Windows
Analysis Report
1iZH7aeO5F.exe
Overview
General Information
Sample name: | 1iZH7aeO5F.exerenamed because original name is a hash value |
Original sample name: | 320f34b9a9f567e773d2a526daf749fa.exe |
Analysis ID: | 1443977 |
MD5: | 320f34b9a9f567e773d2a526daf749fa |
SHA1: | 6a56b12f075f8daaf354ca44810bec29e756c941 |
SHA256: | 16e030019f05b734a973a0fafc0fb678d0eb2736cfd5159a7ea82ebf3c198170 |
Tags: | exenjratRAT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 1iZH7aeO5F.exe (PID: 5696 cmdline:
"C:\Users\ user\Deskt op\1iZH7ae O5F.exe" MD5: 320F34B9A9F567E773D2A526DAF749FA) - netsh.exe (PID: 728 cmdline:
netsh fire wall add a llowedprog ram "C:\Us ers\user\D esktop\1iZ H7aeO5F.ex e" "1iZH7a eO5F.exe" ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF) - conhost.exe (PID: 2724 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - netsh.exe (PID: 5344 cmdline:
netsh fire wall delet e allowedp rogram "C: \Users\use r\Desktop\ 1iZH7aeO5F .exe" MD5: 4E89A1A088BE715D6C946E55AB07C7DF) - conhost.exe (PID: 5444 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - netsh.exe (PID: 5284 cmdline:
netsh fire wall add a llowedprog ram "C:\Us ers\user\D esktop\1iZ H7aeO5F.ex e" "1iZH7a eO5F.exe" ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF) - conhost.exe (PID: 1876 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
NjRAT | RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored. |
{"Campaign ID": "HacKed", "Version": "0.7d", "Install Name": "ef4ab10333351fde29c0e75b008795bc", "Install Dir": "system", "Registry Value": "Software\\Microsoft\\Windows\\CurrentVersion\\Run", "Network Seprator": "|'|'|"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Njrat | detect njRAT in memory | JPCERT/CC Incident Response Group |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Njrat | detect njRAT in memory | JPCERT/CC Incident Response Group |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
Njrat | detect njRAT in memory | JPCERT/CC Incident Response Group |
| |
JoeSecurity_Njrat | Yara detected Njrat | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
CN_disclosed_20180208_c | Detects malware from disclosed CN malware set | Florian Roth |
| |
Njrat | detect njRAT in memory | JPCERT/CC Incident Response Group |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
System Summary |
---|
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Timestamp: | 05/19/24-13:58:30.141221 |
SID: | 2814856 |
Source Port: | 49743 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:24.873447 |
SID: | 2814856 |
Source Port: | 49741 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:37.401284 |
SID: | 2814856 |
Source Port: | 49745 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:27.517197 |
SID: | 2814856 |
Source Port: | 49742 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:40.953521 |
SID: | 2814856 |
Source Port: | 49746 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:43.869191 |
SID: | 2814856 |
Source Port: | 49747 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:01.293185 |
SID: | 2814856 |
Source Port: | 49704 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:03.600944 |
SID: | 2814856 |
Source Port: | 49705 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:22.261137 |
SID: | 2814856 |
Source Port: | 49740 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:55.620050 |
SID: | 2033132 |
Source Port: | 49731 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:52.818612 |
SID: | 2033132 |
Source Port: | 49730 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:32.733312 |
SID: | 2814856 |
Source Port: | 49744 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:21.177524 |
SID: | 2814856 |
Source Port: | 49759 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:19.605486 |
SID: | 2825564 |
Source Port: | 49739 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:19.811421 |
SID: | 2814856 |
Source Port: | 49753 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:22.393782 |
SID: | 2814856 |
Source Port: | 49754 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:58.732625 |
SID: | 2814856 |
Source Port: | 49732 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:04.716868 |
SID: | 2814856 |
Source Port: | 49734 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:12.889712 |
SID: | 2814856 |
Source Port: | 49752 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:48.841533 |
SID: | 2814856 |
Source Port: | 49756 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:55.673276 |
SID: | 2814856 |
Source Port: | 49731 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:07.280571 |
SID: | 2814856 |
Source Port: | 49735 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:00.265208 |
SID: | 2814856 |
Source Port: | 49750 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:03.906997 |
SID: | 2814856 |
Source Port: | 49757 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:11.073416 |
SID: | 2814856 |
Source Port: | 49758 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:14.849038 |
SID: | 2814856 |
Source Port: | 49714 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:17.710652 |
SID: | 2814856 |
Source Port: | 49716 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:52.868787 |
SID: | 2814856 |
Source Port: | 49730 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:09.905031 |
SID: | 2814856 |
Source Port: | 49736 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:19.605486 |
SID: | 2814860 |
Source Port: | 49739 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:10.297630 |
SID: | 2814856 |
Source Port: | 49751 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:13.052528 |
SID: | 2814856 |
Source Port: | 49737 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:27.299562 |
SID: | 2033132 |
Source Port: | 49720 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:30.702609 |
SID: | 2825564 |
Source Port: | 49721 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:24.819791 |
SID: | 2033132 |
Source Port: | 49741 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:22.209333 |
SID: | 2033132 |
Source Port: | 49740 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:37.333591 |
SID: | 2814856 |
Source Port: | 49755 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:01.588817 |
SID: | 2814856 |
Source Port: | 49733 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:09.310016 |
SID: | 2033132 |
Source Port: | 49707 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:49.912771 |
SID: | 2033132 |
Source Port: | 49728 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:06.277632 |
SID: | 2033132 |
Source Port: | 49706 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:12.109502 |
SID: | 2033132 |
Source Port: | 49708 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:53.202661 |
SID: | 2033132 |
Source Port: | 49749 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:03.547062 |
SID: | 2033132 |
Source Port: | 49705 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:44.237483 |
SID: | 2033132 |
Source Port: | 49726 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:47.102281 |
SID: | 2033132 |
Source Port: | 49727 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:48.599643 |
SID: | 2033132 |
Source Port: | 49748 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:22.622570 |
SID: | 2814860 |
Source Port: | 49754 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:27.466502 |
SID: | 2033132 |
Source Port: | 49742 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:23.369142 |
SID: | 2814856 |
Source Port: | 49719 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:30.687437 |
SID: | 2033132 |
Source Port: | 49721 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:37.885777 |
SID: | 2814856 |
Source Port: | 49760 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:01:03.033945 |
SID: | 2814856 |
Source Port: | 49761 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:20.532509 |
SID: | 2814856 |
Source Port: | 49718 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:30.091760 |
SID: | 2033132 |
Source Port: | 49743 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:33.272402 |
SID: | 2033132 |
Source Port: | 49722 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:36.010938 |
SID: | 2033132 |
Source Port: | 49723 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:19.573184 |
SID: | 2814856 |
Source Port: | 49739 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:32.682513 |
SID: | 2033132 |
Source Port: | 49744 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:38.789971 |
SID: | 2033132 |
Source Port: | 49724 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:41.511014 |
SID: | 2033132 |
Source Port: | 49725 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:01.287429 |
SID: | 2033132 |
Source Port: | 49704 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:37.347524 |
SID: | 2033132 |
Source Port: | 49745 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:43.807491 |
SID: | 2033132 |
Source Port: | 49747 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:40.901851 |
SID: | 2033132 |
Source Port: | 49746 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:33.320635 |
SID: | 2814856 |
Source Port: | 49722 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:30.693152 |
SID: | 2814856 |
Source Port: | 49721 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:36.065243 |
SID: | 2814856 |
Source Port: | 49723 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:01:02.978980 |
SID: | 2033132 |
Source Port: | 49761 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:27.352576 |
SID: | 2814856 |
Source Port: | 49720 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:38.799294 |
SID: | 2814856 |
Source Port: | 49724 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:41.523438 |
SID: | 2814856 |
Source Port: | 49725 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:47.112042 |
SID: | 2814856 |
Source Port: | 49727 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:44.293131 |
SID: | 2814856 |
Source Port: | 49726 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:37.831032 |
SID: | 2033132 |
Source Port: | 49760 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:12.837250 |
SID: | 2033132 |
Source Port: | 49752 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:00.214834 |
SID: | 2033132 |
Source Port: | 49750 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:22.622570 |
SID: | 2825564 |
Source Port: | 49754 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:10.247529 |
