445007 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:50.426459074 CEST | 443 | 49761 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:04:50.426477909 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:50.426498890 CEST | 49761 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:04:54.459506989 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.459552050 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:54.459625959 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.459827900 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.459846973 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:54.659784079 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:54.659882069 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.660497904 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.660502911 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:54.661665916 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.661670923 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:54.849919081 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:54.849984884 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:54.849997044 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.850038052 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.850593090 CEST | 49762 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:04:54.850605965 CEST | 443 | 49762 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:04:59.896092892 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:59.896131992 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:04:59.896218061 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:59.896399975 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:04:59.896414995 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:00.251300097 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:00.251435995 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:00.251837969 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:00.251847029 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:00.253036022 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:00.253041983 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:00.749311924 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:00.749393940 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:00.749398947 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:00.749443054 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:00.749521017 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:00.749538898 CEST | 443 | 49764 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:00.749553919 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:00.749593973 CEST | 49764 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:02.818259001 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:02.818294048 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:02.818384886 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:02.818598986 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:02.818609953 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:03.171717882 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:03.171813011 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:03.172238111 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:03.172244072 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:03.173496962 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:03.173501968 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:03.512689114 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:03.512757063 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:03.512765884 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:03.512805939 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:03.513014078 CEST | 49765 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:03.513025999 CEST | 443 | 49765 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:08.611321926 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:08.611357927 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:08.611412048 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:08.611735106 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:08.611748934 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:08.827698946 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:08.827804089 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:09.337568045 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:09.337622881 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:09.338826895 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:09.338831902 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:10.082154989 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:10.082223892 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:10.082243919 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:10.082261086 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:10.082281113 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:10.082300901 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:10.082324028 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:10.082336903 CEST | 443 | 49766 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:10.082355022 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:10.082371950 CEST | 49766 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:11.117014885 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:11.117052078 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:11.117130041 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:11.117330074 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:11.117342949 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:11.471896887 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:11.472001076 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:11.472516060 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:11.472528934 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:11.473735094 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:11.473747969 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:12.055849075 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:12.055917025 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:12.055958033 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:12.055986881 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:12.056080103 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:12.056097984 CEST | 443 | 49767 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:12.056122065 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:12.056144953 CEST | 49767 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:13.099071980 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.099107981 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.099169016 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.099369049 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.099385977 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.452290058 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.452361107 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.458436012 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.458446026 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.459986925 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.459992886 