SID: | 2033132 |
Source Port: | 49751 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:21.171817 |
SID: | 2033132 |
Source Port: | 49759 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:19.518408 |
SID: | 2033132 |
Source Port: | 49739 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:20.476527 |
SID: | 2033132 |
Source Port: | 49718 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:17.487883 |
SID: | 2033132 |
Source Port: | 49738 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:13.046674 |
SID: | 2033132 |
Source Port: | 49737 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:11.022301 |
SID: | 2033132 |
Source Port: | 49758 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:17.698975 |
SID: | 2033132 |
Source Port: | 49716 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:23.312492 |
SID: | 2033132 |
Source Port: | 49719 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:30.702609 |
SID: | 2814860 |
Source Port: | 49721 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:19.755628 |
SID: | 2033132 |
Source Port: | 49753 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:12.130118 |
SID: | 2814856 |
Source Port: | 49708 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:58.681738 |
SID: | 2033132 |
Source Port: | 49732 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:01.531695 |
SID: | 2033132 |
Source Port: | 49733 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:53.253209 |
SID: | 2814856 |
Source Port: | 49749 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:22.388360 |
SID: | 2033132 |
Source Port: | 49754 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:06.329376 |
SID: | 2814856 |
Source Port: | 49706 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:09.320195 |
SID: | 2814856 |
Source Port: | 49707 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:37.282316 |
SID: | 2033132 |
Source Port: | 49755 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:49.965614 |
SID: | 2814856 |
Source Port: | 49728 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:07.229080 |
SID: | 2033132 |
Source Port: | 49735 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:59:48.789535 |
SID: | 2033132 |
Source Port: | 49756 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:57:14.793035 |
SID: | 2033132 |
Source Port: | 49714 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:04.686444 |
SID: | 2033132 |
Source Port: | 49734 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-13:58:09.853627 |
SID: | 2033132 |
Source Port: | 49736 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 05/19/24-14:00:03.901621 |
SID: | 2033132 |
Source Port: | 49757 |
Destination Port: | 13006 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Spreading |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_0187A186 |
Source: | DNS traffic detected: |
Source: | Window created: | Jump to behavior |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_062E076A | |
Source: | Code function: | 0_2_062E0739 |
Source: | Code function: | 0_2_05767347 | |
Source: | Code function: | 0_2_05764298 | |
Source: | Code function: | 0_2_05767780 | |
Source: | Code function: | 0_2_05764287 |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_062E05EE | |
Source: | Code function: | 0_2_062E05B7 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Registry key created or modified: | Jump to behavior |
Source: | Registry value created: | Jump to behavior |
Source: | Process created: |
Source: | Process created: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 11 Replication Through Removable Media | Windows Management Instrumentation | 12 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 1 Masquerading | OS Credential Dumping | 11 Security Software Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 2 Process Injection | 51 Disable or Modify Tools | LSASS Memory | 2 Process Discovery | Remote Desktop Protocol | 1 Clipboard Data | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 12 Registry Run Keys / Startup Folder | 31 Virtualization/Sandbox Evasion | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 1 Access Token Manipulation | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 1 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Process Injection | LSA Secrets | 1 Peripheral Device Discovery | SSH | Keylogging | 1 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 12 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
91% | ReversingLabs | ByteCode-MSIL.Backdoor.Bladabhindi | ||
71% | Virustotal | Browse | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML | |||
91% | ReversingLabs | ByteCode-MSIL.Backdoor.Bladabhindi | ||
71% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
13% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
6.tcp.eu.ngrok.io | 3.68.171.119 | true | true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
3.69.115.178 | unknown | United States | 16509 | AMAZON-02US | true | |
3.68.171.119 | 6.tcp.eu.ngrok.io | United States | 16509 | AMAZON-02US | true |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1443977 |
Start date and time: | 2024-05-19 13:56:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 43s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1iZH7aeO5F.exerenamed because original name is a hash value |
Original Sample Name: | 320f34b9a9f567e773d2a526daf749fa.exe |
Detection: | MAL |
Classification: | mal100.spre.phis.troj.adwa.evad.winEXE@10/6@4/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
07:56:56 | API Interceptor | |
13:56:57 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3.69.115.178 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
3.68.171.119 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
6.tcp.eu.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Gafgyt, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe
Download File
Process: | C:\Users\user\Desktop\1iZH7aeO5F.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 95232 |
Entropy (8bit): | 5.558282844115275 |
Encrypted: | false |
SSDEEP: | 768:KY3/KpD7O/pBcxYsbae6GIXb9pDX2b98PL0OXLeuXxrjEtCdnl2pi1Rz4Rk3hsGi:ZKBOx6baIa9RPj00ljEwzGi1dDRDUgS |
MD5: | 320F34B9A9F567E773D2A526DAF749FA |
SHA1: | 6A56B12F075F8DAAF354CA44810BEC29E756C941 |
SHA-256: | 16E030019F05B734A973A0FAFC0FB678D0EB2736CFD5159A7EA82EBF3C198170 |
SHA-512: | 92C05E4D6C55B68810E55B918C5C017C5D772E9F85C65EC0F35B0B9B24345BA33E0E9D1FB0055DF8CEDB437EE55F6409E3ED16E6ECA3A0A03BE3831DC5531D50 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Corporation.exe:Zone.Identifier
Download File
Process: | C:\Users\user\Desktop\1iZH7aeO5F.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\1iZH7aeO5F.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5 |
Entropy (8bit): | 2.321928094887362 |
Encrypted: | false |
SSDEEP: | 3:6n:6n |
MD5: | 2099BB64FD1770D321DF364F99B658D1 |
SHA1: | 3124EDEAA14C060BECFA8B980ED77DB15D56A9E3 |
SHA-256: | D53CE6BDBD0C3CB4596AC3103F15824570A9858DA95F63CEDF64CEC11DC44E2D |
SHA-512: | 3481F2A02F7B1255AD0F3CD8A716DE9C7414753B6F8657F0BF99738FF6623F8717469BC10E737D6C0D1D13846E726D50BAEB5E8EF73EFCFCE7BE5C63327C4895 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\netsh.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 313 |
Entropy (8bit): | 4.971939296804078 |
Encrypted: | false |
SSDEEP: | 6:/ojfKsUTGN8Ypox42k9L+DbGMKeQE+vigqAZs2E+AYeDPO+Yswyha:wjPIGNrkHk9iaeIM6ADDPOHyha |
MD5: | 689E2126A85BF55121488295EE068FA1 |
SHA1: | 09BAAA253A49D80C18326DFBCA106551EBF22DD6 |
SHA-256: | D968A966EF474068E41256321F77807A042F1965744633D37A203A705662EC25 |
SHA-512: | C3736A8FC7E6573FA1B26FE6A901C05EE85C55A4A276F8F569D9EADC9A58BEC507D1BB90DBF9EA62AE79A6783178C69304187D6B90441D82E46F5F56172B5C5C |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.558282844115275 |
TrID: |
|
File name: | 1iZH7aeO5F.exe |
File size: | 95'232 bytes |
MD5: | 320f34b9a9f567e773d2a526daf749fa |
SHA1: | 6a56b12f075f8daaf354ca44810bec29e756c941 |
SHA256: | 16e030019f05b734a973a0fafc0fb678d0eb2736cfd5159a7ea82ebf3c198170 |
SHA512: | 92c05e4d6c55b68810e55b918c5c017c5d772e9f85c65ec0f35b0b9b24345ba33e0e9d1fb0055df8cedb437ee55f6409e3ed16e6eca3a0a03be3831dc5531d50 |
SSDEEP: | 768:KY3/KpD7O/pBcxYsbae6GIXb9pDX2b98PL0OXLeuXxrjEtCdnl2pi1Rz4Rk3hsGi:ZKBOx6baIa9RPj00ljEwzGi1dDRDUgS |
TLSH: | 8F93F84977E56524E4BF56F79871F2004E34B48B1602E39D48F219AA1B33AC44F89FEB |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Ef.................p............... ........@.. ....................................@................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x418efe |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6645061A [Wed May 15 18:59:38 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x18ea8 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x1a000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x16f04 | 0x17000 | e7224b3d383a503c52fc24ac0d2fffe8 | False | 0.36818529211956524 | data | 5.590134667871109 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.reloc | 0x1a000 | 0xc | 0x200 | 02466978873e232bef309f048b95192f | False | 0.041015625 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
05/19/24-13:58:30.141221 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:24.873447 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:37.401284 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:27.517197 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:40.953521 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:43.869191 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:01.293185 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:03.600944 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:22.261137 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:55.620050 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:52.818612 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:32.733312 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:21.177524 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
05/19/24-13:58:19.605486 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:19.811421 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:22.393782 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:58.732625 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:04.716868 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:12.889712 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:48.841533 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:55.673276 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:07.280571 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:00.265208 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:03.906997 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:11.073416 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:14.849038 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:17.710652 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:52.868787 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:09.905031 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:19.605486 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:10.297630 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:13.052528 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:27.299562 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:30.702609 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:24.819791 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:22.209333 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:37.333591 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:01.588817 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:09.310016 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:49.912771 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:06.277632 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:12.109502 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:53.202661 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:03.547062 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:44.237483 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:47.102281 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:48.599643 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49748 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:22.622570 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:27.466502 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:23.369142 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:30.687437 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:37.885777 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
05/19/24-14:01:03.033945 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49761 | 13006 | 192.168.2.5 | 3.69.115.178 |
05/19/24-13:57:20.532509 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:30.091760 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:33.272402 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:36.010938 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:19.573184 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:32.682513 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:38.789971 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:41.511014 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:01.287429 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:37.347524 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:43.807491 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:40.901851 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:33.320635 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:30.693152 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:36.065243 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:01:02.978980 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49761 | 13006 | 192.168.2.5 | 3.69.115.178 |
05/19/24-13:57:27.352576 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:38.799294 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:41.523438 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:47.112042 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:44.293131 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:37.831032 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
05/19/24-13:59:12.837250 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:00.214834 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:22.622570 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:10.247529 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:21.171817 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
05/19/24-13:58:19.518408 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:20.476527 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:17.487883 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49738 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:13.046674 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:11.022301 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:17.698975 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:23.312492 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:30.702609 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:19.755628 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:12.130118 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:58.681738 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:01.531695 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:53.253209 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:22.388360 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:06.329376 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:09.320195 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:37.282316 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:49.965614 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:07.229080 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:59:48.789535 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:57:14.793035 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:04.686444 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-13:58:09.853627 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
05/19/24-14:00:03.901621 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 19, 2024 13:57:00.706864119 CEST | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:00.712179899 CEST | 13006 | 49704 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:00.712282896 CEST | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:01.287429094 CEST | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:01.292992115 CEST | 13006 | 49704 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:01.293184996 CEST | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:01.298612118 CEST | 13006 | 49704 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:01.527338028 CEST | 13006 | 49704 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:01.527580976 CEST | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:03.535880089 CEST | 49704 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:03.536628008 CEST | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:03.541361094 CEST | 13006 | 49704 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:03.546312094 CEST | 13006 | 49705 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:03.546418905 CEST | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:03.547061920 CEST | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:03.600800037 CEST | 13006 | 49705 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:03.600944042 CEST | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:03.606427908 CEST | 13006 | 49705 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:04.259557009 CEST | 13006 | 49705 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:04.259629965 CEST | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:06.265609980 CEST | 49705 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:06.266484022 CEST | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:06.271133900 CEST | 13006 | 49705 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:06.276257038 CEST | 13006 | 49706 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:06.276515961 CEST | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:06.277631998 CEST | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:06.328999043 CEST | 13006 | 49706 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:06.329375982 CEST | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:06.334913969 CEST | 13006 | 49706 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:07.016166925 CEST | 13006 | 49706 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:07.016289949 CEST | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:09.252491951 CEST | 49706 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:09.253823996 CEST | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:09.258171082 CEST | 13006 | 49706 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:09.309335947 CEST | 13006 | 49707 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:09.309598923 CEST | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:09.310015917 CEST | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:09.319981098 CEST | 13006 | 49707 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:09.320194960 CEST | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:09.325562000 CEST | 13006 | 49707 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:10.010397911 CEST | 13006 | 49707 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:10.010504007 CEST | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:12.015156984 CEST | 49707 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:12.015753031 CEST | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:12.020390987 CEST | 13006 | 49707 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:12.069127083 CEST | 13006 | 49708 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:12.069211006 CEST | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:12.109502077 CEST | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:12.130033016 CEST | 13006 | 49708 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:12.130117893 CEST | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:12.181282997 CEST | 13006 | 49708 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:12.767674923 CEST | 13006 | 49708 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:12.767762899 CEST | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:14.780648947 CEST | 49708 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:14.781725883 CEST | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:14.786449909 CEST | 13006 | 49708 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:14.792304039 CEST | 13006 | 49714 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:14.792398930 CEST | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:14.793035030 CEST | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:14.848963976 CEST | 13006 | 49714 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:14.849037886 CEST | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:14.854300022 