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.904305935 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.904381037 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.904428959 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.904449940 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.904551029 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.904568911 CEST | 443 | 49768 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:13.904581070 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.904614925 CEST | 49768 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:13.956968069 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:13.957020998 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:13.957089901 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:13.957277060 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:13.957298994 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:14.308116913 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:14.308181047 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.308640003 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.308650017 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:14.309753895 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.309762001 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:14.828250885 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:14.828322887 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:14.828365088 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.828389883 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.829873085 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.829890013 CEST | 443 | 49769 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:14.829901934 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.829936028 CEST | 49769 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:14.867353916 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:14.867377043 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:14.867460966 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:14.867676973 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:14.867687941 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.047733068 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.047821045 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.048234940 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.048243999 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.049484015 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.049494982 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.726402998 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.726459980 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.726509094 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.726552010 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.726566076 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.726608992 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.726629972 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.726650000 CEST | 443 | 49770 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:15.726660967 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:15.726784945 CEST | 49770 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:20.773017883 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:20.773068905 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:20.773142099 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:20.773407936 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:20.773426056 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:21.129941940 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:21.130058050 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:21.130548000 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:21.130557060 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:21.131829977 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:21.131845951 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:21.474138975 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:21.474200010 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:21.474215984 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:21.474250078 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:21.474632025 CEST | 49771 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:21.474657059 CEST | 443 | 49771 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:27.092787981 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.092823982 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.092883110 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.094007969 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.094022036 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.277106047 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.277158022 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.277740955 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.277748108 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.279454947 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.279459953 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.819932938 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.820014000 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.820014000 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.820092916 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.820152044 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.820152044 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:27.820168972 CEST | 443 | 49772 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:27.820338011 CEST | 49772 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:32.883784056 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:32.883821964 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:32.883877993 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:32.884134054 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:32.884145021 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.064727068 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.064790010 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.065248966 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.065258026 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.067011118 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.067015886 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.599915028 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.599977016 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.600002050 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.600013971 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.600045919 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.600059986 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.600157022 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.600169897 CEST | 443 | 49773 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:33.600187063 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:33.600210905 CEST | 49773 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:34.655008078 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:34.655052900 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:34.656636953 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:34.656830072 