CEST | 13006 | 49714 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:15.462346077 CEST | 13006 | 49714 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:15.462440968 CEST | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:17.475456953 CEST | 49714 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:17.481023073 CEST | 13006 | 49714 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:17.692450047 CEST | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:17.697977066 CEST | 13006 | 49716 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:17.698230028 CEST | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:17.698975086 CEST | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:17.710458040 CEST | 13006 | 49716 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:17.710652113 CEST | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:17.716022968 CEST | 13006 | 49716 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:18.390405893 CEST | 13006 | 49716 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:18.390521049 CEST | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:20.433239937 CEST | 49716 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:20.438611984 CEST | 13006 | 49716 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:20.470069885 CEST | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:20.475892067 CEST | 13006 | 49718 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:20.476016045 CEST | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:20.476526976 CEST | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:20.532409906 CEST | 13006 | 49718 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:20.532509089 CEST | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:20.537506104 CEST | 13006 | 49718 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:21.163750887 CEST | 13006 | 49718 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:21.163847923 CEST | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:23.199655056 CEST | 49718 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:23.205229998 CEST | 13006 | 49718 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:23.305973053 CEST | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:23.311635971 CEST | 13006 | 49719 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:23.312000990 CEST | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:23.312491894 CEST | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:23.368923903 CEST | 13006 | 49719 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:23.369142056 CEST | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:23.374557018 CEST | 13006 | 49719 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:23.994513988 CEST | 13006 | 49719 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:23.994699955 CEST | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:26.859771967 CEST | 49719 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:26.865475893 CEST | 13006 | 49719 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:27.293231010 CEST | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:27.298656940 CEST | 13006 | 49720 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:27.298854113 CEST | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:27.299561977 CEST | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:27.352477074 CEST | 13006 | 49720 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:27.352576017 CEST | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:27.357965946 CEST | 13006 | 49720 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:28.000294924 CEST | 13006 | 49720 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:28.000597000 CEST | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:30.015774965 CEST | 49720 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:30.020919085 CEST | 13006 | 49720 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:30.235384941 CEST | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:30.241103888 CEST | 13006 | 49721 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:30.241460085 CEST | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:30.687437057 CEST | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:30.692929029 CEST | 13006 | 49721 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:30.693151951 CEST | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:30.698801994 CEST | 13006 | 49721 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:30.702609062 CEST | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:30.708355904 CEST | 13006 | 49721 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:30.942318916 CEST | 13006 | 49721 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:30.942410946 CEST | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:32.963355064 CEST | 49721 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:32.969074011 CEST | 13006 | 49721 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:33.262398958 CEST | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:33.267849922 CEST | 13006 | 49722 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:33.267996073 CEST | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:33.272402048 CEST | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:33.320544958 CEST | 13006 | 49722 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:33.320635080 CEST | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:33.325567007 CEST | 13006 | 49722 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:33.987447977 CEST | 13006 | 49722 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:33.987545013 CEST | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:35.999485970 CEST | 49722 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:36.000149012 CEST | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:36.005404949 CEST | 13006 | 49722 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:36.010292053 CEST | 13006 | 49723 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:36.010509014 CEST | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:36.010937929 CEST | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:36.065155983 CEST | 13006 | 49723 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:36.065243006 CEST | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:36.070827961 CEST | 13006 | 49723 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:36.730247021 CEST | 13006 | 49723 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:36.730344057 CEST | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:38.735157013 CEST | 49723 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:38.736939907 CEST | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:38.740503073 CEST | 13006 | 49723 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:38.789081097 CEST | 13006 | 49724 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:38.789299965 CEST | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:38.789971113 CEST | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:38.799204111 CEST | 13006 | 49724 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:38.799293995 CEST | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:38.804706097 CEST | 13006 | 49724 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:39.491616011 CEST | 13006 | 49724 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:39.491710901 CEST | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:41.499517918 CEST | 49724 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:41.500193119 CEST | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:41.505074978 CEST | 13006 | 49724 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:41.510272026 CEST | 13006 | 49725 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:41.510540009 CEST | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:41.511013985 CEST | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:41.523205996 CEST | 13006 | 49725 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:41.523437977 CEST | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:41.533231020 CEST | 13006 | 49725 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:42.188287020 CEST | 13006 | 49725 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:42.188580990 CEST | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:44.210433960 CEST | 49725 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:44.217730045 CEST | 13006 | 49725 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:44.229238987 CEST | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:44.236638069 CEST | 13006 | 49726 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:44.236740112 CEST | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:44.237483025 CEST | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:44.292938948 CEST | 13006 | 49726 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:44.293131113 CEST | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:44.298566103 CEST | 13006 | 49726 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:45.038036108 CEST | 13006 | 49726 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:45.041393995 CEST | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:47.046538115 CEST | 49726 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:47.047523022 CEST | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:47.052436113 CEST | 13006 | 49726 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:47.101434946 CEST | 13006 | 49727 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:47.101650953 CEST | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:47.102281094 CEST | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:47.111841917 CEST | 13006 | 49727 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:47.112041950 CEST | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:47.117280960 CEST | 13006 | 49727 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:47.803777933 CEST | 13006 | 49727 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:47.803966045 CEST | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:49.821165085 CEST | 49727 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:49.827218056 CEST | 13006 | 49727 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:49.906727076 CEST | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:49.912256956 CEST | 13006 | 49728 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:49.912365913 CEST | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:49.912770987 CEST | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:49.965373039 CEST | 13006 | 49728 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:49.965614080 CEST | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:49.971074104 CEST | 13006 | 49728 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:50.713473082 CEST | 13006 | 49728 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:50.713582993 CEST | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:52.735888958 CEST | 49728 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:52.740900040 CEST | 13006 | 49728 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:52.813009024 CEST | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:52.818058014 CEST | 13006 | 49730 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:52.818151951 CEST | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:52.818612099 CEST | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:52.868726015 CEST | 13006 | 49730 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:52.868787050 CEST | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:52.873661995 CEST | 13006 | 49730 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:53.517165899 CEST | 13006 | 49730 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:53.517393112 CEST | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:55.594805002 CEST | 49730 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:55.600140095 CEST | 13006 | 49730 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:55.613459110 CEST | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:55.618798018 CEST | 13006 | 49731 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:55.618894100 CEST | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:55.620049953 CEST | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:55.673068047 CEST | 13006 | 49731 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:55.673275948 CEST | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:55.678239107 CEST | 13006 | 49731 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:56.167782068 CEST | 13006 | 49731 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:56.172513962 CEST | 13006 | 49731 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:56.172593117 CEST | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:58.509807110 CEST | 49731 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:58.676235914 CEST | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:58.681272030 CEST | 13006 | 49732 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:58.681359053 CEST | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:58.681737900 CEST | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:58.732489109 CEST | 13006 | 49732 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:58.732625008 CEST | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:57:58.737463951 CEST | 13006 | 49732 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:59.257917881 CEST | 13006 | 49732 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:59.262646914 CEST | 13006 | 49732 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:57:59.262742996 CEST | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:01.459604979 CEST | 49732 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:01.525835991 CEST | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:01.530859947 CEST | 13006 | 49733 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:01.530931950 CEST | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:01.531694889 CEST | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:01.588594913 CEST | 13006 | 49733 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:01.588816881 CEST | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:01.593736887 CEST | 13006 | 49733 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:02.102580070 CEST | 13006 | 49733 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:02.107541084 CEST | 13006 | 49733 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:02.107593060 CEST | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:04.110130072 CEST | 49733 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:04.656816006 CEST | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:04.661909103 CEST | 13006 | 49734 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:04.662117004 CEST | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:04.686444044 CEST | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:04.716681957 CEST | 13006 | 49734 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:04.716867924 CEST | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:04.726691961 CEST | 13006 | 49734 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:05.206093073 CEST | 13006 | 49734 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:05.210772038 CEST | 13006 | 49734 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:05.210978031 CEST | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:07.218476057 CEST | 49734 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:07.219360113 CEST | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:07.228316069 CEST | 13006 | 49735 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:07.228400946 CEST | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:07.229079962 CEST | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:07.280512094 CEST | 13006 | 49735 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:07.280570984 CEST | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:07.285444975 CEST | 13006 | 49735 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:07.784384966 CEST | 13006 | 49735 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:07.789230108 CEST | 13006 | 49735 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:07.789314985 CEST | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:09.796533108 CEST | 49735 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:09.797410965 CEST | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:09.852890968 CEST | 13006 | 49736 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:09.853144884 CEST | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:09.853626966 CEST | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:09.904807091 CEST | 13006 | 49736 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:09.905030966 CEST | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:09.912184000 CEST | 13006 | 49736 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:10.407164097 CEST | 13006 | 49736 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:10.411992073 CEST | 13006 | 49736 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:10.412209988 CEST | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:12.459871054 CEST | 49736 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:12.710725069 CEST | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:12.715817928 CEST | 13006 | 49737 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:12.715913057 CEST | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:13.046674013 CEST | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:13.052445889 CEST | 13006 | 49737 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:13.052527905 CEST | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:13.058029890 CEST | 13006 | 49737 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:13.293591022 CEST | 13006 | 49737 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:13.298610926 CEST | 13006 | 49737 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:13.298803091 CEST | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:15.365113020 CEST | 49737 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:15.848793030 CEST | 49738 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:15.854072094 CEST | 13006 | 49738 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:15.854154110 CEST | 49738 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:16.416874886 CEST | 13006 | 49738 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:16.465197086 CEST | 13006 | 49738 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:16.465239048 CEST | 13006 | 49738 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:16.465382099 CEST | 49738 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:16.466444969 CEST | 49738 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:17.487883091 CEST | 49738 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:17.493505001 CEST | 13006 | 49738 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:19.512399912 CEST | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:19.517882109 CEST | 13006 | 49739 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:19.517997026 CEST | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:19.518408060 CEST | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:19.572984934 CEST | 13006 | 49739 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:19.573184013 CEST | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:19.578232050 CEST | 13006 | 49739 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:19.605485916 CEST | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:19.611136913 CEST | 13006 | 49739 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:20.115334988 CEST | 13006 | 49739 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:20.120012999 CEST | 13006 | 49739 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:20.120191097 CEST | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:22.155855894 CEST | 49739 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:22.156706095 CEST | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:22.208738089 CEST | 13006 | 49740 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:22.208830118 CEST | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:22.209332943 CEST | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:22.261029005 CEST | 13006 | 49740 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:22.261137009 CEST | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:22.266113043 CEST | 13006 | 49740 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:22.789012909 CEST | 13006 | 49740 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:22.793915987 CEST | 13006 | 49740 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:22.794013977 CEST | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:24.805918932 CEST | 49740 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:24.813409090 