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:34.656836033 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:34.837395906 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:34.837450027 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:34.837874889 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:34.837879896 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:34.839570045 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:34.839575052 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:35.373827934 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:35.373893976 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:35.373975992 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:35.373991966 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:35.374016047 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:35.374053955 CEST | 443 | 49774 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:35.374083042 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:35.374098063 CEST | 49774 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:39.430622101 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:39.430635929 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:39.430697918 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:39.430980921 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:39.430995941 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:39.610713959 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:39.610770941 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:39.611217976 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:39.611227036 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:39.612639904 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:39.612644911 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:40.281117916 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:40.281543016 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:40.281569004 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:40.281631947 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:40.281641006 CEST | 443 | 49775 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:40.281670094 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:40.281723976 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:40.283200026 CEST | 49775 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:41.462110043 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:41.462141037 CEST | 443 | 49776 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:41.462196112 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:41.462481976 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:41.462497950 CEST | 443 | 49776 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:41.807674885 CEST | 443 | 49776 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:41.807809114 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:41.809799910 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:41.809799910 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:41.809809923 CEST | 443 | 49776 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:41.809824944 CEST | 443 | 49776 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:42.254204988 CEST | 443 | 49776 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:42.254293919 CEST | 443 | 49776 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:42.254314899 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:42.254456997 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:42.254456997 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:42.254525900 CEST | 49776 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:44.207504034 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:44.207562923 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:44.207617044 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:44.208290100 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:44.208307028 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:44.397622108 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:44.397715092 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:45.038084030 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:45.038114071 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:45.038441896 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:45.038494110 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:45.039020061 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:45.080121040 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:45.319808960 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:45.319866896 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:45.319930077 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:45.320194960 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:45.320205927 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:45.677402973 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:45.677457094 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:45.677956104 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:45.677962065 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:45.679744959 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:45.679749012 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:46.170100927 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:46.170213938 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:46.170274973 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:46.170330048 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:46.170337915 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:46.170337915 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:46.170348883 CEST | 443 | 49778 | 95.164.68.73 | 192.168.2.4 |
May 11, 2024 00:05:46.170367956 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:46.170392990 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:46.170392990 CEST | 49778 | 443 | 192.168.2.4 | 95.164.68.73 |
May 11, 2024 00:05:48.314795017 CEST | 49779 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:05:48.314835072 CEST | 443 | 49779 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:05:48.316441059 CEST | 49779 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:05:48.320326090 CEST | 49779 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:05:48.320338964 CEST | 443 | 49779 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:05:48.520405054 CEST | 443 | 49779 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:05:48.520679951 CEST | 49779 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:05:48.521970987 CEST | 49779 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:05:48.521976948 CEST | 443 | 49779 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:05:48.522186995 CEST | 49779 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:05:48.522228956 CEST | 443 | 49779 | 54.175.181.104 | 192.168.2.4 |
May 11, 2024 00:05:48.522351027 CEST | 49779 | 443 | 192.168.2.4 | 54.175.181.104 |
May 11, 2024 00:05:51.678014994 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:51.678044081 CEST | 443 | 49780 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:51.678114891 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:51.678450108 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:51.678463936 CEST | 443 | 49780 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:52.026103020 CEST | 443 | 49780 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:52.026256084 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:52.026602983 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:52.026611090 CEST | 443 | 49780 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:52.028354883 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:52.028387070 CEST | 443 | 49780 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:52.028487921 CEST | 443 | 49780 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:05:52.028595924 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:52.028595924 CEST | 49780 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:05:53.082654953 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:53.082722902 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:53.082741022 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:53.082782984 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:53.082789898 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:53.082799911 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:53.082834959 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:53.083092928 CEST | 49777 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:53.083106995 CEST | 443 | 49777 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:53.187452078 CEST | 49781 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:53.187489033 CEST | 443 | 49781 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:53.187544107 CEST | 49781 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:53.187910080 CEST | 49781 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:53.187923908 CEST | 443 | 49781 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:53.371217012 CEST | 443 | 49781 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:53.371274948 CEST | 49781 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:53.371756077 CEST | 49781 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:53.371762037 CEST | 443 | 49781 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:53.373580933 CEST | 49781 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:53.373620987 CEST | 443 | 49781 | 138.124.183.215 | 192.168.2.4 |
May 11, 2024 00:05:53.373672962 CEST | 49781 | 443 | 192.168.2.4 | 138.124.183.215 |
May 11, 2024 00:05:54.587270975 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:54.587306976 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:54.590352058 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:54.590647936 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:54.590662003 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:54.773096085 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:54.773156881 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:54.773655891 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:54.773664951 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:54.775115967 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:05:54.775120974 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:05:57.462661982 CEST | 49783 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:57.462696075 CEST | 443 | 49783 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:57.462765932 CEST | 49783 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:57.463027954 CEST | 49783 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:57.463037968 CEST | 443 | 49783 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:57.675482988 CEST | 443 | 49783 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:57.675545931 CEST | 49783 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:57.676095963 CEST | 49783 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:57.676110029 CEST | 443 | 49783 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:57.677645922 CEST | 49783 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:05:57.677691936 CEST | 443 | 49783 | 91.194.11.183 | 192.168.2.4 |
May 11, 2024 00:05:57.677740097 CEST | 49783 | 443 | 192.168.2.4 | 91.194.11.183 |
May 11, 2024 00:06:01.100152969 CEST | 49784 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:06:01.100197077 CEST | 443 | 49784 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:06:01.100255013 CEST | 49784 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:06:01.100661993 CEST | 49784 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:06:01.100677013 CEST | 443 | 49784 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:06:01.455171108 CEST | 443 | 49784 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:06:01.455318928 CEST | 49784 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:06:02.959152937 CEST | 49784 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:06:02.959256887 CEST | 443 | 49784 | 3.69.236.35 | 192.168.2.4 |
May 11, 2024 00:06:02.959311962 CEST | 49784 | 443 | 192.168.2.4 | 3.69.236.35 |
May 11, 2024 00:06:11.854818106 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:06:11.854876041 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:06:11.854886055 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:06:11.854926109 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:06:11.854979038 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
May 11, 2024 00:06:11.855031967 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:06:11.855292082 CEST | 49782 | 443 | 192.168.2.4 | 104.21.16.155 |
May 11, 2024 00:06:11.855308056 CEST | 443 | 49782 | 104.21.16.155 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 11, 2024 00:04:12.655221939 CEST | 61036 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:04:12.871501923 CEST | 53 | 61036 | 1.1.1.1 | 192.168.2.4 |
May 11, 2024 00:04:13.858141899 CEST | 49810 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:04:14.159241915 CEST | 53 | 49810 | 1.1.1.1 | 192.168.2.4 |
May 11, 2024 00:04:18.686336040 CEST | 59418 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:04:18.799472094 CEST | 53 | 59418 | 1.1.1.1 | 192.168.2.4 |
May 11, 2024 00:04:19.608544111 CEST | 55062 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:04:19.711488962 CEST | 53 | 55062 | 1.1.1.1 | 192.168.2.4 |
May 11, 2024 00:04:35.505889893 CEST | 52484 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:04:35.619683981 CEST | 53 | 52484 | 1.1.1.1 | 192.168.2.4 |
May 11, 2024 00:05:43.047148943 CEST | 63227 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:05:43.138046026 CEST | 53 | 63227 | 1.1.1.1 | 192.168.2.4 |
May 11, 2024 00:06:00.977772951 CEST | 57865 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:06:01.079061031 CEST | 53 | 57865 | 1.1.1.1 | 192.168.2.4 |
May 11, 2024 00:06:08.749888897 CEST | 53677 | 53 | 192.168.2.4 | 1.1.1.1 |
May 11, 2024 00:06:08.864455938 CEST | 53 | 53677 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
May 11, 2024 00:04:12.655221939 CEST | 192.168.2.4 | 1.1.1.1 | 0x8441 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 11, 2024 00:04:13.858141899 CEST | 192.168.2.4 | 1.1.1.1 | 0x3148 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 11, 2024 00:04:18.686336040 CEST | 192.168.2.4 | 1.1.1.1 | 0xaee4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 11, 2024 00:04:19.608544111 CEST | 192.168.2.4 | 1.1.1.1 | 0x69b6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 11, 2024 00:04:35.505889893 CEST | 192.168.2.4 | 1.1.1.1 | 0x5f9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 11, 2024 00:05:43.047148943 CEST | 192.168.2.4 | 1.1.1.1 | 0xc6d8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 11, 2024 00:06:00.977772951 CEST | 192.168.2.4 | 1.1.1.1 | 0xc19b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 11, 2024 00:06:08.749888897 CEST | 192.168.2.4 | 1.1.1.1 | 0x7f64 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