CEST | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:24.819134951 CEST | 13006 | 49741 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:24.819308996 CEST | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:24.819791079 CEST | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:24.873346090 CEST | 13006 | 49741 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:24.873446941 CEST | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:24.878827095 CEST | 13006 | 49741 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:25.415775061 CEST | 13006 | 49741 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:25.420315981 CEST | 13006 | 49741 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:25.423047066 CEST | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:25.425296068 CEST | 13006 | 49741 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:25.425358057 CEST | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:27.455615997 CEST | 49741 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:27.458981037 CEST | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:27.465780973 CEST | 13006 | 49742 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:27.465873003 CEST | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:27.466501951 CEST | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:27.517106056 CEST | 13006 | 49742 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:27.517196894 CEST | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:27.522274017 CEST | 13006 | 49742 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:28.022763968 CEST | 13006 | 49742 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:28.027399063 CEST | 13006 | 49742 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:28.027482986 CEST | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:30.037406921 CEST | 49742 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:30.058484077 CEST | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:30.089128017 CEST | 13006 | 49743 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:30.089318991 CEST | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:30.091759920 CEST | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:30.141149044 CEST | 13006 | 49743 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:30.141221046 CEST | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:30.146365881 CEST | 13006 | 49743 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:30.666953087 CEST | 13006 | 49743 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:30.671837091 CEST | 13006 | 49743 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:30.671900988 CEST | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:32.671598911 CEST | 49743 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:32.672281981 CEST | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:32.681972027 CEST | 13006 | 49744 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:32.682321072 CEST | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:32.682512999 CEST | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:32.733011961 CEST | 13006 | 49744 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:32.733311892 CEST | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:32.738326073 CEST | 13006 | 49744 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:33.252136946 CEST | 13006 | 49744 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:33.256732941 CEST | 13006 | 49744 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:33.256799936 CEST | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:37.211405039 CEST | 49744 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:37.341661930 CEST | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:37.346852064 CEST | 13006 | 49745 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:37.346962929 CEST | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:37.347523928 CEST | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:37.401163101 CEST | 13006 | 49745 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:37.401283979 CEST | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:37.406938076 CEST | 13006 | 49745 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:37.911853075 CEST | 13006 | 49745 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:37.917891026 CEST | 13006 | 49745 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:37.917967081 CEST | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:39.953352928 CEST | 49745 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:40.896017075 CEST | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:40.901087046 CEST | 13006 | 49746 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:40.901169062 CEST | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:40.901850939 CEST | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:40.953305006 CEST | 13006 | 49746 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:40.953521013 CEST | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:40.958776951 CEST | 13006 | 49746 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:41.461981058 CEST | 13006 | 49746 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:41.466789007 CEST | 13006 | 49746 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:41.466876984 CEST | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:43.468612909 CEST | 49746 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:43.798475027 CEST | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:43.803898096 CEST | 13006 | 49747 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:43.804028034 CEST | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:43.807491064 CEST | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:43.868988991 CEST | 13006 | 49747 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:43.869190931 CEST | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:43.874283075 CEST | 13006 | 49747 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:44.373368979 CEST | 13006 | 49747 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:44.378490925 CEST | 13006 | 49747 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:44.378582001 CEST | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:47.659929991 CEST | 49747 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:47.676023006 CEST | 49748 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:47.713282108 CEST | 13006 | 49748 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:47.714719057 CEST | 49748 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:48.300187111 CEST | 13006 | 49748 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:48.343403101 CEST | 49748 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:48.345344067 CEST | 13006 | 49748 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:48.345360994 CEST | 13006 | 49748 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:48.345525980 CEST | 49748 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:48.345525980 CEST | 49748 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:48.599642992 CEST | 49748 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:48.605360985 CEST | 13006 | 49748 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:53.195399046 CEST | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:53.201680899 CEST | 13006 | 49749 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:53.201792002 CEST | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:53.202661037 CEST | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:53.253122091 CEST | 13006 | 49749 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:53.253209114 CEST | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:53.258634090 CEST | 13006 | 49749 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:53.777420998 CEST | 13006 | 49749 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:53.782360077 CEST | 13006 | 49749 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:58:53.782478094 CEST | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:58:55.780972004 CEST | 49749 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:00.208844900 CEST | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:00.214071989 CEST | 13006 | 49750 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:00.214262009 CEST | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:00.214833975 CEST | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:00.265001059 CEST | 13006 | 49750 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:00.265208006 CEST | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:00.270168066 CEST | 13006 | 49750 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:00.782491922 CEST | 13006 | 49750 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:00.787286997 CEST | 13006 | 49750 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:00.787374973 CEST | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:02.828882933 CEST | 49750 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:10.240875006 CEST | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:10.246640921 CEST | 13006 | 49751 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:10.246789932 CEST | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:10.247529030 CEST | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:10.297420025 CEST | 13006 | 49751 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:10.297630072 CEST | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:10.303257942 CEST | 13006 | 49751 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:10.805330038 CEST | 13006 | 49751 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:10.810036898 CEST | 13006 | 49751 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:10.810112953 CEST | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:12.826059103 CEST | 49751 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:12.829778910 CEST | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:12.836666107 CEST | 13006 | 49752 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:12.836771965 CEST | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:12.837249994 CEST | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:12.889538050 CEST | 13006 | 49752 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:12.889712095 CEST | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:12.895312071 CEST | 13006 | 49752 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:13.387269974 CEST | 