May 11, 2024 00:04:12.871501923 CEST | 1.1.1.1 | 192.168.2.4 | 0x8441 | No error (0) | 91.194.11.183 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:14.159241915 CEST | 1.1.1.1 | 192.168.2.4 | 0x3148 | No error (0) | 138.124.183.215 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:18.799472094 CEST | 1.1.1.1 | 192.168.2.4 | 0xaee4 | No error (0) | pub-ingress-aws-use1.cloud-ara.tyk.io | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:04:18.799472094 CEST | 1.1.1.1 | 192.168.2.4 | 0xaee4 | No error (0) | ae97372e4f96e4d1299fbaeb7130b656-1584023256.us-east-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:04:18.799472094 CEST | 1.1.1.1 | 192.168.2.4 | 0xaee4 | No error (0) | 54.175.181.104 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:18.799472094 CEST | 1.1.1.1 | 192.168.2.4 | 0xaee4 | No error (0) | 35.172.8.165 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:18.799472094 CEST | 1.1.1.1 | 192.168.2.4 | 0xaee4 | No error (0) | 54.159.36.188 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:19.711488962 CEST | 1.1.1.1 | 192.168.2.4 | 0x69b6 | No error (0) | 95.164.68.73 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:35.619683981 CEST | 1.1.1.1 | 192.168.2.4 | 0x5f9f | No error (0) | pub-ingress-aws-euc1.cloud-ara.tyk.io | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:04:35.619683981 CEST | 1.1.1.1 | 192.168.2.4 | 0x5f9f | No error (0) | ae1f8849daaac4ee6b80681872ab88b9-1762121307.eu-central-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:04:35.619683981 CEST | 1.1.1.1 | 192.168.2.4 | 0x5f9f | No error (0) | 3.69.236.35 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:35.619683981 CEST | 1.1.1.1 | 192.168.2.4 | 0x5f9f | No error (0) | 3.72.42.242 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:04:35.619683981 CEST | 1.1.1.1 | 192.168.2.4 | 0x5f9f | No error (0) | 35.157.36.116 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:05:43.138046026 CEST | 1.1.1.1 | 192.168.2.4 | 0xc6d8 | No error (0) | 104.21.16.155 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:05:43.138046026 CEST | 1.1.1.1 | 192.168.2.4 | 0xc6d8 | No error (0) | 172.67.213.171 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:06:01.079061031 CEST | 1.1.1.1 | 192.168.2.4 | 0xc19b | No error (0) | pub-ingress-aws-euc1.cloud-ara.tyk.io | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:06:01.079061031 CEST | 1.1.1.1 | 192.168.2.4 | 0xc19b | No error (0) | ae1f8849daaac4ee6b80681872ab88b9-1762121307.eu-central-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:06:01.079061031 CEST | 1.1.1.1 | 192.168.2.4 | 0xc19b | No error (0) | 3.69.236.35 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:06:01.079061031 CEST | 1.1.1.1 | 192.168.2.4 | 0xc19b | No error (0) | 35.157.36.116 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:06:01.079061031 CEST | 1.1.1.1 | 192.168.2.4 | 0xc19b | No error (0) | 3.72.42.242 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:06:08.864455938 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f64 | No error (0) | pub-ingress-aws-use1.cloud-ara.tyk.io | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:06:08.864455938 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f64 | No error (0) | ae97372e4f96e4d1299fbaeb7130b656-1584023256.us-east-1.elb.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
May 11, 2024 00:06:08.864455938 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f64 | No error (0) | 54.175.181.104 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:06:08.864455938 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f64 | No error (0) | 54.159.36.188 | A (IP address) | IN (0x0001) | false | ||
May 11, 2024 00:06:08.864455938 CEST | 1.1.1.1 | 192.168.2.4 | 0x7f64 | No error (0) | 35.172.8.165 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49745 | 91.194.11.183 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:13 UTC | 246 | OUT | |
2024-05-10 22:04:13 UTC | 538 | OUT | |
2024-05-10 22:04:13 UTC | 151 | IN | |
2024-05-10 22:04:13 UTC | 52 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49750 | 138.124.183.215 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:14 UTC | 247 | OUT | |
2024-05-10 22:04:14 UTC | 154 | OUT | |
2024-05-10 22:04:15 UTC | 159 | IN | |
2024-05-10 22:04:15 UTC | 4022 | IN | |
2024-05-10 22:04:15 UTC | 4104 | IN | |
2024-05-10 22:04:15 UTC | 627 | IN | |
2024-05-10 22:04:15 UTC | 4104 | IN | |
2024-05-10 22:04:15 UTC | 4104 | IN | |
2024-05-10 22:04:15 UTC | 4104 | IN | |
2024-05-10 22:04:15 UTC | 688 | IN | |
2024-05-10 22:04:15 UTC | 4104 | IN | |
2024-05-10 22:04:15 UTC | 4104 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49753 | 54.175.181.104 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:19 UTC | 284 | OUT | |
2024-05-10 22:04:19 UTC | 656 | OUT | |
2024-05-10 22:04:19 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49754 | 95.164.68.73 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:20 UTC | 245 | OUT | |
2024-05-10 22:04:20 UTC | 444 | OUT | |
2024-05-10 22:04:20 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49755 | 95.164.68.73 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:26 UTC | 247 | OUT | |
2024-05-10 22:04:26 UTC | 154 | OUT | |
2024-05-10 22:04:26 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49756 | 54.175.181.104 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:29 UTC | 286 | OUT | |
2024-05-10 22:04:29 UTC | 154 | OUT | |
2024-05-10 22:04:29 UTC | 206 | IN | |
2024-05-10 22:04:29 UTC | 9 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49757 | 138.124.183.215 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:31 UTC | 245 | OUT | |
2024-05-10 22:04:31 UTC | 154 | OUT | |
2024-05-10 22:04:32 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49758 | 3.69.236.35 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:35 UTC | 279 | OUT | |
2024-05-10 22:04:35 UTC | 154 | OUT | |
2024-05-10 22:04:36 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49759 | 95.164.68.73 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:42 UTC | 247 | OUT | |
2024-05-10 22:04:42 UTC | 154 | OUT | |
2024-05-10 22:04:42 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49760 | 3.69.236.35 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:47 UTC | 279 | OUT | |
2024-05-10 22:04:47 UTC | 154 | OUT | |
2024-05-10 22:04:48 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49761 | 3.69.236.35 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:50 UTC | 279 | OUT | |
2024-05-10 22:04:50 UTC | 154 | OUT | |
2024-05-10 22:04:50 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49762 | 54.175.181.104 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:04:54 UTC | 286 | OUT | |
2024-05-10 22:04:54 UTC | 154 | OUT | |
2024-05-10 22:04:54 UTC | 206 | IN | |
2024-05-10 22:04:54 UTC | 9 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49764 | 95.164.68.73 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:00 UTC | 247 | OUT | |
2024-05-10 22:05:00 UTC | 154 | OUT | |
2024-05-10 22:05:00 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49765 | 3.69.236.35 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:03 UTC | 281 | OUT | |
2024-05-10 22:05:03 UTC | 154 | OUT | |
2024-05-10 22:05:03 UTC | 206 | IN | |
2024-05-10 22:05:03 UTC | 9 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49766 | 91.194.11.183 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:09 UTC | 248 | OUT | |
2024-05-10 22:05:09 UTC | 154 | OUT | |
2024-05-10 22:05:10 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49767 | 3.69.236.35 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:11 UTC | 279 | OUT | |
2024-05-10 22:05:11 UTC | 154 | OUT | |
2024-05-10 22:05:12 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49768 | 95.164.68.73 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:13 UTC | 247 | OUT | |
2024-05-10 22:05:13 UTC | 154 | OUT | |
2024-05-10 22:05:13 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49769 | 3.69.236.35 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:14 UTC | 279 | OUT | |
2024-05-10 22:05:14 UTC | 154 | OUT | |
2024-05-10 22:05:14 UTC | 253 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49770 | 138.124.183.215 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:15 UTC | 247 | OUT | |
2024-05-10 22:05:15 UTC | 154 | OUT | |
2024-05-10 22:05:15 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49771 | 3.69.236.35 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:21 UTC | 281 | OUT | |
2024-05-10 22:05:21 UTC | 154 | OUT | |
2024-05-10 22:05:21 UTC | 206 | IN | |
2024-05-10 22:05:21 UTC | 9 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49772 | 138.124.183.215 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:27 UTC | 247 | OUT | |
2024-05-10 22:05:27 UTC | 154 | OUT | |
2024-05-10 22:05:27 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49773 | 138.124.183.215 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:33 UTC | 245 | OUT | |
2024-05-10 22:05:33 UTC | 154 | OUT | |
2024-05-10 22:05:33 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49774 | 138.124.183.215 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:34 UTC | 247 | OUT | |
2024-05-10 22:05:34 UTC | 154 | OUT | |
2024-05-10 22:05:35 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49775 | 138.124.183.215 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:39 UTC | 245 | OUT | |
2024-05-10 22:05:39 UTC | 154 | OUT | |
2024-05-10 22:05:40 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49776 | 95.164.68.73 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:41 UTC | 247 | OUT | |
2024-05-10 22:05:41 UTC | 154 | OUT | |
2024-05-10 22:05:42 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49777 | 104.21.16.155 | 443 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:45 UTC | 229 | OUT | |
2024-05-10 22:05:45 UTC | 248 | OUT | |
2024-05-10 22:05:53 UTC | 570 | IN | |
2024-05-10 22:05:53 UTC | 26 | IN | |
2024-05-10 22:05:53 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49778 | 95.164.68.73 | 443 | 7320 | C:\Windows\System32\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:45 UTC | 245 | OUT | |
2024-05-10 22:05:45 UTC | 154 | OUT | |
2024-05-10 22:05:46 UTC | 150 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49782 | 104.21.16.155 | 443 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-05-10 22:05:54 UTC | 229 | OUT | |
2024-05-10 22:05:54 UTC | 180 | OUT | |
2024-05-10 22:06:11 UTC | 574 | IN | |
2024-05-10 22:06:11 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 00:03:58 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\loaddll64.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61d400000 |
File size: | 165'888 bytes |
MD5 hash: | 763455F9DCB24DFEECC2B9D9F8D46D52 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 1 |
Start time: | 00:03:59 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 00:03:59 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70e6c0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 00:03:59 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\regsvr32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64ee30000 |
File size: | 25'088 bytes |
MD5 hash: | B0C2FA35D14A9FAD919E99D9D75E1B9E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 00:03:59 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 00:03:59 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 00:04:02 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 00:04:02 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\WerFault.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67a3b0000 |
File size: | 570'736 bytes |
MD5 hash: | FD27D9F6D02763BDE32511B5DF7FF7A0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 00:04:05 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 00:04:05 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\WerFault.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67a3b0000 |
File size: | 570'736 bytes |
MD5 hash: | FD27D9F6D02763BDE32511B5DF7FF7A0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 00:04:08 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 00:04:08 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 15 |
Start time: | 00:04:08 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 16 |
Start time: | 00:04:08 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 00:04:08 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | false |
Target ID: | 20 |
Start time: | 00:04:08 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\WerFault.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67a3b0000 |
File size: | 570'736 bytes |
MD5 hash: | FD27D9F6D02763BDE32511B5DF7FF7A0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 21 |
Start time: | 00:04:08 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\WerFault.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff67a3b0000 |
File size: | 570'736 bytes |
MD5 hash: | FD27D9F6D02763BDE32511B5DF7FF7A0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 22 |
Start time: | 00:04:16 |
Start date: | 11/05/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | false |
Target ID: | 26 |
Start time: | 00:04:29 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 27 |
Start time: | 00:04:37 |
Start date: | 11/05/2024 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74e4b0000 |
File size: | 71'680 bytes |
MD5 hash: | EF3179D498793BF4234F708D3BE28633 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 1.2% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 225 |