13006 | 49752 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:13.392446995 CEST | 13006 | 49752 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:13.392549992 CEST | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:15.442898035 CEST | 49752 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:19.748450994 CEST | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:19.754750967 CEST | 13006 | 49753 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:19.754848003 CEST | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:19.755628109 CEST | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:19.811333895 CEST | 13006 | 49753 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:19.811420918 CEST | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:19.817445993 CEST | 13006 | 49753 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:20.323151112 CEST | 13006 | 49753 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:20.328187943 CEST | 13006 | 49753 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:20.328274965 CEST | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:22.328125954 CEST | 49753 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:22.328955889 CEST | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:22.338855028 CEST | 13006 | 49754 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:22.339066982 CEST | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:22.388360023 CEST | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:22.393337965 CEST | 13006 | 49754 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:22.393781900 CEST | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:22.398782969 CEST | 13006 | 49754 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:22.622570038 CEST | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:22.627674103 CEST | 13006 | 49754 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:22.914586067 CEST | 13006 | 49754 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:22.919317961 CEST | 13006 | 49754 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:22.919583082 CEST | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:24.932934046 CEST | 49754 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:37.275433064 CEST | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:37.280826092 CEST | 13006 | 49755 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:37.280919075 CEST | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:37.282315969 CEST | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:37.333513975 CEST | 13006 | 49755 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:37.333590984 CEST | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:37.338846922 CEST | 13006 | 49755 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:37.848175049 CEST | 13006 | 49755 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:37.852895975 CEST | 13006 | 49755 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:37.852968931 CEST | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:47.371789932 CEST | 49755 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:48.783298969 CEST | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:48.788662910 CEST | 13006 | 49756 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:48.788805008 CEST | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:48.789535046 CEST | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:48.841438055 CEST | 13006 | 49756 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:48.841532946 CEST | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:48.846586943 CEST | 13006 | 49756 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:49.334038019 CEST | 13006 | 49756 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:49.339335918 CEST | 13006 | 49756 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 13:59:49.339473009 CEST | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 13:59:52.007766008 CEST | 49756 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:03.062750101 CEST | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:03.068126917 CEST | 13006 | 49757 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:03.068238974 CEST | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:03.901621103 CEST | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:03.906897068 CEST | 13006 | 49757 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:03.906996965 CEST | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:03.912389994 CEST | 13006 | 49757 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:04.130201101 CEST | 13006 | 49757 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:04.130300999 CEST | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:06.221843004 CEST | 49757 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:06.227242947 CEST | 13006 | 49757 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:11.016043901 CEST | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:11.021339893 CEST | 13006 | 49758 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:11.021446943 CEST | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:11.022300959 CEST | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:11.073262930 CEST | 13006 | 49758 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:11.073415995 CEST | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:11.078424931 CEST | 13006 | 49758 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:11.706121922 CEST | 13006 | 49758 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:11.706233978 CEST | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:13.725110054 CEST | 49758 | 13006 | 192.168.2.5 | 3.68.171.119 |
May 19, 2024 14:00:13.730432034 CEST | 13006 | 49758 | 3.68.171.119 | 192.168.2.5 |
May 19, 2024 14:00:18.962853909 CEST | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:18.968255997 CEST | 13006 | 49759 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:18.968373060 CEST | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:21.171817064 CEST | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:21.177273035 CEST | 13006 | 49759 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:21.177524090 CEST | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:21.183069944 CEST | 13006 | 49759 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:21.399013996 CEST | 13006 | 49759 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:21.399175882 CEST | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:23.450938940 CEST | 49759 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:23.456183910 CEST | 13006 | 49759 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:37.824238062 CEST | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:37.830080032 CEST | 13006 | 49760 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:37.830188990 CEST | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:37.831032038 CEST | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:37.885608912 CEST | 13006 | 49760 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:37.885776997 CEST | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:37.891309977 CEST | 13006 | 49760 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:38.523072004 CEST | 13006 | 49760 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:00:38.523303032 CEST | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:40.600415945 CEST | 49760 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:00:40.606077909 CEST | 13006 | 49760 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:01:02.972568989 CEST | 49761 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:01:02.978178978 CEST | 13006 | 49761 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:01:02.978405952 CEST | 49761 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:01:02.978980064 CEST | 49761 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:01:03.033751011 CEST | 13006 | 49761 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:01:03.033945084 CEST | 49761 | 13006 | 192.168.2.5 | 3.69.115.178 |
May 19, 2024 14:01:03.039242983 CEST | 13006 | 49761 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:01:03.674268961 CEST | 13006 | 49761 | 3.69.115.178 | 192.168.2.5 |
May 19, 2024 14:01:03.674542904 CEST | 49761 | 13006 | 192.168.2.5 | 3.69.115.178 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 19, 2024 13:57:00.620995998 CEST | 60397 | 53 | 192.168.2.5 | 1.1.1.1 |
May 19, 2024 13:57:00.631136894 CEST | 53 | 60397 | 1.1.1.1 | 192.168.2.5 |
May 19, 2024 13:58:01.460277081 CEST | 54210 | 53 | 192.168.2.5 | 1.1.1.1 |
May 19, 2024 13:58:01.522325039 CEST | 53 | 54210 | 1.1.1.1 | 192.168.2.5 |
May 19, 2024 13:59:09.434355974 CEST | 60016 | 53 | 192.168.2.5 | 1.1.1.1 |
May 19, 2024 13:59:09.452888966 CEST | 53 | 60016 | 1.1.1.1 | 192.168.2.5 |
May 19, 2024 14:00:13.725698948 CEST | 62026 | 53 | 192.168.2.5 | 1.1.1.1 |
May 19, 2024 14:00:13.781152010 CEST | 53 | 62026 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
May 19, 2024 13:57:00.620995998 CEST | 192.168.2.5 | 1.1.1.1 | 0xf37 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 19, 2024 13:58:01.460277081 CEST | 192.168.2.5 | 1.1.1.1 | 0x4c41 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 19, 2024 13:59:09.434355974 CEST | 192.168.2.5 | 1.1.1.1 | 0xb8c7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
May 19, 2024 14:00:13.725698948 CEST | 192.168.2.5 | 1.1.1.1 | 0x3618 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
May 19, 2024 13:57:00.631136894 CEST | 1.1.1.1 | 192.168.2.5 | 0xf37 | No error (0) | 3.68.171.119 | A (IP address) | IN (0x0001) | false | ||
May 19, 2024 13:58:01.522325039 CEST | 1.1.1.1 | 192.168.2.5 | 0x4c41 | No error (0) | 3.68.171.119 | A (IP address) | IN (0x0001) | false | ||
May 19, 2024 13:59:09.452888966 CEST | 1.1.1.1 | 192.168.2.5 | 0xb8c7 | No error (0) | 3.68.171.119 | A (IP address) | IN (0x0001) | false | ||
May 19, 2024 14:00:13.781152010 CEST | 1.1.1.1 | 192.168.2.5 | 0x3618 | No error (0) | 3.69.115.178 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 07:56:51 |
Start date: | 19/05/2024 |
Path: | C:\Users\user\Desktop\1iZH7aeO5F.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xf90000 |
File size: | 95'232 bytes |
MD5 hash: | 320F34B9A9F567E773D2A526DAF749FA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 07:56:53 |
Start date: | 19/05/2024 |
Path: | C:\Windows\SysWOW64\netsh.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1080000 |
File size: | 82'432 bytes |