Total number of Limit Nodes: | 13 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180018D1C Relevance: 1.5, APIs: 1, Instructions: 36memoryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018000B992 Relevance: 45.9, APIs: 19, Strings: 7, Instructions: 387registryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018001C45C Relevance: 24.0, APIs: 9, Strings: 4, Instructions: 1208COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018000C480 Relevance: 23.1, APIs: 12, Strings: 1, Instructions: 358threadCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180001950 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 262filethreadCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180004C00 Relevance: 16.9, APIs: 11, Instructions: 377stringCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800118B8 Relevance: 9.1, APIs: 6, Instructions: 83COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180001490 Relevance: 7.6, APIs: 5, Instructions: 105nativememoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800012B0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 127nativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018000D1F4 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 42COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800176FC Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 248COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800190AC Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 165COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180020B88 Relevance: 3.2, APIs: 2, Instructions: 232COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018000A040 Relevance: .2, Instructions: 156COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800206B0 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180005BC0 Relevance: 28.3, APIs: 12, Strings: 4, Instructions: 288memorystringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018000C110 Relevance: 23.0, APIs: 12, Strings: 1, Instructions: 231filethreadCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018000CA00 Relevance: 21.4, APIs: 2, Strings: 10, Instructions: 436COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180001E60 Relevance: 19.6, APIs: 2, Strings: 9, Instructions: 394COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180017F94 Relevance: 15.9, APIs: 1, Strings: 8, Instructions: 104COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180005590 Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 75libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180021160 Relevance: 10.8, APIs: 3, Strings: 3, Instructions: 282COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800215C0 Relevance: 10.8, APIs: 3, Strings: 3, Instructions: 282COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018000A640 Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 233COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800076B0 Relevance: 10.7, APIs: 3, Strings: 3, Instructions: 229COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180005AC0 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 77registrylibraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180020A3C Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180014DC4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 24libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800204A4 Relevance: 7.6, APIs: 5, Instructions: 56COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180012930 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 147COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180017B48 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 134COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180008970 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 123COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180008780 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 123COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180012B3C Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 171COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0000000180002900 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 118COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018001F38C Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 100fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018001AA90 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 50COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018001AA2C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 25COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018001A9D8 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000018001AB6C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000001800116DC Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 6.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 4.9% |
Total number of Nodes: | 245 |
Total number of Limit Nodes: | 22 |
Graph
Function 000000026E7A1370 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 62injectionsleepmemoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007DF4F0240100 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 214COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000002921300D2AC Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000002921300D31C Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00007DF4F02B0000 Relevance: 6.2, APIs: 4, Instructions: 179registryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 000000026E7A14C0 Relevance: 1.5, APIs: 1, Instructions: 7COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 000000026E7A1730 Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 115COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Execution Graph
Execution Coverage: | 10.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 5.6% |
Total number of Nodes: | 764 |
Total number of Limit Nodes: | 12 |
Graph
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A8BA8 Relevance: 4.6, APIs: 3, Instructions: 67COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A958C Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 18memorynativeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A6814 Relevance: 1.5, APIs: 1, Instructions: 13nativeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013AA5CC Relevance: 1.5, APIs: 1, Instructions: 11nativeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A40DC Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 122networkCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A30B0 Relevance: 7.6, APIs: 5, Instructions: 95COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A7134 Relevance: 6.0, APIs: 4, Instructions: 28processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A720C Relevance: 4.5, APIs: 3, Instructions: 38COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A52FC Relevance: 1.5, APIs: 1, Instructions: 17threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A1030 Relevance: 31.7, APIs: 17, Strings: 1, Instructions: 206pipefileprocessCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A6464 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 31nativefileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A650C Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 43nativefileCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A6618 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 43filenativeCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A1A08 Relevance: 6.1, APIs: 4, Instructions: 113fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013ADDF8 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013ADB28 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A36A4 Relevance: 12.2, APIs: 8, Instructions: 237COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A9BF4 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 100fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A75E8 Relevance: 7.6, APIs: 5, Instructions: 92networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 013A9A50 Relevance: 7.6, APIs: 5, Instructions: 79processCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|