MD5 hash: | 4E89A1A088BE715D6C946E55AB07C7DF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 3 |
Start time: | 07:56:53 |
Start date: | 19/05/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 07:56:57 |
Start date: | 19/05/2024 |
Path: | C:\Windows\SysWOW64\netsh.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1080000 |
File size: | 82'432 bytes |
MD5 hash: | 4E89A1A088BE715D6C946E55AB07C7DF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 5 |
Start time: | 07:56:57 |
Start date: | 19/05/2024 |
Path: | C:\Windows\SysWOW64\netsh.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1080000 |
File size: | 82'432 bytes |
MD5 hash: | 4E89A1A088BE715D6C946E55AB07C7DF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 6 |
Start time: | 07:56:57 |
Start date: | 19/05/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 07:56:57 |
Start date: | 19/05/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 21.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 8.5% |
Total number of Nodes: | 129 |
Total number of Limit Nodes: | 9 |
Graph
Function 05764298 Relevance: 10.7, Strings: 7, Instructions: 1950COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05764287 Relevance: 10.5, Strings: 7, Instructions: 1751COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E05B7 Relevance: 1.6, APIs: 1, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E0739 Relevance: 1.6, APIs: 1, Instructions: 57nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E05EE Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A186 Relevance: 1.5, APIs: 1, Instructions: 42networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E076A Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05767347 Relevance: .7, Instructions: 662COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05767780 Relevance: .5, Instructions: 497COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05768279 Relevance: 3.7, Strings: 2, Instructions: 1242COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057682F4 Relevance: 3.6, Strings: 2, Instructions: 1079COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0576832E Relevance: 3.6, Strings: 2, Instructions: 1076COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0576835D Relevance: 3.6, Strings: 2, Instructions: 1075COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E232C Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AA75 Relevance: 1.6, APIs: 1, Instructions: 92fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E2224 Relevance: 1.6, APIs: 1, Instructions: 89timeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E1C18 Relevance: 1.6, APIs: 1, Instructions: 89COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E08CC Relevance: 1.6, APIs: 1, Instructions: 86COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E3318 Relevance: 1.6, APIs: 1, Instructions: 85COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057698A0 Relevance: 1.6, Strings: 1, Instructions: 335COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E234E Relevance: 1.6, APIs: 1, Instructions: 84COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E3249 Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AE77 Relevance: 1.6, APIs: 1, Instructions: 78fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E17F2 Relevance: 1.6, APIs: 1, Instructions: 77networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E1DCE Relevance: 1.6, APIs: 1, Instructions: 77fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E1C3E Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E0A6C Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AAA6 Relevance: 1.6, APIs: 1, Instructions: 76fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187BAA3 Relevance: 1.6, APIs: 1, Instructions: 74threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E3417 Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AC37 Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A9BF Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E2065 Relevance: 1.6, APIs: 1, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E043F Relevance: 1.6, APIs: 1, Instructions: 70COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E3183 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187B7B5 Relevance: 1.6, APIs: 1, Instructions: 69fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187BCB8 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A140 Relevance: 1.6, APIs: 1, Instructions: 69networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E1812 Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E1DEE Relevance: 1.6, APIs: 1, Instructions: 67fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E24FE Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A2D2 Relevance: 1.6, APIs: 1, Instructions: 67COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E27BA Relevance: 1.6, APIs: 1, Instructions: 66libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A61E Relevance: 1.6, APIs: 1, Instructions: 65comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E2262 Relevance: 1.6, APIs: 1, Instructions: 64timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AB7C Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E343A Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E3356 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E090A Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A573 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AEAE Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187B885 Relevance: 1.6, APIs: 1, Instructions: 59fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187BB6C Relevance: 1.6, APIs: 1, Instructions: 59windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E31A6 Relevance: 1.6, APIs: 1, Instructions: 58COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E2092 Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E27DA Relevance: 1.6, APIs: 1, Instructions: 56libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E3282 Relevance: 1.6, APIs: 1, Instructions: 55COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E046E Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187B7E2 Relevance: 1.6, APIs: 1, Instructions: 53fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AC6A Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187B718 Relevance: 1.6, APIs: 1, Instructions: 51COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E252E Relevance: 1.5, APIs: 1, Instructions: 49networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E0AB2 Relevance: 1.5, APIs: 1, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E12D4 Relevance: 1.5, APIs: 1, Instructions: 49windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187BCEE Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187B8AA Relevance: 1.5, APIs: 1, Instructions: 47fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A2FE Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187BB8E Relevance: 1.5, APIs: 1, Instructions: 46windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A59A Relevance: 1.5, APIs: 1, Instructions: 45COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187ABBE Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187BAF2 Relevance: 1.5, APIs: 1, Instructions: 43threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187B73A Relevance: 1.5, APIs: 1, Instructions: 40COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187A65E Relevance: 1.5, APIs: 1, Instructions: 39comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 062E12F6 Relevance: 1.5, APIs: 1, Instructions: 35windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0187AA12 Relevance: 1.5, APIs: 1, Instructions: 35COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05769890 Relevance: 1.5, Strings: 1, Instructions: 265COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057699A5 Relevance: 1.5, Strings: 1, Instructions: 232COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05769A03 Relevance: 1.5, Strings: 1, Instructions: 221COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05769A53 Relevance: 1.5, Strings: 1, Instructions: 214COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05769AD5 Relevance: 1.4, Strings: 1, Instructions: 193COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05769BC5 Relevance: 1.4, Strings: 1, Instructions: 146COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05760958 Relevance: 1.4, Strings: 1, Instructions: 109COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05763802 Relevance: .5, Instructions: 497COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05767E40 Relevance: .3, Instructions: 287COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057639BF Relevance: .2, Instructions: 182COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05767E2F Relevance: .2, Instructions: 150COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0576821E Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05763B18 Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0576A1A0 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057600B8 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05760007 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05622500 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01B60A34 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05760118 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05769EC1 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057671C1 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0188B698 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 056223A4 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01B60A13 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01B605DF Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05760879 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057600A8 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01B60AF0 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01B60606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0188B6E7 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0562256B Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05621E17 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 056223F3 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05764200 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 057636A8 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0576A15F Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018723F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018723BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05764210 Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|